RootsWeb.com Mailing Lists
Total: 1/1
    1. [NCHERTFO-L] New Virus
    2. Julie
    3. New virus I was recently hit by a new virus called the Downloader.BO.B.dr. It completely crashed my system and I lost some personal files although it could have been much worse considering the fact that I had my most critical files on another hard disk. This virus was just caught by Symantec on the 6th of May, 2003 and I was hit a few days before, so my antivirus software didn't catch it. Most antivirus software makers now have updates for this virus but you need to be sure you have updated your virus definition list through your antivirus software's home site. I was sent an email message that looked like a mailer daemon message that says your email can't be delivered because of errors in the email address you sent it to. These attachments however have a virus imbedded which will execute the next time you restart Windows, or try to. Symantec, makers of Norton Antivirus says the following about this virus: _____________________________________________________ "Downloader.BO.B.dr arrives disguised as an administrative email, which may have the following characteristics: From: MAILER-DAEMON Subject: Warning: could not send message! Message: WARNING I CAN"T SEND YOUR MESSAGE ALL DETAILS ARE IN THE ATTACHMENT Attachment: Error.hta The email is generated and distributed manually by a hacker and is not a function of the Trojan Horse. If you open the attachment, it displays a fake message that contains the following text: WARNING! There were errors while processing your mail. All the information is in the attachment. DO NOT RESPONF TO THIS MESSAGE. Then, the Trojan creates a file on your computer as C:\windows\Sys_con.exe and then executes it. This file may be detected as Downloader.BO or Downloader.BO.B." ________________________________________________________ Do not open any of these emails, instead go directly to your AV software web site and check for new virus definitions, download them and scan your computer. If you would like more information on this, go to Symantec's web site: http://securityresponse.symantec.com/avcenter/venc/data/downloader.bo.b.dr.h tml Julie

    05/09/2003 03:19:36