Computer upgrades, repairs, troubleshooting and consulting services. Products, virus and malware alerts  FAQs and VFaqs.

 

The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

CpuCare.com Home PageBusiness to Business Contact

Virus and Malware Alerts

 

We Build the Best & Repair the Rest! ©

 

Alerts December 2000

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


Top 10 1999 Alerts January 2000 Alerts February 2000 Alerts March 2000 Alerts April 2000 Alerts May 2000 Alerts June 2000 Alerts July 2000 Alerts August 2000 Alerts September 2000 Alerts October 2000 Alerts November 2000 Alerts December 2000

 

 

 

 

Top 10 malware reported to Sophos in December 2000

Position Last
month
Malware Percentage of reports
1 1 W32/Apology-B
   18.3%
2 New W32/Prolin
   16.1%
3 New W32/Hybris-B
   8.7%
4 2= W32/Navidad
   7.6%
5 2= VBS/Kakworm
   5.3%
6 New W32/Verona-B
   4.0%
7 New Troj/JetHome
   3.0%
8 5 VBS/LoveLet-AS
   2.5%
9= New W32/Bymer-A
   1.9%
9= New W32/Hybris-C
   1.9%
Others 30.7%

 

 

This section helps you to understand how it behaves

W32/Prolin is a worm which uses Microsoft Outlook to spread.

The worm arrives as an attachment to an email message with the subject "A great Shockwave flash movie". The body of the message contains the text "Check out this new flash movie that I downloaded just now...It's Great, Bye".

The attached filename is CREATIVE.EXE. If the attached file is run, the worm copies itself into C:\CREATIVE.EXE and C:\Windows\Start Menu\Programs\Startup\CREATIVE.EXE and sends itself as an attachment to all contacts from your Outlook address book. It also sends an email with the subject "Job complete" and the text "Got yet another idiot." to a Yahoo email address.

The worm looks for any files with the extension MP3, JPG and ZIP and moves them into the C:\ directory. The moved files remain unchanged but the worm renames them so that the extension is concatenated with the string "change at least now to Linux", e.g. from "Flowers.jpg" to "Flowers.jpgchange at least now to Linux".

In order to restore the files they should be moved to their default location and renamed so that the concatenated string is removed from the filename. The worm also creates a text file C:\Messageforu.txt which can help to restore the files. The file contains the following text:

"Hi, guess you have got this message. I have kept a list of files that I have infected under this. If you are smart enough just reverse back the process. i could have done far better damage, i could have even completely wiped you harddisk. Remember this is a warning & get it sound and clear... - The Penguin"

The file also contains a list of the previous locations for all the renamed files which were moved to the C:\ directory.
 

 

Google
 


 

 

This webpage is optimized for 800 x 600 monitor resolution or above and the latest web browser. 

 

 

 

Copyright © 1998 The Computer Guys

 Back Home Up