Re: readme.eml

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/18/04


Date: Wed, 18 Feb 2004 12:23:53 -0500

Go to McAfee (http://www.mcafee.com/myapps/mfs/default.asp) and/or Trend
(http://housecall.antivirus.com ) and perform an online scan of your platform.
Let's verify if you indeed have W32.Chir.B@mm

W32/Chir@MM - http://vil.nai.com/vil/content/v_99518.htm

Note:
"Additionally, the worm attempts to write base64-encoded copies of itself to all folders on
network drives, as the file: (computer name).eml. These encoded copies of the worm
are detected as W32/Chir.eml by the indicated DATs."

In addition:
If you post to UseNet with your TRUE, not a munged, email address then you have invited the
Swen Internet worm [aka; W32/Gibe-F] to visit you.

The Swen is news spelled backwards. The reason it is called this is because the Swen worm
harvests email addresses from UseNet News Groups. It has an engine that allows it to post
itself to UseNet News Groups and well as it has its own email engine. From the list of
email addresses that it has harvested, it will then email itself to those addresses.

Dave

"mike" <m i k e . b a r n e s @ verizon.net> wrote in message
news:11c8f01c3f641$b90a1a20$a101280a@phx.gbl...
| My system is pereated with a file named readme.eml which
| acording to MS is the result of a virus called
| W32.Chir.B@mm and I woild like to get rid of the virus and
| deleate the readme.eml files. Any suggestions?



Relevant Pages

  • Re: sysconf.exe
    ... It's a kwbot worm from Kazaa apparently ... McAfee Virus Scan Home Edition. ... >1) Disable System Restore ... >harvests email addresses from UseNet News Groups. ...
    (microsoft.public.scripting.virus.discussion)
  • Re: 1 week of searching FAQ for the answer to these two questions
    ... attachement if not patched so I can learn HOW THis happens. ... >| question in their section on Outlook and virus risk. ... >| worm, trojan) ... >harvests email addresses from UseNet News Groups. ...
    (microsoft.public.scripting.virus.discussion)
  • Re: 1 week of searching FAQ for the answer to these two questions
    ... >Many viruses, like the Swen Internet worm, use a MIME ... >|>| question in their section on Outlook and virus risk. ... >|>harvests email addresses from UseNet News Groups. ...
    (microsoft.public.scripting.virus.discussion)
  • Re: virus
    ... > You don't enough to munge you email address so the Swen Internet worm will ... > itself to UseNet News Groups as well as it has its own email engine. ... > | Ian Kenefick ...
    (microsoft.public.scripting.virus.discussion)
  • Re: 1 week of searching FAQ for the answer to these two questions
    ... | question in their section on Outlook and virus risk. ... | worm, trojan) ... itself to UseNet News Groups as well as it has its own email engine. ...
    (microsoft.public.scripting.virus.discussion)