New virus: Naked Wife (NOT KIDDING) - Off-Road Forums & Discussion Groups
Jeep-Short Wheelbase All discussion of short wheelbase Jeeps: CJ, TJ, YJ and JK

 
LinkBack Thread Tools Display Modes
post #1 of (permalink) Old 03-06-2001, 07:41 PM
**DONOTDELETE**
Guest
 
Posts: n/a
New virus: Naked Wife (NOT KIDDING)

From Symantec:
[email protected]
Discovered on: March 6, 2001
Last Updated on: March 6, 2001 at 03:20:12 PM PST

[email protected] is a mass mailing worm that disguises itself as flash movie. The attachment is named NakedWife.exe. This worm, after it has attempted to email everyone in the Microsoft Outlook address book, will attempt to delete several system files. This will leave the system unusable, requiring a re-install.

NOTE: This worm was previously detected as [email protected]


Category: Trojan Horse, Worm

Virus Definitions: March 6, 2001

Threat Assessment:


Wild:
Medium Damage:
High Distribution:
Medium


Wild:

Number of infections: 50 - 999
Number of sites: 3 - 9
Geographical distribution: Medium
Threat containment: Moderate
Damage:

Payload Trigger: Every time that the worm is executed
Payload:
Deletes files: Attempts to delete several files from the \Windows and \Windows\System folders
Distribution:

Subject of email: Fw: Naked Wife
Name of attachment: NakedWife.exe
Size of attachment: 73,728 bytes

Technical description:

When first executed, [email protected] displays a window that appears to be loading a Flash movie. The window will display the words "JibJab." If you click the "Help > About Windows" menu, the following message will be displayed:

You're are now F***ED. (c) 2001 by BGK (Bill Gates Killer)

In the background, while the flash movie is "loading", this worm attempts to send itself to everyone in the Microsoft Outlook address book. The message that this worm sends is as follows:

Subject:

Naked Wife

Message:

My wife never look like that! ;-)
Best Regards,
[UserName]

where [UserName] is the user name that was used when registering Microsoft Outlook.

After the worm has attempted to mass-mail itself, it will attempt to delete all files from the \Windows and \Windows\System folders that have any of the following extensions:


.ini
.log
.dll
.exe
.com
.bmp

If this payload is executed, the only way to get the system back to an operational state is to reinstall it.

SARC has also received several corrupted samples. The corrupted variant of this worm will be detected as W32.Naked.dam. The corrupted variant cannot cause any damage to the system. However, if found, it should be deleted.


Removal instructions:

To remove this worm:

1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and then run a full system scan, making sure that NAV is set to scan all files.
3. Delete any files detected as [email protected] or W32.Naked.dam.

If the worm has been executed, it is very likely that you will have to reinstall Windows.




Write-up by: Andre Post and Neal Hindocha




Brad
ORC Land Use Section Editor
http://www.off-road.com/land
Vice-Pres. Rock Garden 4 Wheelers, Farmington, NM
http://rockgarden.rockcrawler.com
Sponsored Links
Advertisement
 
post #2 of (permalink) Old 03-06-2001, 08:19 PM
I Might Just Know What I'm Talking About
 
Join Date: Jul 2000
Location: Westen Canada
Posts: 1,838
Thanks: 0
Thanked 0 Times in 0 Posts
 
Re: New virus: Naked Wife (NOT KIDDING)

Good tip Brad . Just another reminder that EVERYONE should be updating thier Virus definitions REGULARLY .

<font color=red>
1979 CJ5
Almost finished [img]/wwwthreads_images/icons/tongue.gif[/img] ( Ya Right ! )</font color=red>

<font color=black>When is Summer going to be here? [img]/wwwthreads_images/icons/tongue.gif[/img] </font color=black>
Jeepzilla is offline  
post #3 of (permalink) Old 03-06-2001, 10:08 PM
Can't Get Enough
 
Join Date: May 2000
Location: Bastrop, Texas
Posts: 1,445
Thanks: 0
Thanked 0 Times in 0 Posts
 
Re: New virus: Naked Wife (NOT KIDDING)

Yep, got that one at work today. Fortunately I figured it was a virus and deleted it, unfortunately one of my co-workers couldn't resist the naked wife connotation and opened it, thus spewing emails out to everyone in his address book and locking up his machine before he could realize what happened. I was fortunate because I didn't recognize the sender, and the topic just rang my warning bell, so I deleted. I never open email with attachments from people I don't know.

82 Scrambler, 360, T5, D300, 4" SUA, AMC20 w/rear discs and Somers Bros 1 piece axle shafts, D30, 3:73's, and lockers.
Smithville, Texas
Member TX4X4 Cyber Club
kerryp is offline  
Sponsored Links
Advertisement
 
Reply

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the Off-Road Forums & Discussion Groups forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address
Please enter a valid email address for yourself.

Email Address:
OR

Log-in










Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode



Posting Rules  
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

 
For the best viewing experience please update your browser to Google Chrome