Hallo und einen schönen Tag zusammen!
> Danke! Das war's also *gg*. Ich hatte heute 3 fremde Mails (unbekannter Absender) ohne Text mit lediglich "Re" als Betreff.
Habe schon den selben Virus geschickt bekommen; und den gleichen Virus als "INETD.EXE". Habe mich auch schon ein biserl über diesen Wurm schlau gemacht, der ist ganz schön gemein:
Central Command is warning its customers of a new Internet worm spreading throughout the world. At this time Central Command is issuing a "Medium" risk to this new worm. Details: Name: I-Worm.Badtrans.B Aliases: Win32.Badtrans-B@mm, W32/Badtrans@mm ITW: Yes Risk: Medium Description: I-Worm.Badtrans.B is a new variation of the Internet worm, I-
Worm.Badtrans.A, a virus that spread via e-mail (a copy of the worm was sent as a reply message to all unread emails in the users Inbox folder).The worm arrives in the following e-mail format: Attachment line: A randomly selected messaged built from the following list and combinations: docs, info, Me_nude, Card, Humor, Sorry_about_yesterday YOU_are_FAT!, stuff, news_doc README, images, HAMSTER The first extension selected will be either: *.doc or *.zip or *.MP3 Second extension selected will be either: *.scr or *.pif These are a couple examples of possible choosen subject lines: Me_nude.zip.scr README.MP3.pif stuff.zip.pif Body: (Blank)If executed, the worm copies itself in the \windows\%system% directory under the filename "kernel32.exe". So that it gets run
each time a user restart their computer the following registry key gets added: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnc e\Kernel32 ="kernel32.exe" Removal: Step 1.) Run a deep scan of your PC and delete any files identified as being infected with I-Worm.Badtrans.B Step 2.) Delete the created registry key listed above Central Command, Inc. respects your online privacy. You at anytime can easily remove your e-mail address from the Central Command mailing
list by entering in your e-mail address at the following web page:
http://www.centralcommand.com/unsubscribe.html
You will receive a confirmation message about your successful removal from News.
Liebe Grüsse
Alegna