[iwar] [fc:Nasty.New.Year.Virus]

From: Fred Cohen (fc@all.net)
Date: 2002-01-02 07:11:52


Return-Path: <sentto-279987-4182-1009984308-fc=all.net@returns.groups.yahoo.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 [204.181.12.215] by localhost with POP3 (fetchmail-5.7.4) for fc@localhost (single-drop); Wed, 02 Jan 2002 07:13:08 -0800 (PST)
Received: (qmail 23544 invoked by uid 510); 2 Jan 2002 15:12:10 -0000
Received: from n25.groups.yahoo.com (216.115.96.75) by all.net with SMTP; 2 Jan 2002 15:12:10 -0000
X-eGroups-Return: sentto-279987-4182-1009984308-fc=all.net@returns.groups.yahoo.com
Received: from [216.115.97.188] by n25.groups.yahoo.com with NNFMP; 02 Jan 2002 15:10:42 -0000
X-Sender: fc@red.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_1_3); 2 Jan 2002 15:11:48 -0000
Received: (qmail 26721 invoked from network); 2 Jan 2002 15:11:48 -0000
Received: from unknown (216.115.97.172) by m2.grp.snv.yahoo.com with QMQP; 2 Jan 2002 15:11:48 -0000
Received: from unknown (HELO red.all.net) (12.232.125.69) by mta2.grp.snv.yahoo.com with SMTP; 2 Jan 2002 15:11:48 -0000
Received: (from fc@localhost) by red.all.net (8.11.2/8.11.2) id g02FBqk16966 for iwar@onelist.com; Wed, 2 Jan 2002 07:11:52 -0800
Message-Id: <200201021511.g02FBqk16966@red.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL3]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Wed, 2 Jan 2002 07:11:52 -0800 (PST)
Subject: [iwar] [fc:Nasty.New.Year.Virus]
Reply-To: iwar@yahoogroups.com
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

Nasty New Year Virus

By Jim Freund, Earth Web, 1/2/2002
<a href="http://networking.earthweb.com/netsecur/print/0,,12084_943961,00.html">http://networking.earthweb.com/netsecur/print/0,,12084_943961,00.html>

Every year seems to bring forth a virus related to New Year's, and each
one seems to be different. The main danger we're looking at this time is
the discrepancy of information from differing sources. If you look up
"Happy New Year Virus" at your preferred search engine, you are likely
to first see sources telling you that this is a hoax. In 1999, that was
true. An e-mail was sent out with text similar to the following:

Warning on December 31, 1999 you may receive an email called, Happy New
Year...do not open it, it contains a deadly virus...it will erase
windows from your computer along with many other program files.Pass this
on as soon as you can to get the WORD out!!!This is not a hoax....this
was reported on CNN on Tuesday the 2nd November 1999!

Bereft of any attachments or a bona-fide e-mail following up on this,
that was, of course, a hoax.

However, do not let this past history or the fact that you may read that
it's harmless take away your vigilance. There's a new virus with the
same header, and this one has definitely spiked its punch.

An e-mail message shows up as follows: 
From: an associate To: you  Subject: Happy New Year or in many
instances, Subject: Hi

Message text: Hi, I can't describe my feelings But all I can say is
Happy new year:-) Bye

Attachment: Christmas.exe

As always, the attachment is the zinger. In this case the attachment
appears to be a Macromedia Flash file, and if launched, will display a
small animated program featuring Santa and a reindeer. Christmas.exe is
a Trojan most commonly known as Reeezak, but has also been cited as
Zacker, Maldal and Keyluc.

December 20, 2001

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Tiny Wireless Camera under $80!
Order Now! FREE VCR Commander!
Click Here - Only 1 Day Left!
http://us.click.yahoo.com/WoOlbB/7.PDAA/ySSFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2002-12-31 02:15:02 PST