Re: Trojan Alert

From: Dave Millen <dave(at)largesalad(dot)co(dot)uk>
To: Avi Schwartz <avi(at)CFFtechnologies(dot)com>, pgsql-admin(at)postgresql(dot)org
Subject: Re: Trojan Alert
Date: 2000-11-24 21:31:10
Message-ID: 3A1EDE1E.2768B60@largesalad.co.uk
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Avi Schwartz wrote:

> According to my virus scanner, the message from Wuttipong Suvaphrom
> <wutti_s(at)hotmail(dot)com> titled "v7.0.3 on Solaris 2.7" contained the
> "TR.Worm.Navidad" Trojan. Be carefull:
>
> ----- log file begin -----
> info: extracting attachment 1 to /var/tmp/avVBIA4R/av-0
> (encoding="quoted-printable", name="(no name)", filename="(no name)")
> info: extracting attachment 2 to /var/tmp/avVBIA4R/av-1
> (encoding="base64",
> name="Navidad.exe", filename="Navidad.exe")
> checking file "/var/tmp/avVBIA4R/av-0"
> checking file "/var/tmp/avVBIA4R/av-1"
> VIRUS! the file "/var/tmp/avVBIA4R/av-1" contains code of
> "TR.Worm.Navidad"
> ----- log file end -----
>
> Thanks,
> Avi
> --
> Avi Schwartz
> avi(at)CFFtechnologies(dot)com

Just got this one too, although in one of its alternative incarnations!

The attached mail has been found to contain a virus
Originally /usr/sbin/scanmails -f pgsql-admin-owner(at)postgresql(dot)org -Y
-a -d dmill
The mail has been stored as /var/virusmails/root/virus-20001124-5063
xxxxxxxxxxxxxxxxxxFri Nov 24 13:58:34 GMT 2000xxxxxxxxxxxxxxxxxxxxxxx
scanmails (0.2.1) called -f pgsql-admin-owner(at)postgresql(dot)org -Y -a -d
dmill
FROM: pgsql-admin-owner(at)postgresql(dot)org
TO: dmill

<snip>

/var/tmp/scanmails5063/unpacked/SFX:
total 2
drwxr-xr-x 2 root root 1024 Nov 24 13:58 .
drwxr-xr-x 3 root root 1024 Nov 24 13:58 ..
Scanning /var/tmp/scanmails5063/unpacked/*
Scanning file /var/tmp/scanmails5063/unpacked/mm.VBPik2
Scanning file /var/tmp/scanmails5063/unpacked/Navidad.exe
/var/tmp/scanmails5063/unpacked/Navidad.exe
Found the W32/Navidad(at)M trojan !!!

Info on the virus can be found at:
http://vil.nai.com/vil/dispVirus.asp?virus_k=98881

Looks like it could be nasty if you run Outlook on a Whinedoze PC.

Watch your backs!
Dave

--
He was part of my dream, of course -- but then I was part of his dream too.
-- Lewis Carroll

email: dave(at)largesalad(dot)co(dot)uk
web1 : www.largesalad.co.uk
web2 : www.p21.co.uk

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Fausto Guzzetti 2000-11-25 09:55:08 Postgresql on Solais 7
Previous Message Lamar Owen 2000-11-24 20:43:34 Re: Which Linux Distribution