A little scary, but I found 2 sites (one in a foreign language) that
mentioned the Avril virus on Dec 18th. A little scary that Sophos,
Symantec, etc didn't seem to have anything until one of the trigger dates,
the 7th. What REALLY bothers me is that it disables the anti-virus, and
there's no definitions for it for weeks. At least this one goes to a
specific site, so you can use proxy/firewall logs to track down any infected
machines.
I don't have the links now, but search for +virus and +www.avril-lavigne.com
and you'll find it off Google.
Dave
-----Original Message-----
From: Nizam S [mailto:snizam@globalsw-in.com]
Sent: Tuesday, January 07, 2003 10:59 PM
To: Pascal Schelcher; focus-virus@securityfocus.com
Subject: RE: Virus LIRVA[Scanned]
Sophos has sent the IDE file to their customers for this worm. But the
worm name they have mentioned is w32/avril.a B
Both are same?
Thanks,
Nizam
-----Original Message-----
From: Pascal Schelcher [mailto:pascal.schelcher@free.fr]
Sent: 07 January 2003 16:29
To: focus-virus@securityfocus.com
Subject: Virus LIRVA[Scanned]
Hello,
Does anybody know the LIRVA.A worm ?
I have some virus alerts about that.
Thanks,
Pascal Schelcher.
Received on Sat Jan 11 16:18:26 2003
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:38 EDT
|