|
VIRUS ALERT Virus Name: W32/Zafi.b@MM This is a
mass-mailing worm that constructs messages using its own SMTP engine,
spoofing the From: address. It also attempts to propagate via P2P, via
copying itself to folders on the local system (containing 'share' or
'upload' in the folder name). The worm sends itself out in
different languages depending on the Top Level Doamin (TLD) of the
receipents address. For example, a user with a .COM Mail address, will
receive the English mailbody, while someone with an .DE Mail address
will receive the German body. The worm searches for directories
of anti-virus and personal firewall software, and then overwrites the
executables in there with a copy of itself. Our email virus scanner has been updated to protect against this threat. Reference: http://vil.nai.com/vil/content/v_126242.htm
|