Computer upgrades, repairs, troubleshooting and consulting services. Products, virus and malware alerts  FAQs and VFaqs.

 

The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

CpuCare.com Home PageBusiness to Business Contact

Virus and Malware Alerts

 

We Build the Best & Repair the Rest! ©

 

Alerts August 1999

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


Top 10 Alerts 1998 Alerts January 1999 Alerts February 1999 Alerts March 1999 Alerts April 1999 Alerts May 1999 Alerts June 1999 Alerts July 1999 Alerts August 1999 Alerts September 1999 Alerts October 1999 Alerts November 1999 Alerts December 1999

 

 

 

 

Top 10 malware reported to Sophos in August 1999

Position Last
month
Malware Percentage of reports
1 6 WM97/Footer-A
   12.5%
2 5 WM97/Ethan
   11.5%
3 4 WM97/Melissa
   7.7%
4 Re-entry WM97/Marker-A
   7.2%
5 2= WM97/Class-D
   5.8%
6 2= W32/Ska-Happy99
   5.3%
7= Re-entry W95/CIH-10xx
   4.3%
7= 10 WM97/Story
   4.3%
9 New WM97/Locale-A
   3.4%
10 New WM97/Cont
   2.9%
Others 35.1%

 

 

This section is for technical experts who want to know more.
W32/Bagle-QW is a worm for the Windows platform.

W32/Bagle-QW spreads via email within a ZIP file.

W32/Bagle-QW includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Bagle-QW copies itself to:

<User>\Application Data\hidn\hidn2.exe
<User>\Application Data\hidn\hldrrr.exe

and creates the following files:

\error.txt - harmless file
\temp.zip - also detected as W32/Bagle-QW

The following registry entry is created to run hidn2.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
drv_st_key
<User>\Application Data\hidn\hidn2.exe

W32/Bagle-QW sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

Registry entries are created under:

HKCU\Software\FirstRun

Emails sent by the worm have the following characteristics:

Subject line chosen from:
new <date>
price<date>
price_ <date>
price_new <date>

The message text may be empty.

The attached file is named:
new_price<date>.zip
price_list<date>.zip
latest_price<date>.zip

<date> is the date the email was sent in the following format 12-Dec-2006.
 

 

Google
 


 

 

This webpage is optimized for 800 x 600 monitor resolution or above and the latest web browser. 

 

 

 

Copyright © 1998 The Computer Guys

 Back Home Up Next