Welcome To P8ntballer.com
The Home Of European Paintball
Sign Up & Join In

Worm Alert!

Smally85

Super5ives 2010 Champions
I've just managed to find and delete a worm on my hard disk. It was called 'Hello Kitty' and it was in plain sight in my 'Windows' folder. Beware. My firewall didn't detect it and it took my virus checker a while to notice it. Don't think too much damage was done. Just thought I'd warn you. May have got it through Kazaa.
 

Philip

Whip it out..
Mar 24, 2002
3,040
12
63
Ellesmere Port
Did it look anything like:

This message was created automatically by mail delivery software (Exim).

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

info@planeteclipse.com
This message has been rejected because it has
an apparently executable attachment kitty.exe
This is a virus prevention measure.
If you meant to send this file then please
package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------
------ The body of the message is 122040 characters long; only the first
------ 65536 or so are included here.

Return-path: <admin@ice-network.co.uk>
Received: from modem-3888.cougar.dialup.pol.co.uk ([217.134.239.48] helo=Tzl)
by mail18.svr.pol.co.uk with smtp (Exim 3.35 #1)
id 188Nh3-00020S-00
for info@planeteclipse.com; Sun, 03 Nov 2002 16:33:45 +0000
From: admin <admin@ice-network.co.uk>
To: info@planeteclipse.com
Subject: A special humour game
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Gbl04Qg3s6RKnnbM00EZ08j92wOvQ756rq
Message-Id: <E188Nh3-00020S-00.2002-11-03-16-33-45@mail18.svr.pol.co.uk>
Date: Sun, 03 Nov 2002 16:33:45 +0000

--Gbl04Qg3s6RKnnbM00EZ08j92wOvQ756rq
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD></HEAD><BODY>

<FONT>Hello,This is a humour game<br>
This game is my first work.<br>
You're the first player.<br>
I wish you would like it.</FONT></BODY></HTML>

--Gbl04Qg3s6RKnnbM00EZ08j92wOvQ756rq
Content-Type: application/octet-stream;
name=kitty.exe
Content-Transfer-Encoding: base64
Content-ID: <We17V54o1MPb>
 

Smally85

Super5ives 2010 Champions
I don't know,

don't think so, I just deleted it as soon as I could. It dosen't look like that, I think it was simply going around my system trying to infect as many files as possible, it wasn't even doing anything that damaging that I can see. Just keep getting warnings from my virus checker 'file....... has been infected by Hello Kitty' and then it said it was a worm.