MADVirus Warnings

 


HOT DATES
VALUE RATES


MADTRAVEL
NEWS


MADBLAST
PORTFOLIO


 

2004-10-29
We don't know its name but the message is the following & DO NOT OPEN: Some of our clients complained about the spam (negative e-mail content) outgoing from your e-mail account. Probably, you have been infected by a proxy-relay trojan server. In order to keep your computer safe,follow the instructions. For further details see the attach. For security reasons attached file is password protected. The password is "82755". Have a good day, 'YOUR COMPANY NAME" YOUR COMPANY WEBSITE.
2004-10-29
According to a Symantec Corp. security alert "Instant Messaging" clients and servers using 32-bit versions of Microsoft Corp.'s Windows platform, Windows XP and Windows Server 2003 are vulnerable. Unaffected 64-bit versions of Windows running on Advanced Micro Devices Inc. or Intel Corp. Called W32.FUNNER, the worm circulated to attack on the Windows Messenger platform. Upon infection, the worm spreads itself through the host's MSN Messenger contact list and alters the Windows's host file, adding more than 900 URLs, reportedly Asian pornography and gaming sites. Symantec and several other security services categorized this attack as a "light," spread nuisance. When you're in an instant messaging environment you have a message that pops up and catches your attention, usually from a trusted individual. That's inherently different from e-mail and these worms have the potential to travel faster than e-mail worms.

16 APR 04
Starting in mid-April, the worm will spread itself by stealing email addresses from the infected computer, spoofing or forging the "from: field." It is a variant of the W32/Netsky.MM virus, W32/NETSKY.S@MM The Medium Risk mass-mailing worm that arrives inside a PIF attachment. It will also launch a Denial of Service attack on various domains, including www.kazaa.com. Look for:

From: Varies (forged addresses taken from infected system)
Subject: Varies - Hello!- Hi!- Re: Important
Body: Varies
Attachment: Varies, but has a .PIF extension. The filename is constructed from strings within the worm, with a random number appended to it
Examples: account - postcard - sample - development

09 APR 04
Another Bagle Virus---Disguised as an email security warning (e.g."Your e-mail account has been temporary disabled"), W32/BAGLE.N@MM is a Medium Risk mass-mailing worm and file infector and arrives inside an attachment, often an encrypted .ZIP or .RAR file with a password included in the email body or hidden within an image file attached to the message. Unlike its predecessors, it can also infect executable programs. Loof for:

From: Varies (forged addresses taken from infected system, a known e-mail)
Subject: Examples - E-mail account disabling warning.- E-mail account security warning.- E-mail technical support message
Body: Examples - We warn you about some attacks on your e-mail account. - Our antivirus software has detected a large amount of viruses outgoing from your email account
Attachment: Varies. ZIP, .EXE, .PIF, RAR, BMP, .JPG or .GIF image file

21 MAR 04
Be Prepared--If you receive a message from ADMINISTRATION@ with the name of your server) and the subject line reads "Important notify about your e-mail account" or something similar. and the body of the message contains directions as seen below...DO NOT OPEN FILE....this is a virus.......

Dear user of MADSearch.com e-mail server gateway,

Your e-mail account has been temporary disabled because of unauthorized access. Further details can be obtained from attached file. For security purposes the attached file is password protected. Password is "82567".

Best wishes,

The MADSearch.com team
http://www.MADSearch.com

29 FEB 04
W32/MYDOOM.F@MM
is a mass-mailing worm that can open up hacker backdoors on infected systems and launch denial-of-service attacks that target www.microsoft.com and www.riaa.com domains. Unlike previous versions this Mydoom can also delete image, movie, Excel and Word files on an infected machine. The worm arrives with random subject lines, such as "Please read," "Something for you" or "Please reply". The body of the e-mail contains an executable file often disguised as a text file.
What to look for:

From: Randomly generated <spoofed>
Subject: Examples include: Announcement, ApprovedNews, Attention, automatic responder, Bug...
Body: Varies. Examples include: Check the attached document, Details are in the attached document, You need Microsoft Office to open it, Greetings, Here is the document, Here it is, I have your password :)
Attachment: Varies. Examples: .cmd, .bat, .exe, .pif, .cmd and .scr, but often arrives in a .zip archive. 34,686 bytes. Examples include: creditcard.bat, creditcard.zip, paypal.zip, photo.zip, textfile.zip

29 FEB 04
Caution: An infected email can come from addresses you recognize. W32/BAGLE.C@MM is a Medium Risk mass-mailing worm with a potentially dangerous remote access component that may open a backdoor on an infected computer to hackers. W32/Bagle.c@MM arrives as a .ZIP attachment. When run, the virus emails itself to addresses it steals from the infected computer. The virus does not mass-mail itself to addresses that contain @avp., @hotmail.com, @microsoft, @msn.com, local, noreply, postmaster@, and root@. The virus also attempts to terminate the process of several security programs.
22 FEB 04
There is a new virus called W32.NETSKY spreading on the internet. This is a potentially very destructive virus. DO NOT OPEN ANY E-MAILS that have the subject: hi, hello, read it immediately, something for you, warning, information, stolen, fake, unknown OR message lines reading: anything or everything ok, what does it mean?, ok, I'm waiting, read the details, here is the document, read it immediately, my hero, here, is that true?, is that your name?, is that your account? We suggest printing the list and taking it home. Delete any e-mails that you receive on your home PCs and make sure that your Antivirus software is up to date. More Information.

15 JAN 04
W32/MIMAIL.S@MM
is a Medium Risk mass-mailing worm that tries to steal credit card information by displaying a fake Microsoft Windows license expiration message. Stolen credit numbers are sent to addresses within the domains @mail15.com and @ziplip.com. W32/Mimail.s@MM also forwards itself to contacts it steals from the infected machine. What to look for:

From: An infected email can come from people you know
Subject: here is the file you asked for
Body: Hi! Here is the file you asked for
Attachment: example--document.txt.scr;
Possible File Extensions: .pif, .scr, .exe, .jpg.scr, .jpg.pif, .jpg.exe, .gif.exe, .gif.pif, .gif.scr
Aliases: W32.Mimail.R@mm.

24 AUG 03
A new variant of W32/Sobig, W32/SOBIG.F@MM is a high risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine. In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses.

Note: The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE

30 MAR 03
From the pen of JAMES SPELLOS, CMP President, Meeting U., news on a free anti-v software for home (non-commercial) users from Alwil Software which distributes Avast. Recently Tudogs, one of the top and most reputable providers of free software, highlighted Avast as a top selection. Website Avast | Website Tudogs