[13086] in bugtraq
Warning to Bugtraq posters.
daemon@ATHENA.MIT.EDU (Steven Alexander)
Thu Dec 23 16:43:25 1999
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id: <000601bf4c9c$6f0bd9c0$0100007f@localhost.cell2000.net>
Date: Wed, 22 Dec 1999 08:48:53 -0800
Reply-To: Steven Alexander <steve@cell2000.net>
From: Steven Alexander <steve@CELL2000.NET>
X-To: aleph1@UNDERGROUND.ORG
To: BUGTRAQ@SECURITYFOCUS.COM
After my last post to bugtraq (Re: w00w00....) I received a message
pertaining to be from myself with the same subject line. The messsage
contained an attachment program named goal.exe. It claimed that this
program was from messagemates.com. If the program is run it will give an
error message about an unfound .DLL. It will also create a new goal.exe in
"C:\WINNT\" and an entry in the registry named "tpawen" with the value
"C:\WINNT\goal.exe /x" under
"HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run". I don't
know what this program is, I am disassembling it now and will post again
later. The header from the message I received indicates that the mail was
received by my mail server from "stu.chesapeake.net, 205.130.220.9". If
anyone knows anything more please email me.
-steven alexander