The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

 

We Build the Best & Repair the Rest! ©

 
     

 

FAQ Search Virus Alerts Hardware Faqs
 

Home
Alerts 2004
Alerts January 2005
Alerts February 2005
Alerts March 2005
Alerts April 2005
Alerts May 2005
Alerts June 2005
Alerts July 2005
Alerts August 2005
Alerts September 2005
Alerts October 2005
Alerts November 2005
Alerts December 2005

 

  March 2004 August 2004 November 2004 October 2004 April 2004 July 2004 Virus Alert Calendars May 2004 September 2004 June 2004 January 2004 February 2004 Alerts 2003 Alerts Jan 2004 Alerts Feb 2004 Alerts March 2004 Alerts April 2004 Alerts Top 10 May 2004 Alerts Top10 June 2004 Alerts Top 10 July 2004 Alerts August 2004 Alerts September 2004 Alerts Oct 2004 Alerts November 2004 Alerts December 2004

 

Our VIRUS Alert Post for January 2004

Recent Virus Alerts

          Here you will find recent virus alerts...

 

Top 10 malware reported to Sophos in January 2004

Position Last
month
Malware Percentage of reports
1 New W32/MyDoom-A
   25.1%
2 New W32/Bagle-A
   16.3%
3 1 W32/Sober-C
   9.9%
4 3 W32/Dumaru-A
   5.3%
5 4 W32/Mimail-J
   3.1%
6 Re-entry W32/Mimail-A
   2.7%
7 2 W32/Mimail-K
   2.6%
8 5 W32/Mimail-C
   2.2%
9 6= W32/Mimail-I
   1.0%
10 8 W32/Klez-H
   0.8%
Others 31.0%

 

W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: WAB, TXT, HTM, SHT, PHP,
ASP, DBX, TBB, ADB and PL.
 

W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.


W32/MyDoom-A 'spoofs', using randomly chosen email addresses in the "To:" and "From:" fields as well as a randomly chosen subject line. The emails distributing this worm have the following characteristics.

 

Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]

 

Message texts
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.

 

Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]

Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP.

 

W32/MyDoom-A is programmed to not forward itself via email if the recipient email address satisfies various conditions:
 

bulletThe worm will not send itself to email addresses belonging to domains containing the following strings: acketst, arin., avp, berkeley, borlan, bsd, example, fido, foo., fsf., gnu, google, .gov, gov., hotmail, iana, ibm.com, icrosof, ietf, inpris, isc.o, isi.e, kernel, linux, math, .mil, mit.e, mozilla, msn., mydomai, nodomai, panda, pgp, rfc-ed, ripe., ruslis, secur, sendmail, sopho, syma, tanford.e, unix, usenet, utgers.ed

As a consequence the worm does not forward itself to a number of email domains, including several anti-virus companies and Microsoft.

 

bulletThe worm will not send itself to email addresses in which the username contains the following strings: abuse, anyone, bugs, ca, contact, feste, gold-certs, help, info, me, no, noone, nobody, not, nothing, page, postmaster, privacy, rating, root, samples, secur, service, site, spm, soft, somebody, someone, submit, the.bat, webmaster, you, your, www

 
bulletThe worm will not send itself to email addresses which contain the the following strings: admin, accoun, bsd, certific, google, icrosoft, linux, listserv, ntivi, spam, support, unix

 


The worm can also copy itself into the shared folder of the KaZaA peer-to-peer application with one of the following filenames and a PIF, EXE, SCR or BAT extension:


activation_crack
icq2004-final
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
winamp5

 

Further reading: MyDoom worm spreads widely across internet, Sophos warns users to be wary of viral email and hacker attack

Recovery

Advanced

Descriptions for Newly Discovered Threats (Includes Viruses, Trojans and Hoaxes)
Name Date Discovered Home Risk Corporate Risk Included In DAT
Ntpass application 01/27/2004 N/A N/A 4321
W32/Mydoom@MM 01/26/2004 High-Outbreak High-Outbreak 4319
W32/Mimail.q@MM 01/26/2004 Low Low 4318
VBS/Braco@MM 01/26/2004 Low Low 4318
W32/Dumaru.y@MM 01/24/2004 Medium Medium 4318
W32/Dumaru.w 01/20/2004 Low Low 4317
StartPage-AU 01/20/2004 Low Low 4318
W32/Bagle@MM 01/18/2004 Low-Profiled Low-Profiled 4316
Downloader-GN 01/14/2004 Low-Profiled Low-Profiled 4315
MS Vulnerabilities MS04-001 - 003 01/13/2004 N/A N/A N/A
Downloader-ER.b 01/12/2004 Low Low 4317
StartPage-AX 01/12/2004 Low Low 4317
Adware-RCSync application 01/12/2004 N/A N/A 4317
Downloader-GH 01/10/2004 Low Low 4314
Downloader-GJ 01/09/2004 Low-Profiled Low-Profiled 4314
Unix/Exploit-SSHIDEN 01/08/2004 Low Low 4314
Adware-HistoryClean 01/07/2004 N/A N/A 4314
W32/Bugbros@MM 01/07/2004 Low-Profiled Low-Profiled 4254
W32/Mimail.p@MM 01/07/2004 Low-Profiled Low-Profiled 4313
BackDoor-AWQ.b 01/06/2004 Low Low 4313
Downloader-GF 01/05/2004 Low Low 4277
JS/Exploit-LnkRun 01/05/2004 Low Low 4313
Proxy-Mitglieder 01/02/2004 Low Low 4314
Linux/Exploit 01/01/2004 Low Low 4312
Downloader-GD 12/31/2003 Low Low 4313

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next