[Dshield] New Outlook virus?
bsavage at rnr-inc.com
Wed Oct 2 12:22:04 GMT 2002
We do use Windows here, and have had absolutely no activity of the type
described over the last few days in the discussion of these new
viruses/attacks. I've checked every morning for port 137 or port 1025 -
1029 traffic: source or destination, in or out, udp/tcp/anything else.
None. Not one packet using or attempting to use those ports.
There's a whole lot I don't know, but I'm puzzled over this one. Glad,
to be sure, but still puzzled.
From: John Draper [mailto:crunch at shopip.com]
Sent: Tuesday, October 01, 2002 4:56 AM
To: list at dshield.org
Subject: Re: [Dshield] New Outlook virus?
> It appears that you receive an infected message that shows no
>attachment when viewed in Outlook. When opened the virus sends email
>out to people in your address book with a subject and content taken
>from a previously sent message. One person reported seeing something
>flash on their screen very quickly when it was opened. The virus is
>attaching itself using the name of an attachment you sent before.
> Up to date Mcafee and Norton virus scanners do not appear to be
>catching it. My Anomy Sanitizer at home caught that there was an .scr
>attachment with the message and defanged it. Other people reported
>that their virus scanner did not catch it but an email defanger did.
I don't use WinBlows, so don't see anything unusual, unless you count
30 identical mail messages with a Klez-H vitus attached! :-)
Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:
More information about the list