The Computer Guys

Miami to Fort Lauderdale Since 1994 - Thank You!

 

 

 

We Build the Best & Repair the Rest! ©

 
     

 

FAQ Search Virus Alerts Hardware Faqs
 

Home
April 2003
Alerts 2002
Alert Jan 2003
Alert February 2003
Alerts March 2003
Alerts April 2003
Alerts May 2003
Alerts June 2003
Alerts July 2003
Alerts August 2003
Alerts September 2003
Alerts October 2003
Alerts November 2003
Alerts December 2003

 

  April 2003 Alerts 2002 Alert Jan 2003 Alert February 2003 Alerts March 2003 Alerts April 2003 Alerts May 2003 Alerts June 2003 Alerts July 2003 Alerts August 2003 Alerts September 2003 Alerts October 2003 Alerts November 2003 Alerts December 2003

 

New Virus Alerts 2003

Our VIRUS Alert Post

Recent Virus Alerts

          Here you will find recent virus & malware alerts...

 

Descriptions for Newly Discovered Threats (Includes Viruses, Trojans and Hoaxes)

 

 

 

 

Virus and Malware reported in 2003

Top 10 malware reported to Sophos in 2003

Position Malware Percentage of reports
1 W32/Sobig-F
   19.9%
2 W32/Blaster-A
   15.1%
3 W32/Nachi-A
   8.4%
4 W32/Gibe-F
   7.2%
5 W32/Dumaru-A
   6.1%
6 W32/Sober-A
   5.8%
7 W32/Mimail-A
   4.8%
8 W32/Bugbear-B
   3.1%
9 W32/Sobig-E
   2.9%
10 W32/Klez-H
   1.6%
Others 25.1%

 

W32/Sobig-F is a worm that spreads via email.

 

W32/Sobig-F copies itself to the Windows folder as winppr32.exe and sets one of the following registry entries:

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= <Windows folder>\winppr32.exe /sinc

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\TrayX
= <Windows folder<\winppr32.exe /sinc

 

The worm sends itself, using its own SMTP engine, as an attachment to email addresses collected from various files on the victim's computer. When it distributes itself via email it forges the sender's email address, making it difficult to know who is truly infected.

The email has the following format:

 

Subject line: Chosen from -
 

Re: That movie
Re: Wicked screensaver
Re: Your application
Re: Approved
Re: Re: My details
Re: Details
Your details
Thank you!

 

Message text: Chosen from -
 

Please see the attached file for details.
See the attached file for details

 

Attached file: Chosen from -
 

movie0045.pif
wicked_scr.scr
application.pif
document_9446.pif
details.pif
your_details.pif
thank_you.pif
document_all.pif
your_document.pif

W32/Sobig-F also attempts to spread by copying itself to Windows network shares.

 

Important information

W32/Sobig-F uses the Network Time Protocol (NTP) to access one of several servers in order to determine the current date and time.

If the time returned by the NTP server is between 19:00 and 22:00 UTC+0 which is 8pm-11pm UK time) on Friday or Sunday, W32/Sobig-F sends a UDP packet to port 8998 of a remote server. This feature could be used to download and run a Trojan or additional worm components.

 

To prevent malicious code from being downloaded by W32/Sobig-F, Sophos strongly recommends that customers consider configuring company firewalls so outgoing connection attempts to UDP port 8998 are blocked.

Customer should consult their firewall documentation, or contact their firewall provider for assistance in implementing this configuration change.


 

If the date is 10 September 2003 or later the worm stops working.

 

 

 

 
April 2003 Alerts 2002 Alert Jan 2003 Alert February 2003 Alerts March 2003 Alerts April 2003 Alerts May 2003 Alerts June 2003 Alerts July 2003 Alerts August 2003 Alerts September 2003 Alerts October 2003 Alerts November 2003 Alerts December 2003

 

 

 

 

 

 

 

This web is optimized for 800 x 600 monitor resolution or above and the latest web browser.  Get the latest IE or Netscape web browser. (you need to connect to the internet first)

 

 

Copyright © 1998 The Computer Guys
 Back Home Up Next