Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 28th, 2002, 06:11 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default New Virus --> VBS/Britney-A

Check out the details at silicon.com here:
http://www.silicon.com/public/door?R...&REQINT1=51686
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #2  
Old February 28th, 2002, 06:12 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: New Virus --> VBS/Britney-A

Quote from the article:
Quote:
Worm Warning: Britney pics carry a nasty surprise

A virus named after teen pop sensation Britney Spears has been discovered by anti-virus experts.

The worm, called VBS/Britney-A spreads via both Microsoft Outlook and Internet Relay Chat (IRC) networks and it emails itself to all addresses in the Outlook address list.

The virus arrives with a subject line "RE: Britney Pics" and has the following body text: "Take a look at these pics..." The worm requires ActiveX to be enabled for the VBS script to run so it tries to get the user to enable it with a message: "Enable ActiveX To See Britny Pictures".
Virus experts say despite the appealing nature of its purported contents, it's unlikely to cause any serious damage to corporate networks.

Sophos anti-virus said: "The worm looks at different directories on C:, D:, and E: for a file called MIRC.INI. If it is found, the worm drops a file called SCRIPT.INI which will help it spread via IRC. It also drops a copy of itself in the Windows directory as the file BRITNEY.CHM."

Graham Cluley, technical specialist at Sophos said Britney is not a serious outbreak: "We haven't seen it in the wild yet, but obviously a virus named Britney will attract a degree of attention so we are going to alert our customers."



__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #3  
Old February 28th, 2002, 06:15 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: New Virus --> VBS/Britney-A

In other recent news, virus researchers indicate it MAY ACTUALLY be a BAD idea to open e-mails claiming "open me - free pictures if you enable a very unsafe part of your operating system". *
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #4  
Old February 28th, 2002, 06:17 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: New Virus --> VBS/Britney-A

Sophos virus article:

(from here: http://www.sophos.com/virusinfo/articles/britney.html

Quote:
Britney fears: virus could drive you crazy, warns Sophos

Sophos, a world leader in corporate anti-virus protection, is today warning users about a new worm that can spread by clicking on an attachment pretending to be photographs of teen pop princess Britney Spears.

VBS/Britney-A arrives in the victim's inbox with the subject line "RE:Britney Pics", body text "Take a look at these pics..." and attachment "BRITNEY.CHM." When executed, the file displays a message similar to "Enable ActiveX To See Britny Pictures" (sic) before infecting the hard drive and sending itself to all addresses in the Outlook address book. The worm also attempts to distribute itself via Internet Relay Chat.

"Britney has joined the ranks of glamorous, highly attractive people to have viruses written about them," said Graham Cluley, senior technology consultant at Sophos Anti-Virus. "Previous stars to receive this treatment include Anna Kournikova and Jennifer Lopez."

"Britney is a very popular celebrity and many computer users - from teenyboppers to fascinated fathers - would be interested in seeing photos of her," Cluley continued. "Users should remember basic safe computing rules and not be coaxed into opening any unsolicited email attachments."

As yet, Sophos has only received one report of this worm in the wild, but in view of Britney's fame, the company is nonetheless encouraging users to be vigilant.


__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #5  
Old February 28th, 2002, 06:18 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: New Virus --> VBS/Britney-A

Sophos virus bulletin:

Quote:
VBS/Britney-A
Aliases
VBS/Breetnee, VBS/BritneyPic@MM, worm/BritneyPic

Type
Visual Basic Script worm

Detection
A virus identity file (IDE) file which provides protection is available now from the Latest virus identities section, and will be incorporated into the April 2002 (3.56) release of Sophos Anti-Virus.

At the time of writing Sophos has received just one report of this worm from the wild.


Description
VBS/Britney-A is a mass-mailing worm which spreads via both Microsoft Outlook and IRC networks. The worm copies itself to BRITNEY.CHM in the Windows folder and then emails itself to all addresses in the Outlook address list. The emails will have the following characteristics:

Subject Line: RE: Britney Pics
Body Text: Take a look at these pics ...
Attachment: BRITNEY.CHM

http://www.sophos.com/images/viruses...ey-a-2_450.gif

The worm requires ActiveX to be enabled for the VBS to run and so it prompts the user to enable ActiveX with the message "Enable ActiveX To See Britny Pictures".

http://www.sophos.com/images/viruses...ey-a-1_450.gif

VBS/Britney-A searches the C:, D: and E: drives for the presence of a file called MIRC.INI. If it finds a file of this name then the worm creates a SCRIPT.INI file which will then attempt to send copies of the files to other IRC users.

