Click your ruby slippers together 3 times and repeat "There's no place like home, there's no place like home, there's no place like home..." If you came to this page directly, click the icon at the left to be taken to our Home Page
 
Virus News 

 

 


 

November 2004

Select the links for detailed information and removal tools for the latest viruses

Updated 12/02/2004


W32.Mugly.B 11/30/2004 2
W32.Salga.A 11/30/2004 2
W32.Garroch 11/27/2004 2
Backdoor.Berbew.M 11/26/2004 2
W32.Inzae.B 11/23/2004 2
W32.Inzae.A 11/22/2004 2
W32.Yanz.B 11/22/2004 2
Trojan.Vundo 11/20/2004 2
W32.Sober.I 11/19/2004 3
W32.Beagle.AX 11/12/2004 2
W32.Bofra.E 11/12/2004 2
W32.Mydoom.AK 11/11/2004 2
W32.Mydoom.AJ 11/10/2004 2
W32.Orpheus.A 11/09/2004 2
W32.Mydoom.AI 11/08/2004 2
W32.Mydoom.AH 11/08/2004 2
W32.Gaobot.BQJ 11/08/2004 2
VBS.Midfin 11/08/2004 2
W32.Randex.BTB 11/06/2004 2
W32.Bagz.H 11/02/2004 2
VBS.Yeno.C 11/01/2004 2
VBS.Yeno.B 11/01/2004 2

   
 

 

VBS.Yeno.B@mm
Discovered November 01, 2004

Systems Affected: All Windows32 Systems

VBS.Yeno.B@mm is a mass-mailing worm that sends itself to email addresses in the Microsoft Outlook address book. It also infects .vbs, .vbe, .htm, and .html files on drives C, D and E.

Large scale e-mailing: Sends email to all addresses in the Outlook addressbook.
Subject of email: Fw: I give you again
Name of attachment: OXNEY.B.VBS
Size of attachment: 6,945 bytes

Read the full Symantec report here


VBS.Yeno.C@mm
Discovered November 01, 2004

Systems Affected: All Windows32 Systems

VBS.Yeno.C@mm is a mass-mailing worm that sends itself to the email addresses in the Microsoft Outlook address book. It also infects .vbs, .vbe, .htm, and .html files on drives C, D and E.

Large scale e-mailing: Sends email to all addresses in the Outlook addressbook.
Subject of email: Fw: I give you again
Name of attachment: OXNEY.C.VBS

Read the full Symantec report here


W32.Bagz.H@mm
Discovered November 02, 2004

Systems Affected: All Windows32 Systems

W32.Bagz.H@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses gathered from a compromised system. It also lowers the security settings by overwriting the local hosts file and preventing access to several security-related Web sites.

Large scale e-mailing: Sends mail to addresses harvested from the local system.
Modifies files: Modifies local hosts file.
Compromises security settings: Disables various programs including antivirus and firewall programs.
Subject of email: Varies
Name of attachment: Varies with .exe or .zip file extension
Size of attachment: 166,913 bytes

Read the full Symantec report here


W32.Randex.BTB
Discovered November 06, 2004

Systems Affected: All Windows32 Systems

W32.Randex.BTB is a network aware worm that spreads to network shares protected by weak passwords. It also opens a back door and may be remotely controlled via IRC channels.

Compromises security settings: Allows unauthorized remote use of an infected computer.
Shared drives: Attempts to authenticate and copy itself onto network shared drives. Targets randomly selected hosts.

Read the full Symantec report here


VBS.Midfin@mm
Discovered November 08, 2004

Systems Affected: All Windows32 Systems

VBS.Midfin@mm is an encrypted VBScript mass-mailing worm. It sends itself to all email addresses in the Microsoft Outlook address book. It also spreads using MIRC, and infects all .vbs and .vbe files.

Large scale e-mailing: Sends a mass-mailing.
Modifies files: Modifies .vbs, .vbe, and .txt files.
Subject of email: AntiVirus UPDATE 28062004.dat

Read the full Symantec report here


W32.Gaobot.BQJ
Discovered November 08, 2004

Systems Affected: All Windows32 Systems

W32.Gaobot.BQJ is a network-aware worm that opens a backdoor and can be controlled through IRC channels. It also attempts to lower security settings by terminating processes and by blocking access to security related Web sites. It spreads by exploiting vulnerabilities, and through backdoors opened by other malicious threats.

