On Wed, Jan 16, 2002 at 07:02:55PM -0500, L.S McGill wrote:
Jennifer just recieved an email attachment from FFML that contained a virus
PWS-Gen.hooker. This was sent as a C&C of Curse of the Banshee. You may
wish to run a virus scan. The sender was identified as Sophie and the
address was from france. This is a password ripping trojan.
Information can be found on the mcafee Virus Information Library or at
Symantec.
I recieved a message from "Sophie" with the W32.Badtrans.B@mm virus. I
tried to reply to Sophie, telling her (or so I assumed from the name)
that her computer was infected. The email address bounced.
At first, because it was sent in reply to a FFML message I'd posted in
the COB C&C thread, I thought it was worth warning the FFML about. I
told pmak, then realized: "Hey, viruses can't go through the FFML
itself, since it strips attachments."
I guess, though, that I wasn't the only one to get sent a virus by
"Sophie". I wonder if this is some sort of attack or if Sophie just
has the worst luck; being infected by two different worms at a time
when her mail is bouncing...
Nah. Looks more like an attack.
(If an admin determines that this message is not appropriate for the
FFML, you have my profound apologies. I just wanted to warn people,
since the way that the W32.Badtrans.B@mm virus was sent to me was
designed to exploit a vulnerability in Outlook Express, which meant
that FFMLers using that mail client might get infected without their
knowledge.)