Re: Win32.Sircam.Worm Alert.....

From: dzzie@yahoo.com
Date: 07/24/01


From: dzzie@yahoo.com
To: security-basics@securityfocus.com
Subject: Re: Win32.Sircam.Worm Alert.....
Message-Id: <20010724184526.SKJB5378.pop03-srv.alltel.net@quas>
Date: Tue, 24 Jul 2001 13:45:26 -0500


there also appears to be at least one variant i got that is not
detected by norton yet.

i made a quick program to extract the user file from
the virus, when it couldnt auto determine the file
type i took a closer look

it looks like this variant is a pack file with a bunch of exe's
i havent looked to close at it yet or extracted any of the programs

possibly a bug from multiple infections "piling" up the payload?

but even if it was just teh same payload over and over one of them
should have triggered norton i think

it arrived in the same Sircam fasion though so at least that is the
same.



Relevant Pages

  • Re: Importing GAL
    ... Instead of limiting it to 2000 entries, I would like to extract "US" as ... > Const CdoAddressListGAL = 0 ... > Dim X As Variant, CDOList As Variant, TitleList As Variant, ... > Dim objSession As MAPI.Session, oFolder As MAPI.AddressList, ...
    (microsoft.public.excel.misc)
  • Re: clean up a field in table
    ... disregard first sentence - i am importing data into ACCESS 2003 not EXCHANGE ... > worse writes a book in one but leaves the other memofield empty. ... > before memofield begins - that way data will extract fine. ... > Public Function ExtractDetail(textLine As Variant, ...
    (microsoft.public.access.modulesdaovba)
  • Re: clean up a field in table
    ... > between the last single fieldAND vbcrlf at the START ... > My database is ready to go EXCEPT these dreaded memo fields. ... > right before memofield begins - that way data will extract fine. ... > Public Function ExtractDetail(textLine As Variant, ...
    (microsoft.public.access.modulesdaovba)
  • Re: clean up a field in table
    ... kicker - Not only do they move it to the end, but it also inserts vbcrlf ... worse writes a book in one but leaves the other memofield empty. ... before memofield begins - that way data will extract fine. ... Public Function ExtractDetail(textLine As Variant, ...
    (microsoft.public.access.modulesdaovba)
  • Re: Antivirus-like background applications and their overhead
    ... AND it has next to zero false positives each ... But your question is not about Norton, it is about a view on the ... payload of antivirus-like products. ...
    (microsoft.public.windowsxp.general)