
VBS/JOLIN - A NEW VB
SCRIPT WORM DETECTED
VBS/Jolin is an
intended VB script worm uses Microsoft
outlook and mIRC to spread. The worm
contains bugs in its code, so it won't
work properly. The email message subject
will be "FW: Check this
out... " and the
attachment will be "!!jolin_caught_naked!!!!.jpg.vbs
"
and the
message body will be "This was the
first naked picture taken by a Taiwan
singer! Jolin... please don't get over
steam by staring at the picture! keke~
".
The VBS extension
will not appear if Windows Scripting Host
is installed. When you open the
attachment, it will try to copy in
"%WINDIR%\JOLIN_NAKED_SECRET_FOLDER\
folder,
Windows folder and Windows system folder.
It also try to delete all *.DLL, *.EXE
and *.INF files in the Windows system
folder. Then it will try to open the
Microsoft Outlook Address book and email
to all the addresses stored in that.
How can I
protect my system?
Fire has
incorporated VBS/Jolin in virus signature
file, with the aim of helping users
affected by this script attack to detect
and eliminate it from their systems. Fire
anti-virus users can update this
signature file by using online
update facility.
To protect
your system against infection,
disable Windows Scripting Host by
following these steps: Click the Start
button, Settings, Control Panel, then
select Add/Remove Programs, then select
the Windows Setup tab, then double-click
Accessories, scroll down to Windows
Scripting Host, and uncheck the box. Save
changes and close the window.
How can I find
my system is infected?
A
free download
of
FireLite
[ 1100KB
]
version is available to detect
all viruses. If you find any virus, use
registered windows version of Fire to
remove. To get the registered version of
Fire call us at 044-28170440 or
mail to service@fireav.com
or
purchase Fire online using
[Analysis:
Mr.Ramesh, Mr.A.Xavier, Prognet
Technologies Pvt. Ltd, Jul. 2001]

|