5 Replies - 1548 Views - Last Post: 30 January 2002 - 03:50 PM

#1 skyhawk133   User is offline

  • Head DIC Head
  • member icon

Reputation: 1981
  • View blog
  • Posts: 20,434
  • Joined: 17-March 01

VIRUS ALERT:  new photos from my party!

Posted 29 January 2002 - 05:28 PM

From: http://vil.mcafee.co...p?virus_k=99332

This mass-mailing worm drops a BackDoor trojan (BackDoor-AAF) on WindowsNT/2K/XP system. The worm itself carries no destructive payloads. It arrives in an email message containing the following information:

Subject: new photos from my party!
Body: Hello!

My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!

Attachment: www.myparty.yahoo.com (29,696 byte PE file)


The attachment name may trick some users into thinking that if they click on the file, they will be taken to a Yahoo website. Certain email clients, especially those that underline the filename, may make this attachment appear more like a URL than the above Microsoft Outlook example which is more clearly distinguishable. The attachment is an executable file with a .COM extension, not a URL. Running the attachment infects the local machine.

On Windows9x/ME
If the date is between January 25-29, 2002, the virus copies itself to C:Recycledregctrl.exe and executes that file.

On WinNT/2K/XP
If the date is not between January 25-29, 2002, the worm copies itself to C:Recycled as F-[random number]-[random number]-[random number] with no extension
If the date is between January 25-29, 2002, the worm copies itself to C:regctrl.exe and drops the file MSSTASK.EXE in the STARTUP folder. MSSTASK.EXE is a BackDoor trojan. After the initial file is run, it is deleted. If the executables filename is ACCESS, the user is directed to the www.disney.com website.
This virus only attempts to massmail itself on January 25, 26, 27, 28 or 29, 2002. The users default SMTP server is retrieved from the registry.

HKEY_CURRENT_USERSoftwareMicrosoftInternet Account ManagerAccounts0000001

The virus uses this SMTP server to send itself out to all addresses found in the Windows Address Book and addresses found within .DBX files.


Is This A Good Question/Topic? 0
  • +

Replies To: VIRUS ALERT:  new photos from my party!

#2 jaredigital   User is offline

  • 42. That's my final answer.
  • member icon

Reputation: 1
  • View blog
  • Posts: 4,090
  • Joined: 22-April 01

Re: VIRUS ALERT:  new photos from my party!

Posted 29 January 2002 - 05:46 PM

additionally, never open attached pictures sent by Chris. :) this is the worst kind of virus.
Was This Post Helpful? 0
  • +
  • -

#3 supersloth   User is offline

  • serial frotteur - RUDEST MEMBER ON D.I.C.
  • member icon


Reputation: 4695
  • View blog
  • Posts: 28,516
  • Joined: 21-March 01

Re: VIRUS ALERT:  new photos from my party!

Posted 29 January 2002 - 06:05 PM

ever, worst virus ever.

if by chance you do open one from chris, you will immediately grab the nearest fork and gouge your eyes out. its just the way people react... :biggrin:

Was This Post Helpful? 0
  • +
  • -

#4 SlashRaid   User is offline

  • Dream.In.Force

Reputation: 1
  • View blog
  • Posts: 2,421
  • Joined: 21-January 02

Re: VIRUS ALERT:  new photos from my party!

Posted 30 January 2002 - 09:16 AM

Just adding a link for those of you interested, article on the My Party virus.

[skyhawk takes out the "" in the url]

Was This Post Helpful? 0
  • +
  • -

#5 hipatrip   User is offline

  • D.I.C Head

Reputation: 0
  • View blog
  • Posts: 110
  • Joined: 07-November 01

Re: VIRUS ALERT:  new photos from my party!

Posted 30 January 2002 - 03:41 PM

Monday, I recieved three mails of it. I interpretted it as spam, so I deleted them immediatly.
Was This Post Helpful? 0
  • +
  • -

#6 EchoHype   User is offline

  • D.I.C Regular

Reputation: 0
  • View blog
  • Posts: 270
  • Joined: 16-October 01

Re: VIRUS ALERT:  new photos from my party!

Posted 30 January 2002 - 03:50 PM

LOL, I just signed on, opened up email, 212 new emails, received 13 emails with the subject of: New pics from the party, but from different emails. So i sent one copy to AOL and had them trace it, cha ching, all from the same destination, what a punk!


=)


heh, wanna-be web designers!

Was This Post Helpful? 0
  • +
  • -

Page 1 of 1