AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1831
Last Updated: 2006-11-07 20:29:51 UTC
(References:)
- http://www.kaspersky.com/news?id=204900036
"Kaspersky Lab has intercepted a mass-mailing containing Trojan-Dropper.MSWord.Lafool.v. This mass mailing is unusual as messages appear to be sent from mcafee @ europe.com and allegedly originated from McAfee, an antivirus company. Kaspersky Lab believes that McAfee is in no way involved in the distribution of this Trojan and that the email address used in the messages ([removed]) is faked and used in order to cause recipients to open infected messages. Lafool.v is a Word document called “McAfee Inc. Reports.doc”. The file is 80,635 bytes in size, and allegedly contains a report about the propagation of malicious programs on the Internet. The document contains a macro written in Visual Basic for Applications. Lafool.v extracts a new modification of LdPinch, a well known Trojan password stealing program, from itself, and launches it for execution. LdPinch steals passwords to a number of services and applications, including AOL Instant Messenger and ICQ, and other confidential user data. Kaspersky Anti-Virus detects the new variant of this program as Trojan-PSW.Win32.LdPinch.bbg* …
* http://www.viruslist.com/en/viruses/encycl…?virusid=140927
"…Check the C: root directory for a file called “LS060E.eXE” and delete it: C:\LS060E5.eXE …"

- http://isc.sans.org/diary.php?storyid=1831
Last Updated: 2006-11-07 20:29:51 UTC
(References:)
- http://www.kaspersky.com/news?id=204900036
"Kaspersky Lab has intercepted a mass-mailing containing Trojan-Dropper.MSWord.Lafool.v. This mass mailing is unusual as messages appear to be sent from mcafee @ europe.com and allegedly originated from McAfee, an antivirus company. Kaspersky Lab believes that McAfee is in no way involved in the distribution of this Trojan and that the email address used in the messages ([removed]) is faked and used in order to cause recipients to open infected messages. Lafool.v is a Word document called “McAfee Inc. Reports.doc”. The file is 80,635 bytes in size, and allegedly contains a report about the propagation of malicious programs on the Internet. The document contains a macro written in Visual Basic for Applications. Lafool.v extracts a new modification of LdPinch, a well known Trojan password stealing program, from itself, and launches it for execution. LdPinch steals passwords to a number of services and applications, including AOL Instant Messenger and ICQ, and other confidential user data. Kaspersky Anti-Virus detects the new variant of this program as Trojan-PSW.Win32.LdPinch.bbg* …
* http://www.viruslist.com/en/viruses/encycl…?virusid=140927
"…Check the C: root directory for a file called “LS060E.eXE” and delete it: C:\LS060E5.eXE …"