The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

 

We Build the Best & Repair the Rest! ©

 
FAQ Search Virus Alerts Hardware Faqs
 

Home
March 2004
August 2004
November 2004
October 2004
April 2004
July 2004
Virus Alert Calendars
May 2004
September 2004
June 2004
January 2004
February 2004
Alerts 2003
Alerts Jan 2004
Alerts Feb 2004
Alerts March 2004
Alerts April 2004
Alerts Top 10 May 2004
Alerts Top10 June 2004
Alerts Top 10 July 2004
Alerts August 2004
Alerts September 2004
Alerts Oct 2004
Alerts November 2004
Alerts December 2004

 

 

April 2003 Alerts 2002 Alert Jan 2003 Alert February 2003 Alerts March 2003 Alerts April 2003 Alerts May 2003 Alerts June 2003 Alerts July 2003 Alerts August 2003 Alerts September 2003 Alerts October 2003 Alerts November 2003 Alerts December 2003

 

 

 

Top 10 malware reported to Sophos in March 2003

Position Last
month
Malware Percentage of reports
1 1 W32/Klez-H
   15.3%
2 2 W32/Sobig-A
   5.2%
3 New W32/Gibe-D
   4.4%
4 3 W32/Avril-B
   3.2%
5 4 W32/Yaha-E
   3.0%
6 6 W32/Avril-A
   2.6%
7 7 W32/Yaha-K
   2.4%
8 5 W32/Bugbear-A
   2.2%
9 Re-entry JS/NoClose
   2.0%
10 9 W32/Lovgate-B
   2.0%
Others 57.7%

 

This section helps you to understand how it behaves

W32/Gibe-D is a worm which spreads by sending out email and by making itself available for download via the KaZaA peer-to-peer file sharing system.

If you run an infected file, W32/Gibe-D pops up a dialog claiming to be a Microsoft security update. (Microsoft never send out security updates via email, and never publish security updates on peer-to-peer file sharing networks.)

W32/Gibe-D drops a number of files onto your hard disk. These include a file named DX3DRndr.exe (detected by this identity), which is a mailing program. W32/Gibe-D also makes copies of itself, including multiple copies in your KaZaA folder. These files may have a variey of names, including:

IEPatch.exe
KaZaA upload.exe
Porn.exe
Sex.exe
XboX Emulator.exe
PS2 Emulator.exe
XP update.exe
XXX Video.exe
Sick Joke.exe
Free XXX Pictures.exe
My naked sister.exe
Hallucinogenic Screensaver.exe
Cooking with Cannabis.exe
Magic Mushrooms Growing.exe
I-Worm_Gibe Cleaner.exe

If you have mIRC installed, W32/Gibe-D also creates a file called Script.ini in your mIRC folder. This script is detected as mIRC/Simp-Fam.

The characteristics of the emails sent by W32/Gibe-D are variable but typically the subject line and message text are as follows:

Subject line: FWD: See these security patch from Microsoft.
Message text:
"----- Original message follows -----

Microsoft User

this is the latest version of security update, the
"February 2003, Cumulative Patch" update which eliminates all
known security vulnerabilities affecting Internet Explorer,
Outlook and Outlook Express as well as five newly discovered
vulnerabilities. Install now to protect your computer from these
vulnerabilities, the most serious of which could allow an attacker to
run executable on your system. This update includes the functionality
of all previously released patches.

System requirements:
Win 9x/Me/2000/NT/XP

This update applies to:
Microsoft Internet Explorer, version 4.01 and later
Microsoft Outlook, version 8.00 and later
Microsoft Outlook Express, version 4.01 and later

Recommendation:
Customers should install the patch at the earliest opportunity.

How to install:
Run attached file. Click Yes on displayed dialog box.

How to use:
You don't need to do anything after installing this item.

Microsoft Technical Support is available at
http://support.microsoft.com/

For security-related information about Microsoft products,
please visit the Microsoft Security Advisor web site at
http://www.microsoft.com/security

Contact us at
http://www.microsoft.com/isapi/goregwiz.asp?target=/contactus/contactus.asp


Please do not reply to this message. It was sent from an unmonitored
e-mail address and we are unable to respond to any replies.

Thank you for using Microsoft products."

The attached file is usually called UPDATE???.EXE where ??? is a random three-digit number.


 

 

Our VIRUS Alert Post Page for  2003

        Here you will find recent virus alerts...

Name Date Discovered Home Risk Corporate Risk Included In DAT
W32/Lanet@MM 03/31/2003 Low Low 4255
W32/Trab.worm 03/28/2003 Low Low 4256
PWS-WMPatch 03/28/2003 Low Low 4255
Free-Scratch-Cards application 03/27/2003 N/A N/A 4256
AIM-Canbot 03/27/2003 Low Low 4256
Uploader-D.b 03/26/2003 Low Low 4255
BackDoor-ASD 03/25/2003 Low Low 4255
BackDoor-ASE 03/25/2003 Low Low 4255
Butterfly joke 03/25/2003 Low Low 4255
Exploit-MS03-007.Crpt 03/24/2003 Low-Profiled Low-Profiled 4254
W32/Bibrog.e@MM 03/24/2003 Low Low 4254
W32/Lovgate.f@M 03/22/2003 Low-Profiled Low-Profiled 4254
W32/Wanor@MM 03/21/2003 Low Low 4254
Kit-Verg 03/21/2003 Low Low 4255
Qdel376 03/21/2003 Low Low 4254
VTool/Sharpei application 03/21/2003 N/A N/A 4254
Qdel375 03/21/2003 Low Low 4254
Qdel374 03/21/2003 Low Low 4254
Exploit-BadBlue 03/20/2003 Low Low 4256
JS/Exploit-MS03-008 03/20/2003 Low Low 4254
Uploader-D.a 03/20/2003 Low Low 4254
Stoplete 03/20/2003 Low Low 4254
W32/Holar.e@MM 03/20/2003 Low Low 4254
W32/Holar.d@MM 03/19/2003 Low Low 4253
IRC-Picthfork 03/09/2003 Low Low 4252
BackDoor-ARG 03/09/2003 Low Low 4252
W32/Deloder.worm 03/09/2003 Low Low 4252
MultiDropper-FL 03/06/2003 Low Low 4252
ProcKill-AF 03/06/2003 Low Low 4252
Backdoor-AFC 03/06/2003 Low Low 4206
BackDoor-AQT 03/05/2003 Low Low 4252
Downloader-BW 03/05/2003 Low Low 4248
W32/Bibrog.b@MM 03/05/2003 Low Low 4252
PhoenixScan application 03/05/2003 N/A N/A 4252
KeyLog-Kerlib 03/04/2003 Low Low 4252
W32/AimVen.worm 03/04/2003 Low Low 4252
ProcKill-AE 03/03/2003 Low Low 4252
Linux/Exploit-SendMail 03/03/2003 Low Low 4252
IRC/Flood.ap 03/03/2003 Low Low 4251
W32/Rackum.worm 03/03/2003 Low Low 4251
Backdoor-AQP 03/03/2003 Low Low 4252

 

 

Google
 
This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next