Here we go again...Virus warning

From: EdGrenda@aol.com
Date: Tue Nov 27 2001 - 20:35:40 EET


Hi Folks:

Here we go again...We've received about 10 -> 20 copies of a new worm in the
last couple of days, some coming from people on this list.

Here's the description from the Symantec site where you can find lots more
info:

Go to:

http://securityresponse.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html

"W32.Badtrans.B@mm is a MAPI worm that emails itself out as one of several
different file names. This worm also drops a backdoor trojan that logs
keystrokes,using the file \Windows\System\Kdll.dll. It uses functions from
this .dll to log keystrokes."

This thing sends 29K file attachments with any of several extensions, such as
.pif, .doc, .zip etc. More mischievous than devilish, from the descr but
still a pain in the neck.

Regards,
Ed

Ed Grenda
Castle Island Co.
EdGrenda@aol.com (email)
http://home.att.net/~castleisland/

For more information about the rp-ml, see http://rapid.lpt.fi/rp-ml/



This archive was generated by hypermail 2.1.2 : Fri Jan 04 2002 - 09:58:08 EET