[Bioundgrd] New PC virus circulating = PC USERS

Gurukarm Khalsa gkkhalsa at MIT.EDU
Wed Dec 15 12:06:05 EST 2004


The below information comes to us from McAfee/Network Associates. 
It's playing upon holiday good-wishes feelings - don't be fooled!

As always, NEVER NEVER open attachments from someone you don't know; 
even if an attachment APPEARS to be from a friend or colleague but 
you're not expecting anything from that person, check with the sender 
before opening. The "from" field may be forged by the virus.

Regards,
Gurukarm
........................................................................................
Gurukarm K. Khalsa 		MIT Dept. of Biology
Computing help in Building 68	biocomp at mit.edu
........................................................................................



Offering a fake holiday greeting, W32/Zafi.d at MM is a
Medium Risk mass-mailing worm that arrives as an email
attachment. When run, the worm displays a fake error message
(Error in packed file!), infects the host computer and
emails itself to stolen email addresses using the infected
computer's Internet connection.

--> What should I look for?

FROM: Varies (forged addresses taken from infected system)
SUBJECT: Example: Fw: Merry Christmas!
BODY: Example: Happy Hollydays!
ATTACHMENT: Example: postcard.php8583.zip

--> How do I know if I've been infected?

Fake error message displayed. Alerts from a desktop firewall
(if installed) that a new application is asking for Internet
access. TCP port 8181 open on the infected system.

--> How do I find out more?

View details about W32/Zafi.d at MM here.
http://us.mcafee.com/root/campaign.asp?cid=12942


More information about the bioundgrd mailing list