l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
November 4: Social gathering
Next Installfest:
TBD
Latest News:
Oct. 24: LUGOD election season has begun!
Page last updated:
2005 Jan 11 22:15

The following is an archive of a post made to our 'vox mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox] [OT] Anyone else getting hit with a deluge of virus emailbounces?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox] [OT] Anyone else getting hit with a deluge of virus emailbounces?



On Tue, Jan 11, 2005 at 11:12:01AM -0800, Mark K. Kim wrote:
> I'm getting no more spams/virus/virus-reply than usual.  I'm guessing the
> virus is, once again, Outlook-related?  Most of my friends use
> Hotmail/Yahoo/MSN/Gmail.

I obviously didn't look at all of the bounce emails.
(In fact, I didn't look at ANY, except the subject lines.)

However, from the subject line of many of the "you sent a virus..." ones,
I gathered that I'm being indirectly hit by W32/Zafi-D, which is actually
a worm:

  http://www.sophos.com/virusinfo/analyses/w32zafid.html


Some snippets:

  W32/Zafi-D harvests email addresses from the Windows Address Book and
  from files found on the hard drive.

  W32/Zafi-D attempts to open files containing the following strings
  and keep them open so as to make them inaccessible to the user:
    reged, msconfig, task

  W32/Zafi-D copies itself to folders containing one of the following strings:
    share, upload, music 


It looks like it's a manually-activated worm (versus taking advantage of
some Outlook bug, for example), as the description doesn't mention Outlook
or Explorer, and it looks like the worm sends email messages pretending to
be holiday greeting postcards.


Pretty old-school means of propogating, really.

-bill!
bill@newbreedsoftware.com          April shower bring Kompressor power!
http://newbreedsoftware.com/
_______________________________________________
vox mailing list
vox@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Sunset Systems
Who graciously hosts our website & mailing lists!