| |
M1CUK > INFO 06.07.02 13:49l 47 Lines 1544 Bytes #999 (0) @ WW
BID : 3B1176M1CUK
Read: DB0FHN GUEST
Subj: virus update
Path: DB0FHN<DB0ZWI<DB0CHZ<OK0PKL<DB0MRW<DB0SON<DB0SIF<DB0IDN<E20LAL<7M3TJZ<
ON0AR<GB7FCR
Sent: 020622/2249Z @:GB7FCR.#16.GBR.EU #:63147 [Blackpool] FBB-7.03a $:3B1176M1
From: M1CUK@GB7FCR.#16.GBR.EU
To : INFO@WWW
Yet another Windows Virus....
WORM_YAHA.E is a non-destructive worm that arrives as an
email attachment with a random filename and the extensions
.SCR and .BAT.
The email subject line and message body are also randomly
chosen, from a long list of possible choices.
Upon execution, it copies itself to a random four-lettered
filename in the Recycle Bin folder, and sets the attribute
of this copy to "hidden."
This worm sends a message to email addresses taken from the
following sources on the infected user's computer:
-Windows Address Book
-MSN Messenger
-Yahoo Pager List
-ICQ List
WORM_YAHA.E uses a built-in Simple Mail Transfer Protocol (SMTP)
engine to propagate, and uses the infected system's default SMTP
server to send the email. If it does not find an available SMTP
server on the infected system, it chooses SMTP servers from a
predetermined list that contain Internet Protocol (IP) addresses
embedded and encrypted in the worm body.
If you would like to scan your computer for WORM_YAHA.E or thousands
of other worms, viruses, Trojans and malicious code, visit HouseCall,
Trend Micro's free online virus scanner at:
http://housecall.antivirus.com/
--------------------------------
73's
Trev, m1cuk@gb7fcr.#16.gbr.eu
SysOp gb7fcr
ax25 - tcp/ip - telnet - axip - RF & Internet Linked System's
Located in Blackpool, Lancashire, On the North West Coast of the UK
Message timed: 23:03 on 22 Jun 02
Message sent using WinPack-Telnet V6.80
Read previous mail | Read next mail
| |