Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Advice - VBS/VBSWG.aq@MM

Thread Tools
 
Search this Thread
 
Old 06 June 2002, 02:45 PM
  #1  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Seeing a few samples of this in the UK, it uses a double extension so hopefully it should be blocked by most corporates. The file to look out for is ShakiraPics.jpg.vbs which could be quite tempting.

http://vil.nai.com/vil/content/v_99506.htm
Old 06 June 2002, 02:57 PM
  #2  
DJ Dunk
Moderator
Support Scoobynet!
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Thumbs up

Name: VBS/VBSWG-AQ
Type: Visual Basic Script worm
Date: 5 June 2002

A virus identity file (IDE) which provides protection is
available now from our website and will be incorporated into the
July 2002 (3.59) release of Sophos Anti-Virus.

Sophos has received several reports of this worm from the wild.

Description:

VBS/VBSWG-AQ is an email worm. The worm spreads using an email
with the following characteristics:

Subject line: Shakira's Pics
Message text:
Hi :
i have sent the photos via attachment
have funn...
Attached file: ShakiraPics.jpg.vbs

When the attachment is run it will copy itself into the Windows
folder and add the registry entry

HKLM\Software\Microsoft\Windows\CurrentVersion\Run \Registry

to ensure that the worm is run each time Windows is started. It
will then attempt to email itself to all addresses listed in the
Microsoft Outlook address book. If the worm detects that mIRC is
installed it will create the file script.ini in the mIRC folder.
This file is detected by Sophos Anti-Virus as mIRC/Simp-Fam.

VBS/VBSWG-AQ will also create the registry entries

HKCU\Software\ShakiraPics\mailed
and
HKCU\Software\ShakiraPics\mirqued

after it has attempted to spread by email and IRC.

The worm will then search all local and network drives for files
with VBE or VBS extensions and overwrite them with a copy of
itself.

Finally the worm will display the message
"You have been infected by the ShakiraPics Worm".


Download the IDE file from
http://www.sophos.com/downloads/ide/vbswg-aq.ide

Read the analysis at
http://www.sophos.com/virusinfo/analyses/vbsvbswgaq.html

Download a ZIP file containing all the IDE files available for
the current version of Sophos Anti-Virus from
http://www.sophos.com/downloads/ide/ides.zip

Read about how to use IDE files at
http://www.sophos.com/downloads/ide/using.html
Old 06 June 2002, 03:36 PM
  #3  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

Thanks to groupshield allready been notified...

Incident Information:-

Originator: xxxxx xxxx <xxxxx_xxxxx@xxxxx.co.uk>
Recipients: "'xxxxx@xxxxxx-xx.com'" <xxxxxx@xxxxxx-xx.com>
Subject: Shakira's Pictures
Date/Time: 06/06/2002 12:48:20 PM

WARNING: The file attachment ShakiraPics.jpg.vbs was infected with the VBS/VBSWG.gen@MM virus and was not successfully cleaned.
Old 06 June 2002, 03:57 PM
  #4  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Cheers Jack
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
just me
Non Scooby Related
26
03 January 2020 11:12 AM
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
scoobhunter722
ScoobyNet General
52
20 October 2015 04:32 PM
Phil3822
General Technical
0
30 September 2015 06:29 PM
paddyscoob
General Technical
10
30 September 2015 03:51 PM



Quick Reply: Advice - VBS/VBSWG.aq@MM



All times are GMT +1. The time now is 10:32 PM.