LL-L "Virus" 2003.01.14 (07) [D/E/LS]

Lowlands-L admin at lowlands-l.net
Wed Jan 15 01:26:58 UTC 2003


======================================================================
 L O W L A N D S - L * 14.JAN.2003 (07) * ISSN 189-5582 * LCSN 96-4226
 http://www.lowlands-l.net * admin at lowlands-l.net * Encoding: Unicode UTF-8
 Rules & Guidelines: http://www.lowlands-l.net/rules.htm
 Posting Address: lowlands-l at listserv.linguistlist.org
 Server Manual: http://www.lsoft.com/manuals/1.8c/userindex.html
 Archive: http://listserv.linguistlist.org/archives/lowlands-l.html
=======================================================================
 You have received this because you have been subscribed upon request.
 To unsubscribe, please send the command "signoff lowlands-l" as message
 text from the same account to <listserv at listserv.linguistlist.org> or
 sign off at <http://linguistlist.org/subscribing/sub-lowlands-l.html>.
=======================================================================
 A=Afrikaans Ap=Appalachian B=Brabantish D=Dutch E=English F=Frisian
 L=Limburgish LS=Lowlands Saxon (Low German) N=Northumbrian
 S=Scots Sh=Shetlandic V=(West)Flemish Z=Zeelandic (Zeêuws)
=======================================================================

From: Wim <wkv at home.nl>
Subject: LL-L "Virus" 2003.01.14 (01) [E]

Hi!

>From wim verdoold wkv at home.nl

About virusssuss...

Some more virussuss...
 =======================================================================
30 december 2002  VirusAlert: W32.Yaha.K : gevaarlijk (28/100)
OPGEWAARDEERD
 =======================================================================

Informatiepagina op de website van VirusAlert:
http://www.virusalert.nl/?show=virus&id=389

Yaha.K is een mass-mailer internetworm die zich onder sterk wisselende
eigenschappen kan verspreiden. Yaha.K is een afstammeling van Yaha, het
virus dat in juni van 2002 voor de nodige opschudding zorgde. Yaha.K
verspreidt zich op dit moment vooral in de Benelux, de kans dat het
virus bij u binnenkomt is dan ook groot. Wij adviseren de laatste
updates van uw antivirussoftware te installeren en via een gratis online
scanner een second-check op uw systeem uit te voeren.

Payload/Schade
* Uitschakeling van bepaalde security- c.q. antivirussoftware.
* Verspreiding op tamelijk intelligente wijze, waardoor herkenning
lastig is.
* Installatie van een aantal bestanden op uw systeem, inclusief een
verwijzing
vanuit de registry.

This page came trough my virus alert subscription...   I get warned for
new virussus automatically, and I have installed Norton, and anti virus
program, it updates it self automatically, works fine for me!

Some other addresses:

For information on WORM_BUGBEAR.A please visit our Web site at:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BUG
BEAR.A

For information on WORM_RODOK.A please visit our Web site at:
http://veadmin.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM
_RODOK.A

The worm WORM_FRIENDGRT.A is a "Friend Greetings" application that sends
out an invitation email to all addresses listed on the system's
Microsoft Outlook contact list.

The details of the email that it sends are as follows:

Subject: <Recipient> you have an E-Card from <Sender>
Message Body: Greetings!
has sent you an E-Card -- a virtual postcard from FriendGreetings.com.
You can pickup your E-Card at the FriendGreetings.com by clicking on the
link below.
http://www.frie<BLOCKED>eeting.com/203746/pickup.html?
Message: ------------------------------------------------------------?
<Recipient>, I sent you a greeting card. Please pick it up.? <Sender>?
------------------------------------------------------------?

Once a recipient clicks the URL on this message, he or she is prompted
for the installation of this worm program. And as soon as this
installation concludes, this worm immediately mass-mails the described
message.

Other variants of this worm send out the following links instead:

http://www.<BLOCKED>-greetings.com/pickup/pickup.aspx?code=<sender>&id=<
id number>
http://www.<BLOCKED>-cards.net/pickup/pickup.html?code=<sender>&id=<id
number>

WORM_FRIENDGRT.B is detected by pattern file 381.

For more information on WORM_FRIENDGRT.B please visit our Web site at:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_FRI
ENDGRT.B

Lirva C....This mass-mailing worm propagates via email, mapped
network-shared drives, IRC, ICQ and KaZaA Peer-to-Peer file sharing. It
arrives through email with the following details:

Subject: (any of the following)
Fw: Redirection error notification
Re: Brigada Ocho Free membership
Re: According to Purge's Statement
Fw: Avril Lavigne - CHART ATTACK!
Re: Reply on account for IIS-Security Breach (TFTP)
Re: ACTR/ACCELS Transcriptions
Re: IREX admits you to take in FSAU 2003
Fwd: Re: Have U requested Avril Lavigne bio?
Re: Reply on account for IFRAME-Security breach
Fwd: Re: Reply on account for Incorrect MIME-header
Re: Vote seniors masters - don't miss it!
Fwd: RFC-0245 Specification requested...
Fwd: RFC-0841 Specification requested...
Fw: F. M. Dostoyevsky

For more information on WORM_LIRVA.C, please visit our Web site at:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_LIR
VA.C

Well for those who start to get afraid to check their mail, box now...
You can go to the web site off HouseCall   and get your computer checked
on line for virusssuss too..

Nog gelukkig nieuw jaar allemaal!

Of op sien Swols gelokkog nij joar!

Wim.

==================================END===================================
* Please submit postings to <lowlands-l at listserv.linguistlist.org>.
* Postings will be displayed unedited in digest form.
* Please display only the relevant parts of quotes in your replies.
* Commands for automated functions (including "signoff lowlands-l") are
  to be sent to <listserv at listserv.linguistlist.org> or at
  <http://linguistlist.org/subscribing/sub-lowlands-l.html>.
 =======================================================================



More information about the LOWLANDS-L mailing list