The virus, called a worm because it reproduces itself, is a variation on the "Badtrans" worm, which first hit in April. It is protected from in the latest Norton Anti-Virus Definitions ... http://www.cnn.com/2001/TECH/internet/11/26/badtrans.worm/

In addition, only four days before the breakout of Badtrans, the FBI had revealed that it was developing its own keystroke logger, Magic Lantern. The worm writes email addresses to the Protocol.dll file in the system folder to prevent multiple emails to the same person. Information about this vulnerability and a Microsoft patch is located at: http://www.microsoft.com/technet/security/bulletin/MS01-033.asp System administrators are encouraged to apply the Microsoft patch to prevent infection from this worm and other unauthorized access.

ALSO SEE: "Code Red" worm claims 12,000 servers http://www.infosecnews.org/hypermail/0107/4348.html ========================================================= Bob Hardison Re: "Code Red" Computer virus will reinfect networks Sat Jul 28 14:45:05 2001 From the Norton AVCenter .... ...

Badtrans is an Internet worm that sends copies of itself by replying to all unread e-mail found on the infected computer. It gets its name from a "bad data transmission" message it delivers to victims.

Messages posted on some of the underground Internet chat rooms indicate that US hackers plan to continue the blitz they have dubbed the "ChinaKiller." And on the Chinese side, "Many people If it finds addresses in these files, then it sends mail to those addresses using the victim's SMTP server. The virus uses a vulnerability in Microsoft's Internet Explorer 5.01 and 5.5 to automatically execute itself on PCs that don't have a patched Web browser. Desinfection was useless.

The worm will use MAPI to find unread email and reply to it.

The subject line of these emails will be "Re:" and the attachment will be one of these: PICS IMAGES README New_Napster_Site NEWS_DOC HAMSTER YOU_ARE_FAT!

