Meet Gigger, the HDD Formatting Worm  | | |
January 12th, 2002, 03:30 PM
|
#1 (permalink)
| | Misanthropic
Join Date: Oct 2001 Location: Bay Area, California
Posts: 19,305
| Meet Gigger, the HDD Formatting Worm
ohh great!! Another worm ... It even goes through Outlook express? I would NEVER believe that!
Thanks for the heads up. |
| |
January 12th, 2002, 06:09 PM
|
#2 (permalink)
| | The Mad Redhatter
Join Date: Oct 2001 Location: NJ
Posts: 3,552
|
ah, the script kiddies are yet again at work!
anyone who uses outlook should visit the office updatre website and download all th epatches. there's a little known patch there that fixes most of the outlook vunerabilites that these viruses need to spread... |
| |
January 12th, 2002, 07:59 PM
|
#3 (permalink)
| | Senior Member
Join Date: Oct 2001 Location: New Jersey
Posts: 707
|
The link to the article is not working for me. Says file not found.
__________________
"It's only after we've lost everything that we're free to do anything" www.rjponzio.com |
| |
January 12th, 2002, 08:03 PM
|
#4 (permalink)
| | Senior Member
Join Date: Oct 2001 Location: Alberta, Canada
Posts: 563
|
ya, theres a typo in it! After you click it take the <br> off the end and try again!
cya! |
| |
January 12th, 2002, 08:35 PM
|
#5 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Cincinnati Area
Posts: 1,761
|
Someone please tell me..WHY use outlook express? I hate that program and all these recent virii? Seems we can blame M$'s stupidity for them since they invite 'script kiddies' to use flaws built into software. Man...people just need Eudora or something. Netscape Mail even. DUMP OUTLOOK
Paul |
| |
January 12th, 2002, 08:45 PM
|
#6 (permalink)
| | The Mad Redhatter
Join Date: Oct 2001 Location: NJ
Posts: 3,552
|
i happen to like regular outlook... it's still the most powerful and easy to use emailer there is...
once you patch it it's relatively stable and safe... and the only people who realistically get viruses are those who are too stupid to go ahead and blindly open every email they get.
enough with the ms hatred already. |
| |
January 12th, 2002, 10:35 PM
|
#7 (permalink)
| | Senior Member
Join Date: Oct 2001 Location: New Jersey
Posts: 707
|
I have to agree with you there Storm, the problem most the time is not in the program but in the user. There are certain people in my office that routinly get infected by viruses via e-mail while I dont get infected by them ( other than one that got me from an infected web server ).
Keep your programs/virus files up to date
edit:
Oh yeah, the link is working great now BTW  |
| |
January 14th, 2002, 09:50 AM
|
#8 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Columbus, OH
Posts: 1,376
|
I just read the article at The Register. You really would have to be a moron to get infected by this thing.
"Oh, how nice and considerate of MS, I see they sent me antivirus updates. I dont know what antivirus is, but I suppose I better open this attachment."
Do ISPs really do nothing about this stuff? I thought they kept logs of everything everyone did? If that were true, it wouldnt be hard to find out who is sending out mass mailings. |
| |
January 14th, 2002, 10:29 AM
|
#9 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Dahlonega Ga
Posts: 8,106
|
This is the notice we got at work->> Do Not turn off your PC !
There is a new worm that has the potential to be very destructive. It will arrive as an attachment in an "htm" format. We have added filters to the border guards at this time. We will receive the new definitions and post them to our live update site when they are available. It does not appear to be spreading in the wild. JS.Gigger.A@mm JS.Gigger.A@mm is a worm written in JavaScript. It uses Microsoft Outlook and mIRC to spread. It attempts to delete all files on the computer and to format drive C if the computer is successfully restarted. JS.Gigger.A@mm arrives as an email message that has the following characteristics:
Subject: Outlook Express Update
Message: MSNSofware Co.
Attachment: Mmsn_offline.htm
If the worm is executed, it does the following:
It drops the following files:
C:\Bla.hta
C:\B.htm
C:\Windows\Samples\Wsh\Charts. js
C:\Windows\Help\Mmsn_offline.htm
It infects .html files.
It adds the line ECHO y|format c: to the Autoexec.bat file, so that if the computer is restarted, drive C is reformatted. |
| |
January 14th, 2002, 10:34 AM
|
#10 (permalink)
| | Senior Member
Join Date: Oct 2001 Location: New Jersey
Posts: 707
|
Ack! That sounds very bad indeed. Maybe I should give the same notice to the people that work here just incase.
(downloading latest virus files now)  |
| | | Thread Tools | Search this Thread | | | | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |