Full Disclosure mailing list archives
Re[2]: Virus / Trojan
From: Papp Geza <pappgeza () tolna net>
Date: Sat, 10 Jan 2004 01:04:10 +0100
-----BEGIN PGP SIGNED MESSAGE----- Hash: MD5 Hello This trojan: - From Sophos Troj/Dloader-L Aliases TrojanDownloader.Win32.Xombe Type Trojan Description Troj/Dloader-L is a downloading Trojan that downloads and executes another program from the internet. At the time of writing this downloaded Trojan is detected as Troj/Mssvc-A. The Trojan may arrive in an email with the following characteristics: From: windowsupdate () microsoft com Subject line: Windows XP Service Pack 1 (Express) - Critical Update Message text: Window Update has determined that you are running a beta version of Windows XP Service Pack 1 (SP1). To help improve the stability of your computer, Microsoft recommends that you remove the beta version of Windows XP SP1 and re-install Windows XP SP1. If you cannot remove the beta version, you should still reinstall Windows XP SP1. Windows XP SP1 provides the latest security, reliability, and performance updates to the Windows XP family of operating systems. Windows XP SP1 is designed to ensure Windows XP platform compatibility with newly released software and hardware, and includes updates to resolve issues discovered by customers or by Microsoft's internal testing team. The maximum download size is approximately 3 MB, however the size of the download and time required may be less for computers that have had updates previously installed. To minimize the download time needed for installation, setup will only download those files which are required to bring your computer up to date. Windows XP SP1 includes Internet Explorer 6 SP1. Anti-virus software programs may interfere with the installation of Windows XP SP1. Please disable anti-virus software while installing the service pack. Just run the file winxp_sp1.exe in attach and make sure to restart your PC after installation will be completed. (c) 2004 Microsoft Corporation. All rights reserved. Terms of Use Privacy Statement Attached file: winxp_sp1.exe This is variant Troj/Mssvc-A, and maliciosus but executable file, what download. -- Üdvözlettel, Geza Papp dr. Med. Foensic. (Criminal) and Networksecurity & Virusanalyst IT. Tittle and Designation from AVIEN mailto:pappgeza () tolna net www.gyik.com "VIRUS CORE TEAM" ============================================================================ Regular Member of ComSec Online Limited Professional Services Company - > Company Secretarial Service | http://www.comseconline.com/en/about.php ---------------------------------------------------------------------------- Time out of Mind Registered Active Associate SpamCop.net, and The SPAMHOUS Project - > (ROKSO and Spamhaus Block List) http://www.spamhaus.org/index.lasso | http://spamcop.net/ ---------------------------------------------------------------------------- One from charter member Public letter concerning the Writing of Viruses & How it Does Not Teach about Virus Prevention from Hungary | www.avien.org/publicletter.htm ============================================================================ Fiat justitia, pereat mundus! This system protects Tiny Professional Personal Firewall(c) ============================================================================ -----BEGIN PGP SIGNATURE----- Version: 2.6 iQDVAwUAP/9A/z7s5En2+/4VAQFDkwX/abf+xjl7V1uLypwEPrnZ+45G3+sM9zEw U1AfHP2ylonN47J0QD1ETt0mRTb6RWr1XQmEkNuG0azYxHZOC/g/7usMkcUMgYIs h9/koQB+WiLw40UMrlSrG+5QbAhXNwMk4AImBuQCjieVJqQVSIRrlVWlKUFo75Oq TTAi8SioXCChlZAv0u5e1A0e5RxWEB0h1lWyjvobIfpKMdiPkgkVFfc4xjgQbTig DTlCnHSR7wJcbzRK2Kn1ttlN1Ar5CMLM =xQT5 -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Virus / Trojan Otero, Hernan (EDS) (Jan 09)
- Re: Virus / Trojan Exibar (Jan 09)
- Re[2]: Virus / Trojan Papp Geza (Jan 09)
- Re: Virus / Trojan Axel Pettinger (Jan 09)
- Re: Virus / Trojan William Warren (Jan 09)
- Re: Virus / Trojan Nick FitzGerald (Jan 09)
- <Possible follow-ups>
- RE: Virus / Trojan Nicolas CARTRON (Jan 09)
- RE: Virus / Trojan John LaCour (Jan 09)
- Re: Virus / Trojan PhilZ (Jan 15)
- Re: Virus / Trojan Koito Triabva (Jan 15)
- Re: Virus / Trojan Exibar (Jan 09)