l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
December 2: Social Gathering
Next Installfest:
TBA
Latest News:
Nov. 18: Officers elected
Page last updated:
2005 Jan 11 22:15
Events
 Meetings
 Installfests
 Demos
 Photos
Services
 Library
 LERT
 Jobs
 Documents
Interact
 Mailing Lists
 - Search
 - Archives
 Chat (IRC)
 Social Networks
About Us
 Members
 Projects
 Testimonials
 Call for Speakers
 Why Not MS?
 Finances
 Sponsors

^Home
?Search
?News & RSS
?Calendar
@Contact Us
$Buy Stuff
=Printable


The following is an archive of a post made to our 'vox mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox] [OT] Anyone else getting hit with a deluge of virus emailbounces?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox] [OT] Anyone else getting hit with a deluge of virus emailbounces?



On Tue, Jan 11, 2005 at 11:12:01AM -0800, Mark K. Kim wrote:
> I'm getting no more spams/virus/virus-reply than usual.  I'm guessing the
> virus is, once again, Outlook-related?  Most of my friends use
> Hotmail/Yahoo/MSN/Gmail.

I obviously didn't look at all of the bounce emails.
(In fact, I didn't look at ANY, except the subject lines.)

However, from the subject line of many of the "you sent a virus..." ones,
I gathered that I'm being indirectly hit by W32/Zafi-D, which is actually
a worm:

  http://www.sophos.com/virusinfo/analyses/w32zafid.html


Some snippets:

  W32/Zafi-D harvests email addresses from the Windows Address Book and
  from files found on the hard drive.

  W32/Zafi-D attempts to open files containing the following strings
  and keep them open so as to make them inaccessible to the user:
    reged, msconfig, task

  W32/Zafi-D copies itself to folders containing one of the following strings:
    share, upload, music 


It looks like it's a manually-activated worm (versus taking advantage of
some Outlook bug, for example), as the description doesn't mention Outlook
or Explorer, and it looks like the worm sends email messages pretending to
be holiday greeting postcards.


Pretty old-school means of propogating, really.

-bill!
bill@newbreedsoftware.com          April shower bring Kompressor power!
http://newbreedsoftware.com/
_______________________________________________
vox mailing list
vox@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox



LinkedIn
LUGOD Group on LinkedIn
facebook
LUGOD Group on Facebook

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
1105 Kennedy Place, Suite 1, Davis, CA 95616
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
California Computer News
Who donated books and ad space.