The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

We Build the Best & Repair the Rest! ©

 

Alerts February 2002

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


October 2002 2001 Alerts  2001 Alerts January 2002 Alerts February 2002 Alerts March 2002 Alerts April 2002 Alerts May 2002 Alerts June 2002 Alerts July 2002 Alerts August 2002 Alerts Sept 2002 Alerts Oct 2002 Alerts Nov 2002 Alerts Dec 2002

 

 

 

 

Top 10 malware reported to Sophos in February 2002

Position Last
month
Malware Percentage of reports
1 2 W32/MyParty-A
   18.9%
2 1 W32/Badtrans-B
   15.7%
3 8= W32/Klez-E
   13.5%
4 New W32/Klez-G
   10.0%
5 3 W32/Magistr-B
   4.8%
6 4 W32/Sircam-A
   4.5%
7 7 W32/Magistr-A
   3.2%
8 5 W32/Nimda-A
   1.8%
9 Re-entry W32/Hybris-B
   1.5%
10 Re-entry W32/ElKern-B
   1.4%
Others 24.7%

 

 

This section helps you to understand how it behaves

W32/MyParty-A is a Windows 32 email-aware worm which arrives as an email with the following characteristics:

Subject: new photos from my party!

Message text:

Hello!

My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!

Attached filename: www.myparty.yahoo.com

Some people may be fooled into believing the attached file is a link to a website.

If the attached file is executed between 25 January 2002 and 29 January 2002 (inclusive) the worm sends a copy of itself to everybody in the Windows Address book (except the current user) using a built in SMTP engine.

It gets the SMTP server information from the following registry key: HKCU\Software\Microsoft\Internet Account Manager\Accounts\00000001. Please note that W32/MyParty-A does not make any changes to the registry or any INI files. Furthermore, it does not attempt to run itself when the computer is restarted.

The worm also sends an email to napster@gala.net, a free email account based in Russia, to track its spread.

In addition on Windows NT/2000/XP the worm drops a copy of the Trojan Troj/Msstake-A in the user's startup directory. The Trojan is contained in a file named msstask.exe.


 

 

Google
 


 

 

This webpage is optimized for 800 x 600 monitor resolution or above and the latest web browser. 

 

 

 

Copyright © 1998 The Computer Guys

 Back Home Up Next