Payload: Allows unauthorized remote access.
Modifies files: Hosts file.
Releases confidential info: Steals cd keys from various PC games.
Compromises security settings: Terminates processes, some of which are related to system security type programs.
Ports: TCP port 7000; three random ports

Read the full Symantec report here


W32.Mydoom.AH@mm
Discovered November 08, 2004

Systems Affected: All Windows32 Systems

W32.Mydoom.AH@mm is a mass-mailing worm which exploits the Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (BID 11515). It also spreads by sending itself to the email addresses that it finds on the infected computer.

Large scale e-mailing: Sends itself to the email addresses that it finds on the infected computer.
Subject of email: varies
Ports: TCP 1639 and 6667.

Read the full Symantec report here


W32.Mydoom.AI@mm
Discovered November 08, 2004

Systems Affected: All Windows32 Systems

W32.Mydoom.AI@mm is a mass-mailing worm which exploits the Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (BID 11515). It also spreads by sending itself to email addresses it finds in the Windows address book.

Large scale e-mailing: Sends itself to the email addresses that it finds on the infected computer.
Subject of email: varies
Ports: TCP 1639 and 6667.

Read the full Symantec report here


W32.Orpheus.A
Discovered November 09, 2004

Systems Affected: All Windows32 Systems

W32.Orpheus.A is a network-aware worm that opens a backdoor on the infected host.

Payload: Allows unauthorized remote access.
Large scale e-mailing: n/a
Degrades performance: May be used to perform a DoS attack.
Releases confidential info: May be used to log keystrokes.
Shared drives: Attempts to copy to all domains viewable from the infected machine.

Read the full Symantec report here


W32.Mydoom.AJ@mm
Discovered November 10, 2004

Systems Affected: All Windows32 Systems

W32.Mydoom.AJ@mm is a mass-mailing worm that exploits Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (BID 11515). It spreads by sending a link via email to the addresses that it finds on an infected computer.

Payload: Allows unauthorized remote access.

Read the full Symantec report here


W32.Mydoom.AK@mm
Discovered November 11, 2004

Systems Affected: All Windows32 Systems

W32.Mydoom.AK@mm is a mass-mailing worm that exploits the Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (as described in Bugtraq ID 11515). The worm also spreads by sending an email to addresses that it finds on the infected computer.

Payload Trigger: Allows unauthorized remote access.
Large scale e-mailing: Sends a mass-mailing.
Subject of email: Varies
Ports: TCP port 113, 1639, 6667

Read the full Symantec report here


W32.Bofra.E@mm
Discovered November 12, 2004

Systems Affected: All Windows32 Systems

W32.Bofra.E@mm is a mass-mailing worm that exploits the Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (as described in Bugtraq ID 11515). It spreads by sending the email addresses that it finds on an infected computer.

Read the full Symantec report here


W32.Beagle.AX@mm
Discovered November 15, 2004

Systems Affected: All Windows32 Systems

W32.Beagle.AX@mm is a mass-mailing worm that also spreads through file-sharing networks. The worm will open a backdoor on TCP port 2002.

Large scale e-mailing: Sends email to the addresses collected from an infected computer.
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Compromises security settings: Terminates processes associated with various security-related programs. Allows unauthorized remote access to a compromised host
Subject of email: Varies
Name of attachment: Varies with a .hta., vbs, .exe., scr., com., cpl,.or zip extension.
Size of attachment: Varies.
Ports: TCP 80, 2002.

Read the full Symantec report here


W32.Sober.I@mm
Discovered November 19, 2004

Systems Affected: All Windows32 Systems

W32.Sober.I@mm is a mass-mailing worm that uses its own SMTP engine to spread by sending itself as an email attachment to addresses gathered from the infected computer.
The subject of the email varies and will be in either English or German. The email sender address is spoofed. The name of the email attachment varies, and it will have a .bat, .com, .pif, .scr, or .zip file extension. The attachment may also have a double extension.

This threat is written in the Microsoft Visual Basic programming language and is compressed with UPX.

Note:

Live Update definitions with sequence number 38560 or greater will detect this threat.
In certain circumstances the worm may corrupt itself. Should this happen, the worm will not execute on the computer, and antivirus software may be unable to detect it. When a computer is infected with a corrupt version of W32.Sober.I@mm, command prompt windows may be displayed briefly when Windows starts. The W32.Sober@mm Removal Tool will be unable to uninstall corrupt versions of W32.Sober.I@mm and it is necessary to proceed with the manual removal instructions.