SCRIPT.INI will be detected by Sophos Anti-Virus as mIRC/Simp-Fam.


__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #6  
Old February 28th, 2002, 06:20 PM
FanJ
 
Posts: n/a
Default VBS/Britney-A

Name: VBS/Britney-A
Aliases: VBS/Breetnee, VBS/BritneyPic@MM, worm/BritneyPic
Type: Visual Basic Script worm
Date: 28 February 2002


At the time of writing Sophos has received just one report of this worm from the wild.

Description:

VBS/Britney-A is a mass-mailing worm which spreads via both Microsoft Outlook and IRC networks. It copies itself to BRITNEY.CHM in the Windows folder and then emails itself to all *addresses in the Outlook address list. The emails will have the following characteristics:

Subject Line: RE: Britney Pics
Body Text: Take a look at these pics ...
Attachment: BRITNEY.CHM

The worm requires ActiveX to be enabled for the VBS to run and so it prompts the user to enable ActiveX with the message "Enable ActiveX To See Britny Pictures".

VBS/Britney-A searches the C:, D: and E: drives for the presence of a file called MIRC.INI. If it finds a file of this name then the worm creates a SCRIPT.INI file which will then attempt to send copies of the files to other IRC users.

SCRIPT.INI will be detected by Sophos Anti-Virus as
mIRC/Simp-Fam.


Read the analysis at
http://www.sophos.com/virusinfo/analyses/vbsbritneya.html

  #7  
Old February 28th, 2002, 06:20 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: New Virus --> VBS/Britney-A

Wow...same post, same time.

Scary...
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #8  
Old February 28th, 2002, 06:24 PM
UNICRON's Avatar
UNICRON UNICRON is offline
Administrator
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: New Virus --> VBS/Britney-A

Well I sure feel educated after reading all that! A simple link may have sufficed but nevertheless, as a "fascinated father" myself, I'm glad to have this advanced warning.
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #9  
Old February 28th, 2002, 06:25 PM
FanJ
 
Posts: n/a
Default Re: New Virus --> VBS/Britney-A

Hey JC,

Yep, same time *
I just wanted to delete my posting after I saw yours, but was too late *
Thanks for posting Javacool *
  #10  
Old February 28th, 2002, 09:34 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,139
Default Re: New Virus --> VBS/Britney-A

My friend got it!!!! He didn't open it (lucky he, ha). What concerns me is the fact that NOD32 doesn’t detect it (He has NOD32 for AV protection).

I told him that Eest will probably have update tomorrow or day after tomorrow... Isn't little late *

Technodrome


__________________
Classic Trance Hit: PPK - Resurrection
  #11  
Old February 28th, 2002, 09:39 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: New Virus --> VBS/Britney-A

Hi TD,

Quote:
What concerns me is the fact that NOD32 doesn't detect it

Eset/Nod32 does have a copy.

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #12  
Old March 1st, 2002, 05:29 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default Re: New Virus --> VBS/Britney-A

My system is, and always has been, completely, 100% immune from viruses like the above. *What software do I use to gain this protection? *None. *I simply couldn't give a sh*t about Britney so I'd never get past the subject line.
__________________
My Novel
  #13  
Old March 1st, 2002, 07:31 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: New Virus --> VBS/Britney-A

Hi all,
Excuse my ignorance, as i did not follow the developments of NOD32, which i thought to be about the best AV program, so why would it be supposed to catch worms?
As it's a VBS i'd suppose it will be stopped from running by your worm or vbs blocker/protection as well.
Just a question, not interested in Britney either.
__________________
Jooske
"o_o"
  #14  
Old March 1st, 2002, 03:07 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,139
Default Re: New Virus --> VBS/Britney-A

Quote:
Hi TD,


Eset/Nod32 does have a copy.

regards.

paul


Hi Paul

I think it's covered by today’s release. (As I thought) *

Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:12 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums