The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

We Build the Best & Repair the Rest! ©

 
FAQ Search Virus Alerts Hardware Faqs
 

Home
March 2004
August 2004
November 2004
October 2004
April 2004
July 2004
Virus Alert Calendars
May 2004
September 2004
June 2004
January 2004
February 2004
Alerts 2003
Alerts Jan 2004
Alerts Feb 2004
Alerts March 2004
Alerts April 2004
Alerts Top 10 May 2004
Alerts Top10 June 2004
Alerts Top 10 July 2004
Alerts August 2004
Alerts September 2004
Alerts Oct 2004
Alerts November 2004
Alerts December 2004

 

April 2003 Alerts 2002 Alert Jan 2003 Alert February 2003 Alerts March 2003 Alerts April 2003 Alerts May 2003 Alerts June 2003 Alerts July 2003 Alerts August 2003 Alerts September 2003 Alerts October 2003 Alerts November 2003 Alerts December 2003

 

 

 

Top 10 malware reported to Sophos in January 2003

Position Last
month
Malware Percentage of reports
1 New W32/Avril-B
   16.8%
2 New W32/Avril-A
   12.4%
3 2 W32/Klez-H
   12.1%
4 New W32/Sobig-A
   6.1%
5 New W32/Yaha-K
   5.7%
6 1 W32/Bugbear-A
   5.6%
7 Re-entry W32/Yaha-E
   3.3%
8 9= W32/ElKern-C
   2.1%
9 Re-entry W95/Spaces
   1.5%
10 Re-entry W32/Flcss
   1.2%
Others 33.2%

 

This section helps you to understand how it behaves

W32/Avril-B is an internet worm which spreads via email. W32/Avril-B is an extended variant of W32/Avril-A. For information on the generic features of W32/Avril-B see the description of W32/Avril-A.

W32/Avril-B differs from W32/Avril-A as follows.

The format of the sent email has changed to the following:

Subject line - one of the following 16:
Fw: Avril Lavigne - CHART ATTACK!
Fw: F. M. Dostoyevsky "Crime and Punishment"
Fw: Redirection error notification
Fwd: Re: Have U requested Avril Lavigne bio?
Fwd: Re: Reply on account for Incorrect MIME-header
Fwd: RFC-0245 Specification requested...
Fwd: RFC-0841 Specification requested...
Re: According to Purge's Statement
Re: ACTR/ACCELS Transcriptions
Re: Brigada Ocho Free membership
Re: Ha perduto qualque cosa signora?
Re: IREX admits you to take in FSAU 2003
Re: Junior Achievement
Re: Reply on account for IFRAME-Security breach
Re: Reply on account for IIS-Security Breach (TFTP)
Re: Vote seniors masters - don't miss it!

Message text - may contain one of the following 4 alternatives, but they might be skipped and hence not included:

"AVRIL LAVIGNE - THE CHART ATTACK!
Vote fo4r Complicated!
Vote fo4r Sk8er Boi!
Vote fo4r I'm with you!
Chart attack active list:"

"Restricted area response team (RART)
Attachment you sent to is intended to overwrite
start address at 0000:HH4F
To prevent from the further buffer overflow attacks apply the MSO-patch"

"Network Associates weekly report:
Microsoft has identified a security vulnerability in Microsoft®
IIS 4.0 and 5.0 that is eliminated by a previously-released patch.
Customers who have applied that patch are already protected
against the vulnerability and do not need to take additional action.
Microsoft strongly urges all customers using IIS 4.0 and 5.0 who
have not already done so to apply the patch immediately.
Patch is also provided to subscribed list of Microsoft® Tech Support:"

"AVRIL LAVIGNE - THE BEST
Avril Lavigne's popularity increases:>
SO: First, Vote on TRL for I'm With U!
Next, Update your pics database!
Chart attack active list .>.>"

Attachment exe - one of the following 21:
ADialer.exe
ALavigne.exe
AvrilLavigne.exe
AvrilSmiles.exe
BioData.exe
CERT-Vuln-Info.exe
Cogito_Ergo_Sum.exe
Complicated.exe
EntradoDePer.exe
IAmWiThYoU.exe
MSO-Patch-0035.exe
MSO-Patch-0071.exe
Phantom.exe
Readme.exe
Resume.exe
SiamoDiTe.exe
Sk8erBoi.exe
Sophos.exe
Transcripts.exe
TrickerTape.exe
Two-Up-Secretly.exe

The worm may also attach a TXT, HTM, DOC or HTML file to the email from the Personal folder of the user.

