
VBS/Anjulie worm
Information
about VBS/Anjulie worm:
VBS/Anjulie is a
Visual basic script worm uses Microsoft
outlook to spread and also drops the
deadly Win95/CIH virus. The email
message subject will be "Read the true
history on Angelina Julie " and the
attachment will be "AngelinaJulie.txt.vbs,
or T4UMHF5.VBS " and the message
body will be "Your life Your
work Your lovers ".
The VBS extension
will not appear if Windows Scripting Host
is installed. When you open the
attachment, it copies to windows temp as
T4UMHFS.VBS and also drops the file
ALE32.EXE. Then it opens the Microsoft
Outlook Address book and sends email to
all the addresses stored in that.
It also
creates a new key in the registry to load
automatically. Because of the mass
mailing routine there is a threat to down
e-mail servers. The CIH virus dropped by
this worm will attempt to damage hard
disk and mother board.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
\T4UMHF5=C:\WINDOWS\TEMP\T4UMHF5.VBS
Removing
Anjulie worm from your computer:
Fire has
incorporated VBS/Anjulie in virus
signature file, with the aim of helping
users affected by this script attack to
detect and eliminate it from their
systems. Fire anti-virus users can update
this signature file by using online
update facility.
To protect
your system against infection,
disable Windows Scripting Host by
following these steps: Click the Start
button, Settings, Control Panel, then
select Add/Remove Programs, then select
the Windows Setup tab, then double-click
Accessories, scroll down to Windows
Scripting Host, and uncheck the box. Save
changes and close the window.
You
can check the system manually.
VBS/Anjulie worm creates the file "T4UMHF5.VBS"
in the Windows Temp folder. The presence
of this file ensures you are infected
with this worm.
A
free download
of
FireLite
[ 1100KB
]
version is available to detect
all viruses. If you find any virus, use
registered windows version of Fire to
remove. To get the registered version of
Fire call us at 044-28170440 or
mail to service@fireav.com
or
purchase Fire online using
[Analysis:
Mr.Surend Raj, Mr.A.Xavier, Prognet
Technologies Pvt. Ltd, Mar. 2001]

|