Resume.Txt.Vbs
This worm is a distant variant of VBS.LoveLetter.A. It attempts to
email itself to everyone in the Microsoft Outlook address book.
This worm comes as an email attachment named
"resume.txt.vbs". It also contains the functionality to download a
password stealer.
Qaz.Trojan
There's a new Trojan horse in town
called Qaz.trojan (W32.HLLW.QAZ.A), which spreads within a
network of shared computer systems,
infecting the Notepad.exe file.
This is an Internet worm that also acts as a backdoor. When running,
it listens on TCP port 7597 to give hackers access to the system.
When this trojan is executed, it modifies the registry with this key
value:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
StartIE=C:\WINDOWS\notepad.exe qazwsx.hsq
One major significance is the real NOTEPAD.EXE is 52Kb while this
worm is 120,320 bytes.
Previous TCS Virus Alerts:
This page has been accessed
times.
Tulsa Computer Society
Don Singleton, President
djs@ionet.net