W32/Avril-B tries to update itself from the web and also tries to download a backdoor Trojan (apparently Back Orifice 2K) from the web and run it on the user's computer. At the time of this writing the corresponding URL was unavailable. The worm would download the backdoor Trojan into <Windows system>\bo2k.exe and set the following registry entry:

HKLML\Software\Microsoft\Windows\CurrentVersion\Run\SocketListener =
<Windows system>\bo2k.exe

W32/Avril-B drops a different version of the text file avril-ii.inf and sends the cached passwords to different email addresses.

The payload has also been changed slightly, in that the text displayed in the top left corner of the screen is now "AVRIL_LAVIGNE_LET_GO - MY_MUSE:) VOTE FOR I'm With YoU.


 

 

Our VIRUS Alert Page for  2003

        Here you will find recent virus alerts...

January 2003

Name Date Discovered Home Risk Corporate Risk Included In DAT
IRC/Backdoor.g 01/31/2003 Low Low 4247
FDoS-Wping 01/31/2003 Low Low 4247
DDoS-Smurf 01/31/2003 Low Low 4247
Exploit-IISInjector 01/31/2003 Low Low 4247
ProcKill-Z 01/30/2003 Low Low 4246
IRC-Emoz 01/30/2003 Low Low 4247
Keylog-Razytimer 01/30/2003 Low Low 4246
W32/Gemel.worm 01/29/2003 Low Low 4246
W32/Bibrog@MM 01/29/2003 Low Low 4246
Renamer.c 01/29/2003 Low Low 4246
DDoS-SQLhuc 01/28/2003 Low Low 4245
Sadhound 01/27/2003 Low-Profiled Low-Profiled 4245
W32/Netspree.worm 01/27/2003 Low Low 4245
W32/SQLSlammer.worm 01/25/2003 Low-Profiled Medium Stinger
W32/Pkasa@MM 01/24/2003 Low Low 4245
PWS-Likun 01/24/2003 Low Low 4246
Linux/Shinject 01/20/2003 Low Low 4245
PornDial-143 application 01/20/2003 Low Low 4245
W32/Eslac.worm 01/16/2003 Low Low 4244
JS/Spth 01/16/2003 Low Low 4244
IRC/Backdoor.f 01/15/2003 Low Low 4244
QDial4 01/15/2003 Low Low 4244
Downloader-BS 01/15/2003 Low Low 4244
Exploit-JBellz 01/14/2003 Low-Profiled Low-Profiled 4244
MultiDropper-FE 01/14/2003 Low Low 4244
W32/Sahay.worm 01/13/2003 Low-Profiled Low-Profiled 4243
DoS-Atho 01/10/2003 Low Low 4244
W32/Sobig@MM 01/09/2003 Low Low 4242
W32/Lirva.c@MM 01/08/2003 Low Low 4241
W32/Lirva.gen@MM 01/07/2003 Low Low 4241
W32/Lirva.a@MM 01/06/2003 Low-Profiled Low-Profiled 4241
MultiDropper-FD 01/06/2003 Low Low 4242
W32/Speedup.worm 01/06/2003 Low Low 4242
W32/Yaha.m@MM 01/06/2003 Low Low 4241
Backdoor-AOK 01/06/2003 Low Low 4242
W32/Revocer@MM 01/03/2003 Low Low 4241
IRC-OhShootBot 01/03/2003 Low Low 4242
W32/Parved 01/02/2003 Low Low 4242
IRC/Backdoor.e 01/02/2003 Low Low 4241
W32/Etern.worm 01/01/2003 Low Low 4241

Google
 
This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next