View Full Version : VBS_SLUG.worm?
Kubie
12-03-2002, 10:25 AM
Anybody seen this one? I can't find it in any data basses.
Carl
morriswindgate
12-03-2002, 10:37 AM
It is so new that symantec lists it but there is no additional info.
Did you get it?
Statica
12-03-2002, 10:38 AM
Where did you find it?
Kubie
12-03-2002, 10:43 AM
I ran PC-Cillin yesterday and it was clear. This morning, there was an update from PCC. After I loaded the files, I ran a scan and thats what came up. It was found in C:\Program Files and was quarantined.
Also it there was a file Eudora.Align listed and quarantined.
Carl
Kubie
12-03-2002, 08:41 PM
Correction:
The name quarantined is VBS_SLUG.B
So far nothing at Trend, but I'm gonna keep a close eye out.
Carl
kittyfire
12-04-2002, 06:59 PM
:: perks:: Let's take it apart and see how it works
Kubie
12-04-2002, 08:00 PM
kittyfire,
My thoughts would be that since you have all the software experience, I could send it to you and you could dissect it it and let us know.:eek:
Carl
kittyfire
12-04-2002, 08:52 PM
::searching for her old copy of bubblechamber::
Send it over... ::laughs:: kittyfire@bellsouth.net
Black Ice
12-04-2002, 10:03 PM
kittyfire where did you get bubblechamber at .I have a lot of tools but have never herd of that one. does it make it a non exe so you can open it.
kittyfire
12-04-2002, 10:14 PM
Decompiler. ::nodnodnods:: And I got it by skittering along under someone's feet as they were taking classes on it. ::grins:: I got this thing for protecting people. My best success story ever was catching someone while they were hacking someone else. Had some little girl scared because he said if she IMed anyone or didn't keep typing he'd erase her hard drive and crash her computer. Her mother was busy calling for help. Imagine his surprise when I popped up on his screen with "You're real good at scaring little girls, let's see what you can do with a woman." lol@me. I got righteous indignation down to an art.
Kubie
12-04-2002, 10:28 PM
kittyfire,
I submitted the virus name to Trend's submission site and recieved an email stating that this one would take some research.
I had told them that their anti-virus had caught it.
Carl
Black Ice
12-04-2002, 10:39 PM
That's what I like to hear . At least you're on the good side of things. Me I just like to know how they work so I can have a better under standing of how to protect my self and teach my kids what not to do and what to look out for and also how to deal with it. But I still have a lot to learn my self.
kittyfire
12-05-2002, 01:47 PM
I'm no hacker by any stretch of the imagination. This guy was just arrogant enough to be stupid and leave a trail a mile wide that even I could follow... and so I did. :: beams:: There's hackers and then there's hacker vigilantes and I know what side of the fence I'm on. And you're right... the only way to beat it is to understand it.
LoveJones
12-07-2002, 02:29 AM
DeCompiler for which languages?
You will have zero luck for any C-based language, or Java if they have used an obstacator.
Interesting things though =)
Blakhart
12-09-2002, 01:05 AM
Kittyfire, you rock.
ZYFER
12-09-2002, 03:10 AM
Go Kitty!! W00t!!
Kubie
12-09-2002, 08:21 AM
Here is the answer from Trend-Micro:
Thank you for contacting TrendLabs HQ.
We have checked the file you have sent
20021203.upg 21 bytes
Based on our tests, the file contains nothing more than the string 20021203,0623,2,1. This string is not executable and probably provides the date after a certain action has been performed.
With regards to your query about VBS_SLUG.B, we already posted our virus report for this virus.
VBS_SLUG.B is an encrypted malware written in Visual Basic Script that infects HTM, HTML, HTT, and VBS files. It has a destructive payload that deletes all files in the Windows directory, formats the hard drive, and crashes the system. It drops an unencrypted copy of itself that we can detect as VBS_SLUG.A. Both malwares has the capability to spread through mIRC channels.
The information regarding both variants can be viewed at http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=VBS_SLUG.A and http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=VBS_SLUG.B
The said sites also contain removal instructions for these malwares.
Our latest Control Patch (408 version 26) can also detect both variants. This Control Patch can be downloaded at http://www.antivirus.com/download/pattern_cpr.asp
Carl
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.