The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

 

We Build the Best & Repair the Rest! ©

 
FAQ Search Virus Alerts Hardware Faqs
 

Home
March 2004
August 2004
November 2004
October 2004
April 2004
July 2004
Virus Alert Calendars
May 2004
September 2004
June 2004
January 2004
February 2004
Alerts 2003
Alerts Jan 2004
Alerts Feb 2004
Alerts March 2004
Alerts April 2004
Alerts Top 10 May 2004
Alerts Top10 June 2004
Alerts Top 10 July 2004
Alerts August 2004
Alerts September 2004
Alerts Oct 2004
Alerts November 2004
Alerts December 2004

 

 

April 2003 Alerts 2002 Alert Jan 2003 Alert February 2003 Alerts March 2003 Alerts April 2003 Alerts May 2003 Alerts June 2003 Alerts July 2003 Alerts August 2003 Alerts September 2003 Alerts October 2003 Alerts November 2003 Alerts December 2003

 

 

 

Top 10 malware reported to Sophos in February 2003

Position Last
month
Malware Percentage of reports
1 3 W32/Klez-H
   13.7%
2 4 W32/Sobig-A
   7.7%
3 1 W32/Avril-B
   6.0%
4 7 W32/Yaha-E
   4.6%
5 6 W32/Bugbear-A
   4.3%
6 2 W32/Avril-A
   3.1%
7 Re-entry W32/Klez-E
   2.4%
8 5 W32/Yaha-K
   2.4%
9 New W32/Lovgate-B
   2.1%
10 Re-entry W95/Spaces
   2.1%
Others 51.6%

 

This section helps you to understand how it behaves
W32/Sobig-A is a worm that uses a built-in SMTP client and local Windows network shares to spread.

W32/Sobig-A arrives in an email with the following characteristics:

From: big@boss.com

Subject line -chosen from:
Re: Movies
Re: Sample
Re: Document
Re: Here is that sample

Attached file - chosen from:
Document003.pif
Sample.pif
Untitled1.pif
Movie_0074.mpeg.pif

The worm searches the local hard drive for files with the extensions TXT, HTML, EML, HTM, WAB and DBX. The files are used to extract a list of recipient email addresses that will be used by the worm to send infected emails.

When the attachment is run, W32/Sobig-A copies itself into the Windows folder as Winmgm32.exe and creates a new process by running the file.

W32/Sobig-A creates the following registry values to run itself on Windows startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WindowsMGM
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsMGM

The worm connects to a website and attempts to download the file reteral.txt which contains a URL to another file. W32/Sobig-A then attempts to download and run the referenced file.

The worm also attempts to copy itself onto Windows shares of the local network if the folders Windows\All Users\Start Menu\Programs\StartUp or
Documents and Settings\All Users\Start Menu\Programs\Startup exist in a shared folder.
 

 

Our VIRUS Alert Page for  2003

        Here you will find recent virus alerts...

Descriptions for Newly Discovered Threats (Includes Viruses, Trojans and Hoaxes)
Name Date Discovered Home Risk Corporate Risk Included In DAT
W32/Yaha.p@MM 02/28/2003 Low Low 4251
BackDoor-AQO 02/27/2003 Low Low 4251
BackDoor-AQL 02/25/2003 Low Low 4251
W32/Chowl@MM 02/25/2003 Low Low 4251
W32/Gibe.b@MM 02/24/2003 Low Low 4250
X97M/Rawo 02/24/2003 Low Low 4251
W32/Lovgate@M 02/23/2003 Low-Profiled Low-Profiled 4249
ICQPager-J 02/20/2003 Low Low 4249
VBS/Grimgram@MM 02/19/2003 Low Low 4249
DoS-iFrameNet 02/19/2003 Low Low 4249
W32/Lovgate@M 02/19/2003 Low Low 4248
IRC-Yoink 02/17/2003 Low Low 4249
W32/Gant@MM 02/17/2003 Low Low 4248
W32/Proget.worm.b 02/14/2003 Low Low 4248
ZeroPopup application 02/14/2003 N/A N/A 4248
Tellafriend 02/14/2003 Low Low 4248
PWS-Aileen 02/12/2003 Low Low 4249
W32/Ixas@MM 02/11/2003 Low Low 4248
AdwareDropper-A 02/11/2003 Low-Profiled Low-Profiled 4247
PWS-NTSMB 02/10/2003 Low Low 4247
W32/Gool.worm 02/10/2003 Low-Profiled Low-Profiled 4247
W32/Maax@MM 02/08/2003 Low Low 4248
IRC-Demfire 02/07/2003 Low Low 4247
W32/Discoball.worm 02/06/2003 Low Low 4247
VBS/Cian 02/04/2003 Low Low 4247
W32/Winur.worm.b 02/04/2003 Low Low 4246
W32/Winur.worm.a 02/04/2003 Low Low 4246
Xin 02/04/2003 Low Low 4247
HackerDefender 02/03/2003 Low Low 4246
VBS/Waterworks.worm 02/03/2003 Low Low 4246
JS/Fortnight.b@M 02/03/2003 Low Low 4247
VBS/Sludge.worm 02/03/2003 Low Low 4246
IRC/Flood.bi 02/02/2003 Low Low 4246

 

Google
 
This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next