Computer upgrades, repairs, troubleshooting and consulting services. Products, virus and malware alerts  FAQs and VFaqs.

 

The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

CpuCare.com Home PageBusiness to Business Contact

Virus and Malware Alerts

 

We Build the Best & Repair the Rest! ©

 

Alerts June 2001

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


Alerts 2000 Alerts January 2001 Alerts February 2001 Alerts March 2001 Alerts April 2001 Alerts May 2001 Alerts June 2001 Alerts July 2001 Alerts August 2001 Alerts September 2001 Alerts October 2001 Alerts November 2001 Alerts December 2001

 

 

 

 

Top 10 malware reported to Sophos in June 2001

Position Last
month
Malware Percentage of reports
1 2 W32/Magistr-A
   22.2%
2 4 W32/Badtrans-A
   10.9%
3 1 VBS/VBSWG-X
   9.6%
4 5 W32/Apology-B
   7.4%
5 3 W32/Hybris-B
   6.3%
6 New Troj/Keylog-C
   4.6%
7 9= W32/Flcss
   2.8%
8 Re-entry W32/Navidad-B
   2.6%
9= 6 VBS/Kakworm
   2.2%
9= 7 VBS/VBSWG-Z
   2.2%
Others 29.2%

 

 

This section helps you to understand how it behaves

W32/Apology-B is a file infecting virus with email-aware worm and backdoor characteristics.

During the infection process the virus creates three hidden files in the windows directory.

IE_Pack.exe contains code which modifies wsock32.dll. Win32.dll is a copy of the file sent by email, it contains code for all components of the virus. MTX_.exe is the backdoor component. When it is executed it tries to connect to a website and download further programs to run.

The virus replaces wsock32.dll with a modified version which monitors network traffic. When the virus detects the user sending an email, it will send another to the same recipient. The message will have no subject or body text, only an attachment with one of the following names:

README.TXT.pif
I_wanna_see_YOU.TXT.pif
MATRiX_Screen_Saver.SCR
LOVE_LETTER_FOR_YOU.TXT.pif
NEW_playboy_Screen_saver.SCR
BILL_GATES_PIECE.JPG.pif
TIAZINHA.JPG.pif
FEITICEIRA_NUA.JPG.pif
Geocities_Free_sites.TXT.pif
NEW_NAPSTER_site.TXT.pif
METALLICA_SONG.MP3.pif
ANTI_CIH.EXE
INTERNET_SECURITY_FORUM.DOC.pif
ALANIS_Screen_Saver.SCR
READER_DIGEST_LETTER.TXT.pif
WIN_$100_NOW.DOC.pif
IS_LINUX_GOOD_ENOUGH!.TXT.pif
QI_TEST.EXE
AVP_Updates.EXE
SEICHO-NO-IE.EXE
YOU_are_FAT!.TXT.pif
FREE_xxx_sites.TXT.pif
I_am_sorry.DOC.pif
Me_nude.AVI.pif
Sorry_about_yesterday.DOC.pif
Protect_your_credit.HTML.pif
JIMI_HMNDRIX.MP3.pif
HANSON.SCR
FUCKING_WITH_DOGS.SCR
MATRiX_2_is_OUT.SCR
zipped_files.EXE
BLINK_182.MP3.pif

When it is active the virus will also attempt to block user access to websites which contain information about viruses. It blocks access to sites whose URLs include text from the list below.

NII.
nai.
avp.
AVP.
F-Se
f-se
mapl
pand
soph
ndmi
afee
yenn
lywa
tbav
yman

It also prevents the user from sending email to organisations whose domain name begins with text from the following list

NII.
nai.
avp.
AVP.
F-Se
f-se
wildlist.o
il.esafe.c
perfectsup
complex.is
HiServ.com
hiserv.com
metro.ch
beyond.com
mcafee.com
pandasoftw
earthlink.
inexar.com
comkom.co.
meditrade.
mabex.com
cellco.com
symantec.c
successful
inforamp.n
newell.com
singnet.co
bmcd.com.a
bca.com.nz
trendmicro
sophos.com
maple.com.
netsales.n
f-secure.c
F-Secure.c

If you detect W32/Apology-B we recommend using Sophos Anti-Virus in full mode to detect all fragments which may be present on the PC.


 

 

Google
 


 

 

This webpage is optimized for 800 x 600 monitor resolution or above and the latest web browser. 

 

 

 

Copyright © 1998 The Computer Guys

 Back Home Up Next