The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

We Build the Best & Repair the Rest! ©

 

Alerts Nov 2002

FAQ Search Virus Alerts Hardware Faqs

 

 

Computer Repair
PC Maintenance
Disaster Recovery
SpyWare Removal
Company Profile
Disclaimer
Contact Information
Home Users

 

 


October 2002 2001 Alerts  2001 Alerts January 2002 Alerts February 2002 Alerts March 2002 Alerts April 2002 Alerts May 2002 Alerts June 2002 Alerts July 2002 Alerts August 2002 Alerts Sept 2002 Alerts Oct 2002 Alerts Nov 2002 Alerts Dec 2002

 

 

 

 

Top 10 malware reported to Sophos in November 2002

Position Last
month
Malware Percentage of reports
1 1 W32/Bugbear-A
   29.4%
2 New W32/Braid-A
   8.5%
3 2 W32/Klez-H
   7.7%
4 3 W32/Opaserv-A
   5.4%
5 6= W32/Opaserv-C
   5.1%
6 Re-entry W32/Flcss
   4.6%
7 Re-entry W95/Spaces
   3.3%
8 New W32/Opaserv-F
   2.5%
9 10 W32/Opaserv-B
   2.1%
10 6= W32/Opaserv-D
   2.0%
Others 29.4%

 

This section helps you to understand how it behaves

W32/Braid-A is an internet worm which emails itself to every contact in the Microsoft Outlook address book.

The worm attempts to exploit a MIME and an IFRAME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express, and Internet Explorer. These vulnerabilities allow an executable attachment to run automatically, even if you do not double-click on the attachment. Microsoft has issued a patch which secures against these attacks. The patch can be downloaded from Microsoft Security Bulletin MS01-027. (This patch was released to fix a number of vulnerabilities in Microsoft's software, including the ones exploited by this worm.)

When the worm is first run it copies itself to the Desktop as Explorer.exe, to the System folder as Regedit.exe and creates the registry entry

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\regedit = C:\WINDOWS\SYSTEM\regedit.exe

so that this file is run automatically each time the computer is restarted.

The worm drops W32/Flcss to the System folder as Bride.exe. Bride.exe is then launched whenever another executable is run.

 

Backdoor-ANK 11/29/2002 Low Low 4237
W95/CIH.1106 11/28/2002 Low-Profiled Low-Profiled 4236
W32/Holar.b@MM 11/27/2002 Low Low 4236
VBS/Cybarm.a 11/26/2002 Low Low 4102
X97M/Yawn.n@MM 11/26/2002 Low Low 4236
W32/GOP.j@MM 11/26/2002 Low Low 4235
W32/Korvar 11/24/2002 Low-Profiled Low-Profiled 4235
Friend Greeting application (IV) 11/21/2002 N/A N/A 4231
Hide Minimized 11/21/2002 Low Low 4235
W32/Braid.b@MM 11/18/2002 Low Low 4234
Downloader-BO.dr 11/16/2002 Low Low 4234
Friend Greeting application (III) 11/13/2002 N/A N/A 4234
QDel297 11/13/2002 Low Low 4234
Downloader-BO.b 11/12/2002 Low Low 4233
W32/Pepex.c@MM 11/11/2002 Low Low 4233
Diskfill-F 11/11/2002 Low Low 4234
W32/Acinti.worm 11/11/2002 Low Low 4233
BackDoor-AML 11/10/2002 Low Low 4233
Downloader-BO 11/10/2002 Low Low 4233
W32/Fregit.a@MM 11/08/2002 Low Low 4233
Friend Greeting application (II) 11/08/2002 N/A N/A 4234
Downloader-BN.b 11/07/2002 Low Low 4233
W32/Oror.b@MM 11/06/2002 Low Low 4231
W32/Oror.e@MM 11/05/2002 Low-Profiled Low-Profiled 4232
BackDoor-AMH 11/05/2002 Low Low 4233
VBS/VBSWG.aw@MM 11/05/2002 Low Low 4232
W32/Braid@MM 11/04/2002 Low-Profiled Low-Profiled 4232
W32/Poscal.worm 11/02/2002 Low Low 4233
Downloader-BN 11/01/2002 Low Low 4232




 

Google
 
This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

Copyright © 1998 The Computer Guys

 Back Home Up Next