Re: VIRUS ALERT: w32/bugbear@MM

new topic     » goto parent     » topic index » view thread      » older message » newer message

At 04:21 AM 02/10/2002 -0700, Dan wrote:
>I just spent many hours getting the email virus w32/bugbear@MMand one called
>PWS-Hooker.dll off my system, and since they are remailers, it's possible
>people on this list might have been sent it too (from my address book), so
>it wouldn't hurt to be alert for them.
>
>I think they look for old email to re-present, because mine was purportedly
>from David Cuny (at dcuny at siol.net), with a subject:   Re: Peuphoria

I received it as well, on my euphoria account.  By that, I mean that it is only
subscribed to the Euphoria list, and has never been used elsewhere.  No spam
has ever been received in the year that I have had the account, so I was quite
surprised to see a message about "your CDNOW order confirmation".  Luckily,
my email provider (mac.com) scans all incoming mail, and they removed the
attachment.  I can only assume that it came from an infected machine on this
list that has my address in an address book.

It claimed to have come from "manager at griffon.mwsc.edu", but has a return
path of 2Cust70.tnt9.adl1.da.uu.net [63.12.15.70] by way of
pluto.senet.com.au.

The router tnt9.adl1.da.uu.net is part of UUNET/Worldcom's
network and is located in Adelaide, Australia.  So if you are on this list, 
and live
in or near Adelaide, please check your PC for an infection by W32/BugBear at MM.

This has been a public service announcement.

James Powell

new topic     » goto parent     » topic index » view thread      » older message » newer message

Search



Quick Links

User menu

Not signed in.

Misc Menu