It appears that the file I received installs a new goal.exe in C:\Winnt which is set to run on startup. Disassembly of the file reveals that it gathers information about my machine from the registry and attempts to recover my netscape password from prefs.js. It then emails the information to mikeat_private I will post a dissasembly of both files on my website http://www.cell2000.net/security/ -steven alexander
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:23:00 PDT