du skal fjerene alle spor af virussen! d.v.s
www.myparty.yahoo.com (som er en FIL!! ikke en URL ) og msstask.exe.
W32/MyParty-A
Aliases
W32/Myparty@mm, W32.Myparty@mm
Type
Win32 worm
Detection
A virus identity file (IDE) file which provides protection is available now from the
Latest virus identities section, and will be incorporated into the March 2002
(3.55) release of Sophos Anti-Virus.
Sophos has received several reports of this worm from the wild.
Description
W32/MyParty-A is a Windows 32 email-aware worm which arrives as an email
with the following characteristics:
Subject: new photos from my party!
Message text:
Hello!
My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!
Attached filename:
www.myparty.yahoo.com Some people may be fooled into believing the attached file is a link to a
website.
If the attached file is executed between 25 January and 29 January 2002
(inclusive) the worm sends a copy of itself to everybody in the Windows
Address book (except the current user) using a built in SMTP engine.
It gets the SMTP server information from the registry key:
HKCU\Software\Microsoft\Internet Account Manager\Accounts\00000001
The worm also sends an email to napster@gala.net to track its spread.
In addition the worm drops a copy of the Trojan Troj/Msstake-A in the user's
startup directory. The Trojan is contained in a file named msstask.exe.