r-caldas  

r-caldas: Nuevo bicho - BADTRANS.B (fwd)

Pijume Diwesi
Wed, 28 Nov 2001 12:08:31 -0800


Aunque no muy virulento, SI es bastante molesto pues aparece en la pantalla
del computador una y otra vez! Tomen nota del mismo.
Mas informacion en:
        http:[EMAIL PROTECTED]

En dicho URL se incluye tambien informacion de como limpiarlo en caso que
alguno ya haya sido contaminado.
                                  Saludos,  Nestor Raul
 
---------- Forwarded message ----------
Date: Tue, 27 Nov 2001 13:35:00 -0600
From: USMMAIL <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: New Virus Reported - BADTRANS.B
===========================================================================
W32.Badtrans.B@mm
Discovered on: November 24, 2001
Last Updated on: November 26, 2001 at 12:46:58 PM PST

W32.Badtrans.B@mm is a MAPI worm that emails itself out as one of several 
different file names. This worm also creates a file in the \Windows\System 
directory which uses functions from this file to log keystrokes, thereby
collecting password information.

Damage:

    * Payload:
          * Large scale e-mailing: Uses MAPI commands to send email.
          * Compromises security settings: Installs keystroke logging 
            Trojan horse.

Technical description:
This worm arrives as an email with one of several attachment names and a 
combination of two appended extensions.

The list of possible file names is:
HUMOR
DOCS
S3MSONG
ME_NUDE
CARD
SEARCHURL
YOU_ARE_FAT!
NEWS_DOC
IMAGES
PICS

The first extension that is appended to the file name is one of the following:
.DOC
.MP3
.ZIP

The second extension that is appended to the file name is one of the following:
.pif
.scr

The resulting file name would look something like this:
CARD.DOC.PIF
NEWS_DOC.MP3.SCR

For more information on this virus, visit USM's Antivirus Home Page at:
http://antivirus.usm.edu
===========================================================================

==============================================================
Guayabo, la Lista, en donde si te descuidas, te cambian hasta el marco conceptual.

==^================================================================
This email was sent to: [EMAIL PROTECTED]

EASY UNSUBSCRIBE click here: http://topica.com/u/?bUrBVZ.bUFzzs
Or send an email to: [EMAIL PROTECTED]

T O P I C A -- Register now to manage your mail!
http://www.topica.com/partner/tag02/register
==^================================================================


 =============================================================================
 Si necesita retirarse de la lista envie un mensaje a:
                     [EMAIL PROTECTED]
 con una unica linea :
     unsubscribe r-caldas
 Para inscribirse en la lista envie un mensaje a [EMAIL PROTECTED]
 con una unica linea :
     subscribe r-caldas
Los mensajes que circulan en la lista los puede consultar en :
http://www.mail-archive.com/r-caldas@colciencias.gov.co
  • r-caldas: Nuevo bicho - BADTRANS.B (fwd) Pijume Diwesi