Guest guest Posted July 19, 2001 Report Share Posted July 19, 2001 Virus Name: TROJ_SIRCAM.ARisk Type: Medium Risk AlertPattern File: #917This Trojan propagates via email using Microsoft Outlook Express. It sendscopies of itself to all addresses listed in an infected user's address book.It arrives in an email with a random subject line, and an attachment by thesame name. A sample of this email is as follows:Subject: (random subject line) Body text: (could be in English or Spanish) Hi! How are you?I send you this file in order to have your advice ORI hope you can help me with this file that I send ORI hope you like the file that I send you ORThis is the file with the information that you ask forSee you later. ThanksAttached file: (random file name)Upon execution, this Trojan drops a copy of itself as SCam32.EXE in theSystem directory. It also drops the file C:\Recycled\SirC32.EXE. On someoccasions, it drops the blank file SCD.DLL file in the System directory.TROJ_SIRCAM.A is detected by pattern file #917, which you can download atthe Trend Micro Web site at http://www.antivirus.com/download/pattern.asp. For more information regarding TROJ_SIRCAM.A please access the Trend MicroVirus Information Center at http://www.antivirus.com/vinfo Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.