Read the full Symantec report here


Trojan.Vundo
Discovered November 20, 2004

Systems Affected: All Windows32 Systems

Trojan.Vundo is a component of an adware program that downloads and displays pop-up advertisements. It is known to be installed by visiting a Web site link contained in a spammed email.

Degrades performance: Unauthorized process is running
Compromises security settings: Download a file from the internet

Read the full Symantec report here

Get the Removal Tool here


W32.Yanz.B@mm
Discovered November 22, 2004

Systems Affected: All Windows32 Systems

W32.Yanz.B@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it retrieves from the infected computer.

Payload: Downloads and executes a remote file.
Large scale e-mailing: Sends email to addresses collected from the Windows Address Book and files with the following extension: .adb, .asp, .dbx, .doc, .htm, .html, .jsp, .rtf, .txt, or .xml.
Subject of email: Varies
Name of attachment: Varies with a .pif, .scr, or .zip extension
Size of attachment: 122,880 bytes

Read the full Symantec report here


W32.Inzae.A@mm
Discovered November 22, 2004

Systems Affected: All Windows32 Systems

W32.Inzae.A@mm is a mass-mailing worm that uses its own SMTP engine to spread by sending itself as an email attachment.

Large scale e-mailing: Sends email to the addresses collected from an infected computer.
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Subject of email: Varies
Name of attachment: Varies with a .zip extension.

Read the full Symantec report here


W32.Inzae.B@mm
Discovered November 23, 2004

Systems Affected: All Windows32 Systems

W32.Inzae.B@mm is a mass-mailing worm that uses its own SMTP engine to send itself to all the email addresses that it retrieves from the infected machine.

Large scale e-mailing: Sends email to the addresses collected from an infected computer.
Deletes files: Deletes files with the following extensions: .asm, .asp, .bat, .bdsproj, , .bmp, .c, .css, .doc, .dot, .dpr, .gif, .h, .htm, .html, .inf, .ini, .iso, .jpeg, .jpg, .log, .mdb, .mp3, .msi, .nfm, .nrg, .pas, .pcx, .pdf, .php ,.ppt ,.rar ,.reg ,.rpt ,.txt ,.vb ,.vbs, .wav, and .xls.
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Subject of email: Varies
Name of attachment: Varies with .zip file extension.
Size of attachment: Varies

Read the full Symantec report here


W32.Garroch@mm
Discovered November 27, 2004

Systems Affected: All Windows32 Systems

W32.Garroch@mm is a simple worm that sends itself to all addresses it finds in the Microsoft Outlook address book. It also displays a picture and plays a sound emulating a human voice.

Large scale e-mailing: Sends itself to all addresses in the Microsoft Outlook address book.
Subject of email: Urgente
Name of attachment: softhost.exe

Image:

Read the full Symantec report here


Backdoor.Berbew.M
Discovered November 26, 2004

Systems Affected: All Windows32 Systems

Backdoor.Berbew.M is a Trojan horse that steals cached passwords from an infected computer. The Trojan also opens a back door allowing a remote attacker to have unauthorized access to the infected computer.

Deletes files: Deletes folders named 'system'
Releases confidential info: Installed keylogger steals passwords and data entered into forms in Internet Explorer.

Read the full Symantec report here


W32.Salga.A@mm
Discovered November 30, 2004

Systems Affected: All Windows32 Systems

W32.Salga.A@mm is a mass-mailing worm that uses Microsoft Outlook to send itself to all the email addresses that it finds in the Outlook Address Book. It also attempts to spread through mIRC, file-sharing networks, and network shares.

Large scale e-mailing: Sends itself to email addresses collected from files on the local system.
Degrades performance: Mass-mailing may impact system performance.

Read the full Symantec report here


W32.Mugly.B@mm
Discovered November 30, 2004

Systems Affected: All Windows32 Systems

W32.Mugly.B@mm is a worm that uses its own SMTP engine to spread by sending itself as an email attachment. It also drops and runs a W32.Spybot.Worm variant.

Large scale e-mailing: Sends itself to email addresses collected from files on the local system.
Degrades performance: Mass-mailing may impact system performance.
Subject of email: Hhahahah lol!!!!, Your Pic On A Website!!, Rate My Pic......., or You have an Admirer.
Name of attachment: Attachment.zip

Attached image:

Read the full Symantec report here


 

   

 

         
     
© Copyright 1999 - 2004 The Computer Wizard