Important - sonicblue.com and riohome.com - 18/09/2001 07:37
Our UK sysadmin people are waking up the US guys as I type, so this should get fixed soon.
Rob
Edited by Drakino on 18/09/01 07:35 PM.
In reply to:
More information on the new worm has been posted at the Network Associates (McAffe) site:
http://vil.nai.com/vil/virusSummary.asp?virus_k=99209
One of the things that the virus apparently does is to alter your SYSTEM.INI file. The line:
Shell=explorer.exe
Gets changed to
Shell=explorer.exe load.exe -dontrunold
If your machine appears to be behaving strangely or slowly, please check your system.ini file. If you find this alteration, please let me know so that I can gauge if there is any possible threat to our internal network.
Note that the Shell= line might not exist on some NT/2K systems. This is OK. It's only the altered version that indicates the presence of the virus.