Re: [Full-Disclosure] new virus or variant

2004-08-02 Thread Ron DuFresne
On Mon, 2 Aug 2004, Vic Vandal wrote: > There's a new .ZIP attachment that mimics some of the recent ones > in arriving as something like [EMAIL PROTECTED], extracting to > [EMAIL PROTECTED], which is a Windows command file. > [SNIP] Nothing new about this, virus attachments have been do

[Full-Disclosure] new virus or variant

2004-08-02 Thread Vic Vandal
There's a new .ZIP attachment that mimics some of the recent ones in arriving as something like [EMAIL PROTECTED], extracting to [EMAIL PROTECTED], which is a Windows command file. I've only just started looking at the payload, and see it does some reg key checks on WOW (looking for itself...no ti