|
|
The Computer Guys Miami to Fort Lauderdale Since 1994 - Thank You!
|
|
|
|
|
We Build the Best & Repair the Rest! © |
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Top 10 malware reported to Sophos in March 2005
W32/Sober-K is a mass-mailing worm which sends itself to addresses harvested from the infected computer. When first run, W32/Sober-K will open Notepad and display a body of text that starts: Text#674327: W32/Sober-K will copy itself to a folder named %WINDOWS%\MSAGENT\WIN32 with the filenames CSRSS.EXE, SMSS.EXE and WINLOGON.EXE. In order to run automatically each time a user logs on, W32/Sober-K will continually set the following registry entries: HKCU\Software\Microsoft\Windows\CurrentVersion\Run HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce W32/Sober-K also creates the following files: %WINDOWS%\msagent\win32\datamx<number>.dat The READ.ME file contains the following text: Ist eine weitere Test-Version. Läuft nur ein paar Tage! In diesem Sinne: W32/Sober-K will attempt to terminate processes containing the following strings: gcas, gcip, giantanti, msssrt W32/Sober-K harvests email addresses from files with the following strings in their filenames: pmr phtm stm slk inbox imb csv bak imh xhtml imm imh cms nws vcf ctl dhtm cgi pp ppt msg jsp oft vbs uin ldb abc pst cfg mdw mbx mdx mda adp nab fdb vap dsp ade sln dsw mde frm bas adr cls ini ldif log mdb xml wsh tbb abx abd adb pl rtf mmf doc ods nch xls nsf txt wab eml hlp mht nfo php asp shtml dbx aero com coop edu gov museum name int net org pro info Emails will have the following characteristics: Subject Lines include the following: You visit illegal websites Message body texts include the following: Dear Sir/Madam, we have logged your IP-address on more than 40 illegal Websites. Important: Please answer our questions! Yours faithfully, -- FREE Download until April, 2005 Make your own Download Account, it's free! Thanks & have fun ;) -- Download and read the zipped patch. It's very easy to install! -- Ihr neues Passwort und weiter Informationen befinden sich im beigefuegten Dokument. -- Diese an ihnen gerichtete E-Mail, wurde in einem falschen Format gesendet. Vielen Dank fuer Ihr Verstaendnis[System auto- mail] -- wir hoffen das Ihnen die Betreffszeile unsere Mail genug sagt. Informationen,,,, wie Sie sich bei uns anmelden koennen befinden sich im
beigefuegten Dokument. Mehr als 2.5 Millionen registrierte Benutzer!!! Auf Wiedersehen -- Der Betrag von
Passwort, Benutzername und weitere wichtige Informationen zu ihrem neuen Account befinden sich im angehefteten Dokument. Hochachtungsvoll -- mehr als 50 Videos, Alles frei zum Download, aber nur bis zum 01 April 2005 !!! Weitere Details entnehmen Sie bitte dem vorliegendem Dokument. Vielen Dank! -- Eine neue Sober-Variante verbreitet sich derzeit im Internet. Es wird deshalb empfohlen, das Patch-Tool auszufuehren um sich vor diesem Wurm zu schuetzen bzw. diesen wieder zu entfernen. The attached file will have a ZIP extension and includes the following: Formular.zip The ZIP file will contain an executable file with a double extension. For example, doc_data-text.txt<SPACES>.pif The From address line will be faked, but will start with one of the following: Service, Webmaster, Register, Hostmaster, Postmaster, police, Officer, Admin, Web, FBI, Security
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Copyright © 1998 The Computer Guys |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||