The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

 

We Build the Best & Repair the Rest! ©

 
     

 

FAQ Search Virus Alerts Hardware Faqs
 

Home
Alerts 2004
Alerts January 2005
Alerts February 2005
Alerts March 2005
Alerts April 2005
Alerts May 2005
Alerts June 2005
Alerts July 2005
Alerts August 2005
Alerts September 2005
Alerts October 2005
Alerts November 2005
Alerts December 2005

 

 

 

Our VIRUS Alert Post for March 2004

Recent Virus Alerts

          Here you will find recent virus alerts...

 

Top 10 malware reported to Sophos in March 2004

Position Last
month
Malware Percentage of reports
1 New W32/Netsky-D
   30.2%
2 3 W32/Netsky-B
   12.3%
3 New W32/Netsky-C
   11.7%
4= New W32/Bagle-C
   3.5%
4= New W32/Netsky-J
   3.5%
6 New W32/Bagle-E
   3.4%
7 New W32/Netsky-P
   2.1%
8 New W32/Bagle-H
   1.5%
9 New W32/Bagle-J
   1.4%
10 2 W32/MyDoom-A
   0.9%
Others 29.5%

 

 

W32/Netsky-D is a worm that spreads via email. When emailing itself the worm can spoof the sender's email address.

W32/Netsky-D may arrive in an email with the following characteristics:

 

Subject lines:

Re: Approved
Re: Details
Re: Document
Re: Excel file
Re: Hello
Re: Here
Re: Here is the document
Re: Hi
Re: My details
Re: Re: Document
Re: Re: Message
Re: Re: Re: Your document
Re: Re: Thanks!
Re: Thanks!
Re: Word file
Re: Your archive
Re: Your bill
Re: Your details
Re: Your document
Re: Your letter
Re: Your music
Re: Your picture
Re: Your product
Re: Your software
Re: Your text
Re: Your website

 

Message texts:

Your file is attached.
Please read the attached file.
Please have a look at the attached file.
See the attached file for details.
Here is the file.
Your document is attached.

 

Attached file:

all_document.pif
application.pif
document.pif
document_4351.pif
document_excel.pif
document_full.pif
document_word.pif
message_details.pif
message_part2.pif
mp3music.pif
my_details.pif
your_archive.pif
your_bill.pif
your_details.pif
your_document.pif
your_file.pif
your_letter.pif
your_picture.pif
your_product.pif
your_text.pif
your_website.pif
yours.pif

W32/Netsky-D searches all mapped drives for files with the following extensions in order to find email adresses: MSG, OFT, SHT, DBX, TBB, ADB, DOC, WAB, ASP, UIN, RTF, VBS, HTML, HTM, PL, PHP, TXT and EML

W32/Netsky-D is programmed to not forward itself via email if the recipient email address contains the following strings:

messagelabs
abuse
fbi
orton
f-pro
aspersky
cafee
orman
itdefender
f-secur
avp
spam
ymantec
antivi
icrosoft
 

When the worm is run on 2 March 2004 between 06:00 and 08:59 it may cause the computer to beep sporadically.

 

 

Descriptions for Newly Discovered Threats (Includes Viruses, Trojans and Hoaxes)
Name

Date Discovered

Home Risk

Corporate Risk

Included In DAT
W32/Netsky.r@MM 03/31/2004 Low-Profiled Low-Profiled 4346
W32/Bagle.v@MM 03/29/2004 Low Low 4344
W32/Netsky.q@MM 03/28/2004 Medium Medium 4345
W32/Sober.e@MM 03/28/2004 Low Low 4345
W32/Bagle.u@MM 03/26/2004 Medium Medium 4344
Spy-Peep 03/24/2004 Low Low 4345
W32/Snapper@MM 03/24/2004 Low-Profiled Low-Profiled 4342
W32/MyWife.a@MM 03/23/2004 Low-Profiled Low-Profiled 4342
W32/Cone.f@MM 03/22/2004 Low-Profiled Low-Profiled 4342
W32/Lovgate.q@M 03/22/2004 Low Low 4340
W32/Lovgate.r@M 03/22/2004 Low Low 4340
Dustbunny application 03/22/2004 N/A N/A 4342
W32/Netsky.p@MM 03/21/2004 Medium Medium 4340
W32/Witty.worm 03/20/2004 Low-Profiled Low-Profiled 4342
W32/Lovero.worm 03/18/2004 Low Low 4340
MultiDropper-JW 03/18/2004 Low Low 4340
W32/Bagle.t@MM 03/18/2004 Low-Profiled Low-Profiled 4340
W32/Bagle.s@MM 03/18/2004 Low-Profiled Low-Profiled 4340
W32/Bagle.r@MM 03/18/2004 Low-Profiled Low-Profiled 4340
IRC-Deport 03/17/2004 Low Low 4342
W32/Bagle.q@MM 03/17/2004 Low-Profiled Low-Profiled 4340
W32/Lovgate.p@M 03/17/2004 Low Low 4339
W32/Netsky.o@MM 03/17/2004 Low Low 4339
Spy-Idwi 03/16/2004 Low Low 4328
W32/Netsky.n@MM 03/15/2004 Low Low 4339
W32/Bagle.p@MM 03/15/2004 Medium Medium 4338
W32/Polybot.l!irc 03/14/2004 Low-Profiled Low-Profiled 4339
W32/Bagle.n@MM 03/13/2004 Medium Medium 4337
Adware-Findemnow 03/12/2004 N/A N/A 4337
W32/Netsky.m@MM 03/11/2004 Low Low 4328
W32/Netsky.l@MM 03/10/2004 Low Low 4328
W32/Bagle.l 03/09/2004 Low Low 4333
W32/Netsky.k@MM 03/08/2004 Low Low 4336
W32/Netsky.j@MM 03/08/2004 Medium Medium 4335
VBS/Lasku 03/07/2004 Low Low 4335
W32/Sober.d@MM 03/07/2004 Medium Medium 4334
W32/Netsky.i@MM 03/07/2004 Low Low 4333
W32/NetSky.h@MM 03/05/2004 Low Low 4328
W32/Netsky.g@MM 03/04/2004 Low Low 4328
W32/Mydoom.h@MM 03/03/2004 Low Low 4333
W32/Bagle.k@MM 03/03/2004 Low Low 4332
W32/Netsky.f@MM 03/03/2004 Low Low 4328
W32/Mydoom.g@MM 03/02/2004 Low Low 4332
W32/Bagle.j@MM 03/02/2004 Medium Medium 4332
W32/Hiton.a@MM 03/02/2004 Low Low 4331
W32/Bagle.i@MM 03/02/2004 Low Low 4331
W32/Polybot.gen!irc 03/01/2004 Low Low 4333
W32/Bagle.h@MM 03/01/2004 Low-Profiled Low-Profiled 4331
W32/Netsky.e@MM 03/01/2004 Low Low 4328
W32/Netsky.d@MM 03/01/2004 Medium Medium 4328

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next