Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re[2]: First Dcom Worm on wild

From: BrAinsTorM <BrAinsTorM(at)quakenet.biz>
Date: Mon Aug 11 2003 - 16:44:22 EDT

Hello Carlos,

don't forget to del the registry entrys in run :-)

btw below the answer from mcafee which i send the virus.



A.V.E.R.T. Sample Analysis
Issue Number:279341
Virus Research Analyst: Brant Yaeger
Identified:W32/Lovsan.worm

AVERT Labs, Beaverton
Current Scan Engine Version:4.2.60

Current DAT Version:4283

Thank you for your submission.

CL> We have found a file in XP servers named MSBLAST.EXE exploiting the DCOM CL> vulnerability.

Do you need help?X

CL> Our servers kept rebooting, we deleted this file and they stopped. I CL> guess we are seeing as a new malicious code.

CL> Carlos Lang

CL> -----Mensaje original-----
CL> De: Frank Nusko [mailto:BrAinsTorM@quakenet.biz] 
CL> Enviado el: Lunes, 11 de Agosto de 2003 02:37 p.m.
CL> Para: focus-virus@securityfocus.com
CL> Asunto: First Dcom Worm on wild

CL> Today i detected the first worm on wild which spreads itself.

CL> The executable is named msblast.exe and contains the strings:

CL> "SAY LOVE YOU SAN!! Bill gates you make it possible"

CL> as far as i covered from the compressed/packed exe it uses the 48 target

CL> xpl.

CL> After a succesful executing on your system it begins scanning other CL> system

Do you need more help?X

CL> starting from 192.168.0.1 and going up all ip and classes.

CL> so long,

CL> if you catch more informations lemme know them

CL> regards

CL> Frank

CL> ------------------------------------------------------------------------
CL> ---
CL> ------------------------------------------------------------------------
CL> ----

Received on Mon Aug 11 16:57:00 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:40 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library