[R-390] VIRUS !?!?

Pinner Family [email protected]
Fri, 9 Aug 2002 17:03:34 -0500


Hello Everyone,



From www.nai.com

W32/Hybris.gen@MM aka Snowhite and the Seven Dwarfs


Currently this virus downloads plugins from alt.comp.virus. The virus
contains an internal list of several news servers it can access. It searches
the newsgroup for any plugins that it doesn't have, or has older versions
of. Since the worm searches all Internet activity for e-mail addresses,
people who post to alt.comp.virus using their real e-mail address may get
many copies of the worm when Hybris searches alt.comp.virus for new plugins.
When a full moon occurs according to the computer's internal clock, the
virus will randomly post its plugins to the alt.comp.virus newsgroup. It
uses a mail-to-news gateway at anon.lcs.mit.edu to send plugins with a fake
return address of [email protected].


A FREE on line scanner: http://housecall.antivirus.com/

Free virus program for home users: www.grisoft.com AVG 6.0

73

tom








Yes, same set up here Roy. I get blank emails or one or two lines, that's
it.
Just wondered why all of a sudden I'm getting them from list members. Ed
mentioned it was likely the address book deal.

73, Boomer   KA1KAQ

Roy Morgan wrote:

http://mailman.qth.net/mailman/listinfo/r-390

---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.381 / Virus Database: 214 - Release Date: 8/2/2002

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.381 / Virus Database: 214 - Release Date: 8/2/2002