Author Topic: New Email VIRUS ALERT!!!  (Read 7378 times)

0 Members and 1 Guest are viewing this topic.


  • Guest
New Email VIRUS ALERT!!!
« on: August 02, 2003, 02:30:21 PM »
I seen it From also i just got a email from my ISP about it..

Dear Mediacom Subscriber,
A new virus is infecting computers that are connected to the
internet.  Mediacom wants to protect you, the subscriber,
from encountering any problems that this virus can cause to
your computer.  Mediacom is very concerned with keeping you, the
subscriber, aware of when a new a virus has been launched and how
you can protect your computer from being infected.  Please, take a
moment to learn how to protect your computer from infection.

General Virus Info:

1. Spreads via Email
2. The Subject line of the email will read "your account %s''
3. The email will have an attachment called ""

For Virus Details visit this link:

Protect Your Computer With These Easy To Follow Steps:

1. If you have received an email with the above characteristics DELETE it
immediately and then run a Virus Scan.
If you do not have a Virus Scanner and would like to have one it is
Mediacom's RECOMMENDATION that you go to this link,
download an antivirus program, and install it.  After installation is
complete be sure to run a FULL scan of your computer's files.
2. Please, visit this link:
and follow the directions exactly.

Mediacom urges every subscriber to take all the necessary actions
to prevent the spread of viruses.  Please, keep your antivirus program
up-to-date!  Check for updates on a weekly basis!

Thank you for your attention,

Mediacom Online Technical Support


  • Guest
Re:New Email VIRUS ALERT!!!
« Reply #1 on: August 02, 2003, 11:54:46 PM »
Sounds serious...I'm sure AVAST vendors have already found a solution :).

is a worm that spreads via email. It informs the user that his/her email address will expire soon and tries to convince him/her to open and run the attachment.
It comes with the following subject line:
your account [random letters]
The message contains the following text:
Hello there, I would like to inform you about important information
regarding your email address. This email address will be expiring.
Please read attachment for details.
Best regards, Administrator

The attached file is and it is an archive which contains HTML file named Message.htm which contains the executable file and the script to run it.

If executed, the worm copies itself to the following files
C:\Windows\exe.tmp (copy of message.htm)
C:\Windows\zip.tmp (copy of

It adds the following key to the registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\VideoDriver =C:\Windows\videodrv.exe

avast! with VPS file dated on or after 2nd August 2003 is able to detect this worm.

« Last Edit: August 03, 2003, 12:00:29 AM by Waldo »