Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Miss Tracey Smiley?

Thread Tools
 
Search this Thread
 
Old 30th November 2001 | 17:42
  #1 (permalink)  
Thread Starter

Just Binos
 
Joined: Oct 2000
Posts: 1,397
Likes: 0
From: Mackay, Australia
Question Miss Tracey Smiley?

Received an email in my Pprune inbox from a Miss Tracey Smiley, subject Re:, File size 42k. Knowing Pprune to be spam free (it says so!) and confident in my virus checker, I attempted to open the letter, only to get a url as follows: cidA4DMGBP9p and a message that this page could not be opened.

I did a virus scan afterwards, though not on my whole C drive, and turned up nothing. Anybody got any ideas?

I've saved the message should the moderators be interested, though how I would forward it has got me beat.
cidA4DMGBP9p
Binoculars is offline  
Old 30th November 2001 | 19:36
  #2 (permalink)  
25 Anniversary
 
Joined: Sep 2000
Posts: 535
Likes: 1
From: Toronto
Post

Binoculars
See the thread on w32/badtrans/mm.
I had the same type of email from Andy Hughes.
Since I had already experienced the w32/badtrans/mm virus I just deleted it.
My Norton Anti-virus didn't spot it, but it did no harm.
cossack is offline  
Old 1st December 2001 | 15:38
  #3 (permalink)  
Thread Starter

Just Binos
 
Joined: Oct 2000
Posts: 1,397
Likes: 0
From: Mackay, Australia
Post

Thanks Cossack. Always feel a dill starting a new thread on something that's got two pages devoted to it elsewhere, but if you don't check each thread you don't know.

Binoculars is offline  
Old 1st December 2001 | 20:03
  #4 (permalink)  
 
Joined: Mar 2000
Posts: 2,809
Likes: 0
From: Bothell WA
Post

cossack

This is a new virus. Are your definitions up to date?

W32.Badtrans.B@mm
Discovered on: November 24, 2001
Last Updated on: November 29, 2001 at 05:04:14 PM PST
Due to the increased rate of submissions, Symantec Security Response has upgraded the threat level of this worm from level 3 to level 4 as of November 26, 2001.
W32.Badtrans.B@mm is a MAPI worm that emails itself out using different file names. It also creates the file \Windows\System\Kdll.dll. It uses functions from this file to log keystrokes.
TR4A is offline  
Old 2nd December 2001 | 01:53
  #5 (permalink)  
25 Anniversary
 
Joined: Sep 2000
Posts: 535
Likes: 1
From: Toronto
Post

Defs were updated on my return from holiday on 29/11.
Said email was received yesterday.
Just downloaded another update though.
cossack is offline  
Old 2nd December 2001 | 15:38
  #6 (permalink)  
 
Joined: Jun 2000
Posts: 1,003
Likes: 0
From: Geriatrica, UK
Thumbs up

TR4A, thanks for the "heads-up" on Kdll.dll. Sure enough it was right there in CWindows\System created at the time of the offending Virus download. However it seemed not to have been modified afterwards.

Have suitably hidden it in case Windows wants it back for some reason.
fobotcso is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.