Yeah, it's going around today. I've gotten a bunch, too. It appears that Symantec has not yet updated their definitions to catch this.
For what it's worth, this particular strand installs two files on your PC: windll.exe and windirect.exe. Both are Back Orifice type trojan tools that download remote code after infection. The remote code is an SMPT engine that the virus uses to spread the e-mails to other hosts through address in your contact list. Eric Fretz L-3 Communications ComCept Division 2800 Discovery Blvd. Rockwall, TX 75032 tel: 972.772.7501 fax: 972.772.7510 -----Original Message----- From: Gregory Householder [mailto:[EMAIL PROTECTED] Sent: Monday, August 09, 2004 1:40 PM To: Exchange Discussions Subject: New Email Virus??? Hello Everyone, We are getting emails with a zip attachment, the name varies but has price in the name of the zip document. Anyone have any information on this? Greg Householder [EMAIL PROTECTED] _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang =english To unsubscribe send a blank email to %%email.unsub%% Exchange List admin: [EMAIL PROTECTED] To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with. _________________________________________________________________ List posting FAQ: http://www.swinc.com/resource/exch_faq.htm Web Interface: http://intm-dl.sparklist.com/cgi-bin/lyris.pl?enter=exchange&text_mode=&lang=english To unsubscribe send a blank email to [EMAIL PROTECTED] Exchange List admin: [EMAIL PROTECTED] To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with.
