From: | Dave Millen <dave(at)largesalad(dot)co(dot)uk> |
---|---|
To: | Avi Schwartz <avi(at)CFFtechnologies(dot)com>, pgsql-admin(at)postgresql(dot)org |
Subject: | Re: Trojan Alert |
Date: | 2000-11-24 21:31:10 |
Message-ID: | 3A1EDE1E.2768B60@largesalad.co.uk |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-admin |
Avi Schwartz wrote:
> According to my virus scanner, the message from Wuttipong Suvaphrom
> <wutti_s(at)hotmail(dot)com> titled "v7.0.3 on Solaris 2.7" contained the
> "TR.Worm.Navidad" Trojan. Be carefull:
>
> ----- log file begin -----
> info: extracting attachment 1 to /var/tmp/avVBIA4R/av-0
> (encoding="quoted-printable", name="(no name)", filename="(no name)")
> info: extracting attachment 2 to /var/tmp/avVBIA4R/av-1
> (encoding="base64",
> name="Navidad.exe", filename="Navidad.exe")
> checking file "/var/tmp/avVBIA4R/av-0"
> checking file "/var/tmp/avVBIA4R/av-1"
> VIRUS! the file "/var/tmp/avVBIA4R/av-1" contains code of
> "TR.Worm.Navidad"
> ----- log file end -----
>
> Thanks,
> Avi
> --
> Avi Schwartz
> avi(at)CFFtechnologies(dot)com
Just got this one too, although in one of its alternative incarnations!
The attached mail has been found to contain a virus
Originally /usr/sbin/scanmails -f pgsql-admin-owner(at)postgresql(dot)org -Y
-a -d dmill
The mail has been stored as /var/virusmails/root/virus-20001124-5063
xxxxxxxxxxxxxxxxxxFri Nov 24 13:58:34 GMT 2000xxxxxxxxxxxxxxxxxxxxxxx
scanmails (0.2.1) called -f pgsql-admin-owner(at)postgresql(dot)org -Y -a -d
dmill
FROM: pgsql-admin-owner(at)postgresql(dot)org
TO: dmill
<snip>
/var/tmp/scanmails5063/unpacked/SFX:
total 2
drwxr-xr-x 2 root root 1024 Nov 24 13:58 .
drwxr-xr-x 3 root root 1024 Nov 24 13:58 ..
Scanning /var/tmp/scanmails5063/unpacked/*
Scanning file /var/tmp/scanmails5063/unpacked/mm.VBPik2
Scanning file /var/tmp/scanmails5063/unpacked/Navidad.exe
/var/tmp/scanmails5063/unpacked/Navidad.exe
Found the W32/Navidad(at)M trojan !!!
Info on the virus can be found at:
http://vil.nai.com/vil/dispVirus.asp?virus_k=98881
Looks like it could be nasty if you run Outlook on a Whinedoze PC.
Watch your backs!
Dave
--
He was part of my dream, of course -- but then I was part of his dream too.
-- Lewis Carroll
email: dave(at)largesalad(dot)co(dot)uk
web1 : www.largesalad.co.uk
web2 : www.p21.co.uk
From | Date | Subject | |
---|---|---|---|
Next Message | Fausto Guzzetti | 2000-11-25 09:55:08 | Postgresql on Solais 7 |
Previous Message | Lamar Owen | 2000-11-24 20:43:34 | Re: Which Linux Distribution |