Inke Arns on Fri, 2 Apr 1999 22:40:18 +0100


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

protecting the Syndicate


Dear Iaroslava Boubnova, dear friends,

if I am not totally mistaken, it seems that somebody has been trying to
spread a virus via the Syndicate list. First, there was this message
(apparently) from Iaroslava Boubnova <[email protected]> sent through the
Syndicate list:

--- --- ---

Date: Fri, 2 Apr 1999 22:31:52 +0300
From: Iaroslava Boubnova <[email protected]>
Subject: Syndicate: Red Cross mission
X-Spanska: Yes
Sender: [email protected]

begin 644 Happy99.exe

[then follows the text]

Interesting that the virus message was sent at 22:31, only 7 minutes after
Iaroslava's Red Cross messsage (posted at 22:24)
 
----- and this is what I (as the list-owner) received just now from
Japan--------

Date: Sat, 3 Apr 1999 05:16:21 +0900 (JST)
From: <[email protected]>
To: <[email protected]>
Subject: InterScan Virus Alert

$B7Y9p%&%$%k%9BP:v%=%U%H%&%(%"$,(B E-Mail
$BE:IU%U%!%$%k$K%&%$%k%9$r8!CN$7$^$7$?!#E:IU%U%!%$%k$OAw?.$5$l$F$$$^$;$s!#
(BWarning: The AntiVirus software found a virus in your attached file. The
file is ignored.Date:04/03/99
05:15:30,From:<[email protected]>,To:<[email protected]>,File:H
appy99.exe,Virus:TROJ_SKA

--- --- ---end--- --- ---

Well, great. Is there something we can do except using updated anti virus
programs? The virus TROJ_SKA is not included in the latest list of
Symantec's Norton anti virus descriptions (31 March 99)... but there's a
"Happy99.Worm" virus included: "This worm modifies WSOCK.DLL to send itself
as attachment when a posting is made to USENET or MAIL."

Iaroslava, did you notice anything unfamiliar? Could you please check your
computer and delete the virus if necessary?

Or is this a hoax?

Best, Inke


i n k e . a r n s __________________________ b e r l i n ___
49.(0)30.3136678 | [email protected] | http://www.v2.nl/~arns/
mikro: http://www.mikro.org | Syndicate Network: http://www.v2.nl/east/