Because of the highlighted language I wonder if the virus hacker we have had
trouble with has not hacked into MacAfee - the rest of this message read as
it always does
but the line - I look forward to hear from you again - is all too familiar a
line from the
hacker that used to use names from our list for his/her postings. Anyone know
about this one? There was no attachment. Roberta
Fwd: VIRUS ALERT - W32/APost@MM ("APost" or "New Backdoor")
In a message dated 9/4/01 10:51:48 PM Central Daylight Time,
dispatch@mcafee.com writes:
<< Subject: As per your request!
Body: Please find attached file for your review.
I look forward to hear from you again very soon. Thank you.
Attachment: README.EXE >>
[This message is brought to you as a subscriber to the
McAfee.com Dispatch. To unsubscribe, please follow the
instructions at the bottom of the page.]
------------------------------------------------------------
** VIRUS ALERT - W32/APost@mm ("APost" or "New Backdoor") **
------------------------------------------------------------
W32/APost@mm ("APost" or "New Backdoor") worm has been
spreading over the past 24 hours This is a MEDIUM ON WATCH
worm. The infected email can come from addresses that you
recognize and may contain the following information:
Subject: As per your request!
Body: Please find attached file for your review.
I look forward to hear from you again very soon. Thank you.
Attachment: README.EXE
Running the attachment causes the worm to copy itself to the
Windows directory and send a copy of itself to every entry
in the user's Microsoft Outlook Address Book. It will then
display a small dialog box titled "Urgent!". This dialog box
contains one single large button labeled "Open". If this
button is pressed then the worm sends out further copies of
itself, displays an error message box with the title "WinZip
SelfExtractor: Warning" and then terminates.
For detection and removal instructions for the W32/APost@mm
("APost" or "New Backdoor") worm, click here.
McAfee.com VirusScan Online and Clinic subscribers:
If you don't have ActiveShield installed and updated, you
are not protected from this virus. Click here to download ActiveShield.