[Dshield] New Outlook virus?

Bob Savage bsavage at rnr-inc.com
Wed Oct 2 12:22:04 GMT 2002

We do use Windows here, and have had absolutely no activity of the type
described over the last few days in the discussion of these new
viruses/attacks.  I've checked every morning for port 137 or port 1025 -
1029 traffic: source or destination, in or out, udp/tcp/anything else.
None.  Not one packet using or attempting to use those ports.

There's a whole lot I don't know, but I'm puzzled over this one.  Glad,
to be sure, but still puzzled.


-----Original Message-----
From: John Draper [mailto:crunch at shopip.com]
Sent: Tuesday, October 01, 2002 4:56 AM
To: list at dshield.org
Subject: Re: [Dshield] New Outlook virus?

>   It appears that you receive an infected message that shows no
>attachment when viewed in Outlook.  When opened the virus sends email
>out to people in your address book with a subject and content taken
>from a previously sent message.  One person reported seeing something
>flash on their screen very quickly when it was opened.  The virus is
>attaching itself using the name of an attachment you sent before.
>   Up to date Mcafee and Norton virus scanners do not appear to be
>catching it.  My Anomy Sanitizer at home caught that there was an .scr
>attachment with the message and defanged it.  Other people reported
>that their virus scanner did not catch it but an email defanger did.

I don't use WinBlows,  so don't see anything unusual,  unless you count
30 identical mail messages with a Klez-H vitus attached!    :-)


Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:

More information about the list mailing list