2004-10-29
We don't know its name but the message is the following &
DO NOT OPEN: Some of our clients complained about the spam (negative
e-mail content) outgoing from your e-mail account. Probably,
you have been infected by a proxy-relay trojan server. In order
to keep your computer safe,follow the instructions. For further
details see the attach. For security reasons attached file is
password protected. The password is "82755". Have
a good day, 'YOUR COMPANY NAME" YOUR COMPANY WEBSITE.
2004-10-29
According
to a Symantec Corp. security alert "Instant Messaging"
clients and servers using 32-bit versions of Microsoft Corp.'s
Windows platform, Windows XP and Windows Server 2003 are vulnerable.
Unaffected 64-bit versions of Windows running on Advanced Micro
Devices Inc. or Intel Corp. Called W32.FUNNER,
the worm circulated to attack on the Windows Messenger platform.
Upon infection, the worm spreads itself through the host's MSN
Messenger contact list and alters the Windows's host file, adding
more than 900 URLs, reportedly Asian pornography and gaming
sites. Symantec and several other security services categorized
this attack as a "light," spread nuisance. When you're
in an instant messaging environment you have a message that
pops up and catches your attention, usually from a trusted individual.
That's inherently different from e-mail and these worms have
the potential to travel faster than e-mail worms.
16
APR 04
Starting
in mid-April, the worm will spread itself by stealing email
addresses from the infected computer, spoofing or forging
the "from: field." It is a variant of the W32/Netsky.MM
virus, W32/NETSKY.S@MM
The Medium Risk mass-mailing worm that arrives inside a PIF
attachment. It will also launch a Denial of Service attack
on various domains, including www.kazaa.com. Look for:
From:
Varies (forged addresses taken from infected system) Subject: Varies - Hello!- Hi!- Re: Important Body: Varies Attachment: Varies, but has a .PIF extension.
The filename is constructed from strings within the worm,
with a random number appended to it Examples: account - postcard - sample -
development
09
APR 04
Another Bagle Virus---Disguised as an email security warning
(e.g."Your e-mail account has been temporary disabled"),
W32/BAGLE.N@MM
is a Medium Risk mass-mailing worm and file infector and arrives
inside an attachment, often an encrypted .ZIP or .RAR file
with a password included in the email body or hidden within
an image file attached to the message. Unlike its predecessors,
it can also infect executable programs. Loof for:
From:
Varies (forged addresses taken from infected system, a known
e-mail) Subject: Examples - E-mail account disabling
warning.- E-mail account security warning.- E-mail technical
support message Body: Examples - We warn you about some
attacks on your e-mail account. - Our antivirus software
has detected a large amount of viruses outgoing from your
email account Attachment: Varies. ZIP, .EXE, .PIF, RAR,
BMP, .JPG or .GIF image file
21
MAR 04 Be
Prepared--If you receive a message from ADMINISTRATION@
with the name of your server) and the subject line reads "Important
notify about your e-mail account" or something similar.
and the body of the message contains directions as seen below...DO
NOT OPEN FILE....this is a virus.......
Dear
user of MADSearch.com e-mail server gateway,
Your
e-mail account has been temporary disabled because of unauthorized
access. Further details can be obtained from attached file.
For security purposes the attached file is password protected.
Password is "82567".
Best
wishes,
The
MADSearch.com team
http://www.MADSearch.com
29
FEB 04
W32/MYDOOM.F@MM is a mass-mailing worm that
can open up hacker backdoors on infected systems and launch
denial-of-service attacks that target www.microsoft.com and
www.riaa.com domains. Unlike previous versions this Mydoom
can also delete image, movie, Excel and Word files on an infected
machine. The worm arrives with random subject lines, such
as "Please read," "Something for you"
or "Please reply". The body of the e-mail contains
an executable file often disguised as a text file.
What to look for:
From:
Randomly generated <spoofed> Subject:
Examples include: Announcement, ApprovedNews, Attention,
automatic responder, Bug... Body:
Varies. Examples include: Check the attached document, Details
are in the attached document, You need Microsoft Office
to open it, Greetings, Here is the document, Here it is,
I have your password :) Attachment:
Varies. Examples: .cmd, .bat, .exe, .pif, .cmd and .scr,
but often arrives in a .zip archive. 34,686 bytes. Examples
include: creditcard.bat, creditcard.zip, paypal.zip, photo.zip,
textfile.zip
29
FEB 04
Caution: An infected email can come from addresses you recognize.
W32/BAGLE.C@MM
is a Medium Risk mass-mailing worm with a potentially dangerous
remote access component that may open a backdoor on an infected
computer to hackers. W32/Bagle.c@MM arrives as a .ZIP attachment.
When run, the virus emails itself to addresses it steals from
the infected computer. The virus does not mass-mail itself to
addresses that contain @avp., @hotmail.com, @microsoft, @msn.com,
local, noreply, postmaster@, and root@. The virus also attempts
to terminate the process of several security programs.
22
FEB 04
There is a new virus called W32.NETSKY
spreading on the internet. This is a potentially very destructive
virus. DO NOT OPEN ANY E-MAILS that have the subject: hi, hello,
read it immediately, something for you, warning, information,
stolen, fake, unknown OR message lines reading: anything or
everything ok, what does it mean?, ok, I'm waiting, read the
details, here is the document, read it immediately, my hero,
here, is that true?, is that your name?, is that your account?
We suggest printing the list and taking it home. Delete any
e-mails that you receive on your home PCs and make sure that
your Antivirus software is up to date. More
Information.
15
JAN 04
W32/MIMAIL.S@MM is a Medium Risk mass-mailing
worm that tries to steal credit card information by displaying
a fake Microsoft Windows license expiration message. Stolen
credit numbers are sent to addresses within the domains @mail15.com
and @ziplip.com. W32/Mimail.s@MM also forwards itself to contacts
it steals from the infected machine. What to look for:
From:
An infected email can come from people you know Subject: here is the file you asked for Body: Hi! Here is the file you asked for Attachment: example--document.txt.scr; Possible
File Extensions: .pif, .scr, .exe, .jpg.scr, .jpg.pif,
.jpg.exe, .gif.exe, .gif.pif, .gif.scr Aliases: W32.Mimail.R@mm.
24
AUG 03 A new variant of W32/Sobig, W32/SOBIG.F@MM
is a high risk mass-mailing worm. It arrives as an email attachment
with a .pif or .scr extension. When run, it infects the host
computer, then emails itself (using its own SMTP engine) to
harvested email addresses from the victim's machine. In addition,
when it propagates, the worm "spoofs" the "from:
field", using one of the harvested email addresses.
Note:
The worm copies itself onto the infected machine as: C:\WINNT\WINPPR32.EXE
30
MAR 03
From the
pen of JAMES SPELLOS, CMP President, Meeting
U., news on a free anti-v software for home (non-commercial)
users from Alwil Software which distributes Avast. Recently
Tudogs, one of the top and most reputable providers of free
software, highlighted Avast as a top
selection. Website
Avast | Website
Tudogs