[Mono-list] First .NET virus discovered

Eric Chien ecchien@yahoo.com
Thu, 10 Jan 2002 07:10:06 -0800 (PST)


Hello,

If you want a little bit more information try:
http://securityresponse.symantec.com/avcenter/venc/data/w32.donut.html

While this is the first virus to specifically attempt
to identify and infect CLR files, it isn't really an
MSIL virus.  That is (as can be seen by the prefix
W32), it is really just a Win32 ASM virus which copies
a block of MSIL (and metadata) code into the CLR file.

The MSIL itself is not the replication routine at all.

...Eric

--- Dan Lewis <dihlewis@yahoo.co.uk> wrote:
> Well it had to happen sooner or later...
> 
> http://vil.mcafee.com/dispVirus.asp?virus_k=99300&
> 
> Not much information on how it works, yet.
> 
> Dan.
> 
> 
>
_________________________________________________________
> Do You Yahoo!?
> Get your free @yahoo.com address at
> http://mail.yahoo.com
> 
> 
> _______________________________________________
> Mono-list maillist  -  Mono-list@ximian.com
> http://lists.ximian.com/mailman/listinfo/mono-list


__________________________________________________
Do You Yahoo!?
Send FREE video emails in Yahoo! Mail!
http://promo.yahoo.com/videomail/