One more reason to have a banned extension policy in place.

Thanks for the heads up Scott.

John Tolmachoff
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA  92835
www.reliancesoft.com

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry
Sent: Wednesday, June 12, 2002 5:52 AM
To: [EMAIL PROTECTED]
Subject: [Declude.Virus] W32/Frethem-Fam

FYI, there is a new virus out, that Sophos has alerted us to, called 
W32/Fretham-Fam (no other AV companies that was get alerts from,
including 
McAfee, have sent out alerts yet).  This may be become widespread
because 
of the "social engineering" aspect of it -- it pretends to have a
Special 
Password attached, which it does -- but it supposedly needs to be
decrypted 
with the attach file.  The .EXE may run automatically in Outlook when
the 
E-mail is viewed (not sure which OE vulnerability it uses).  There are 
several variants of it already.

More details can be found at 
http://www.sophos.com/virusinfo/analyses/w32frethemfam.html .  The
attached 
files are decrypt-password.exe and password.txt, and it has a subject of

"Re: Your password!".
                                 -Scott

---
[This E-mail was scanned for viruses by Declude Virus
(http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to