Here we go again...We've received about 10 -> 20 copies of a new worm in the
last couple of days, some coming from people on this list.
Here's the description from the Symantec site where you can find lots more
"W32.Badtrans.B@mm is a MAPI worm that emails itself out as one of several
different file names. This worm also drops a backdoor trojan that logs
keystrokes,using the file \Windows\System\Kdll.dll. It uses functions from
this .dll to log keystrokes."
This thing sends 29K file attachments with any of several extensions, such as
.pif, .doc, .zip etc. More mischievous than devilish, from the descr but
still a pain in the neck.
Castle Island Co.
For more information about the rp-ml, see http://rapid.lpt.fi/rp-ml/
This archive was generated by hypermail 2.1.2 : Fri Jan 04 2002 - 09:58:08 EET