New virus (14-12-2000) TROJ_HYBRIS.B
It arrives as an attachment called blancheneige.exe or Snowwhite.exe or sexynain.scr or blanche.scr or nains.exe and more..with the subject of the e-mail marked "Hahaha" . When you try to open it notting happen and the malicious code accesses the Microsoft Outlook address book and sends a copy of itself to every entry. DO NOT OPEN the attachment !
If you have the virus click here for the disinfection software in dos
or visit these sites for help

* Information on TROJ_HYBRIS.B
McAfee AntiVirus

* Norton AntiVirus.
* AntiViral Toolkit Pro
* Anyware AntiVirus
* Inoculate IT
* Norman Data Defense Systems
* Panda AntiVirus
* PC-cillin
* Quick Heal

 


Virus (10-06-2000) 'GIRLS"EXE'
It arrives as an attachment called girls.exe with the subject of the e-mail marked "Choose your poison" and empty in the message area. When you try to open it you get a message something like "C:/windows/temp cannot execute this file" and the malicious code accesses the Microsoft Outlook address book and sends a copy of itself to every entry. DO NOT OPEN the attachment called GIRLS.EXE .... This virus is still unknown !
If you have the virus visit these sites for help

* McAfee AntiVirus
* Norton AntiVirus.
* AntiViral Toolkit Pro
* Anyware AntiVirus
* Inoculate IT
* Norman Data Defense Systems
* Panda AntiVirus
* PC-cillin
* Quick Heal

 

Worms and Trojan Horses

A little like viruses, they have the sole goal of colonizing the planet. Only the tactic is different:- they do not attach to a precise target, rather they travel only on the internet, by e-mail, IRC, or anwhere that permits the transfer of data. In its widest meaning, a worm is a program that is given to you via e-mail. If you start it, it reads your address book (there is one in every e-mail program) and writes everyone, adjoining a copy of its program.
Consequences of the removal:- An infected computer usually (in principal) has one copy of the worm program. In Windows, it is often found in the Windows directory or Windows\System. Removal is usually simple to do manually or with the script below which removes the worm. Anti-virus use the prefix or suffix of the worm to distinguis the viruses.

Many of our member got the WScript/KakWorm. Kak is a none malicious worm that give you a anti-Microsoft message on the first of the month, this worm spreads using Microsoft Outlook Express 5. The worm attaches itself to all outgoing messages via the Signature feature of Outlook Express. Signatures allow one to automatically append information at the end of all outgoing messages. The worm utilizes a known Microsoft Outlook Express security hole so that a viral file is created on the system without having to run any attachment. Simply reading the received email message will cause the virus to be placed on the system. Microsoft has patched this security hole already.
The patch is available from Microsoft's website.(see below in protection) If you have a patched version of Outlook Express, this worm will not affect them.

Infection Removal Scripts

These scipts use Windows Scripting Host (WSH), which equip Windows 98. Under Windows 95, WSH is installed with Internet Explorer 5.

Worm Name
Click for a description
Alias Script
Dowload
Size Date Protection
VBS.LoveLetter I love you lover-killer.vbs 7 Ko 5 May 2000  
WScript/KakWorm Kak suppkak.js
in french
5 Ko 18 February 2000 Download the scipt available at Microsoft
Win32/PrettyPark PrettyPark PrettyPark cleaner 725 Kb 16 March 2000  
Win32/Ska Happy99 rmska.zip 17 Kb 21 March 2000  

These scripts remove only the worms, as they just ad a few files on your disk. For "normal" viruses, which actually modify the content of existing files, you must use a real anti-virus such as Norton Anti-Virus.