RootsWeb.com Mailing Lists
Total: 1/1
    1. [AUS-IMM-SHIPS] ADMIN Please read
    2. Meg G
    3. Hello Listers, A new variant of Badtrans has been discovered, referred to as Badtrans.b. AVERT has raised the Risk Assessment on this variant of W32/Badtrans@MM to High Risk for Consumers. If you receive an email with attachments DON'T OPEN until you are sure. (Read below) Also please contact me off list and we can work from there to isolate the problem. If you think you may have the virus or want to make sure you don't go to http://housecall.antivirus.com/ You can do a check online. SOME INFORMATION ON W32/BADTRANS@MM W32/Badtrans@MM is a mass-mailing worm that drops a remote-access Trojan. The virus arrives via the Microsoft Outlook email program and attempts to send itself by replying to unread email messages. The email may contain the text "Take a look to the attachment" in the message body and will contain an attachment that is 13,312 bytes in size. The attachment name is created in three sections, for example, card.doc.pif. For detection and removal instructions for the W32/Badtrans@MM virus, <A HREF="http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2608">click here</A>, or copy the link below into a browser: => http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=2608 W32/Badtrans@MM is a mass-mailing worm that drops a remote-access Trojan. The virus arrives via email in Microsoft Outlook and attempts to send itself by replying to unread email messages. The email may contain the text "Take a look to the attachment" in the message body and will contain an attachment that is 13,312 bytes in length. The attachment name is created from three sections. The first part is chosen from the possibilities: fun Humor docs info Sorry_about_yesterday Me_nude Card SETUP stuff YOU_are_FAT! HAMSTER news_doc New_Napster_Site README images Pics The second part is chosen from the possibilities: .DOC. .MP3. .ZIP. and the last part from the possibilities: pif scr This new variant also uses the iframe exploit and incorrect MIME header to run automatically on unpatched systems. See Microsoft Security Bulletin (MS01-020) for more information and a patch. Cheers Meg

    11/28/2001 11:19:41