Click your ruby slippers together 3 times and repeat "There's no place like home, there's no place like home, there's no place like home..." If you came to this page directly, click the icon at the left to be taken to our Home Page
 
Virus News 

 

 


 

December 2004

Select the links for detailed information and removal tools for the latest viruses

Updated 12/29/2004



W32.Protoride.B 12/28/2004 2
Perl.Santy.C 12/25/2004 2
Perl.Santy.B 12/25/2004 2
W32.Beaker.A 12/22/2004 2
W32.Envid.C 12/22/2004 2
W32.Randex.CCF 12/21/2004 2
Perl.Santy 12/21/2004 2
W32.Mugly.C 12/17/2004 2
W32.Atak.G 12/17/2004 2
W32.Looked 12/17/2004 2
W32.Envid.B 12/16/2004 2
W32.Atak.F 12/15/2004 2
VBS.Sorpe.B 12/14/2004 2
W32.Erkez.D 12/14/2004 3
VBS.Sorpe.A 12/14/2004 2
W32.Qeds 12/13/2004 2
W32.Janx 12/11/2004 2
VBS.Junkmail 12/10/2004 2
W32.Maslan.C 12/09/2004 2
W32.Maslan.A 12/07/2004 2
W32.Gaobot.BUU 12/07/2004 2
W32.Atak.E 12/07/2004 2
W32.Atak.B 12/03/2004 2
W32.Mugly.A 12/02/2004 2

   
 

 

 


W32.Mugly.A@mm
Discovered December 02, 2004

Systems Affected: All Windows32 Systems

W32.Mugly.A@mm is a worm that uses its own SMTP engine to spread by sending itself as an email attachment to the email addresses gathered from the infected computer. It also drops and runs a W32.Spybot.Worm variant, and may attempt to open a backdoor on the infected computer.

Large scale e-mailing: Sends a mass-mailing.
Causes system instability: Exploits system vulnerabilities.
Compromises security settings: Opens a backdoor.
Subject of email: Varies
Name of attachment: Attachment.zip
Shared drives: Attempts to copy itself to shared drives protected by weak passwords.

Attached image:

Read the full Symantec report here


W32.Atak.B@mm
Discovered December 03, 2004

Systems Affected: All Windows32 Systems

W32.Atak.B@mm is a mass-mailing worm that uses its own SMTP engine to send its messages to the email addresses it gathers from certain files on a compromised computer.

Large scale e-mailing: Sends a mass-mailing of itself.
Deletes files: n/a
Modifies files: n/a
Degrades performance: Mass-mailing may clog mail servers or degrade network performance.
Subject of email: Varies
Name of attachment: Varies with .scr .com .exe .pif or .bat file extension.

Read the full Symantec report here


W32.Atak.E@mm
Discovered December 07, 2004

Systems Affected: All Windows32 Systems

W32.Atak.E@mm is a mass-mailing worm that uses its own SMTP engine to send a copy of itself as an attachment to the email addresses it gathers from files on the compromised computer.

Large scale e-mailing: Sends a mass-mailing of itself to address gathered from the compromised computer.
Subject of email: Varies
Name of attachment: Varies with .bat, .pif, .exe, .com, .scr, or .zip file extension
Size of attachment: 11,189 bytes

Read the full Symantec report here


W32.Gaobot.BUU
Discovered December 07, 2004

Systems Affected: All Windows32 Systems

W32.Gaobot.BUU is a network-aware worm that has back door capabilities and can be controlled through IRC channels. It attempts to lower security settings by blocking access to security-related Web sites and terminating processes. This worm spreads by exploiting several Windows vulnerabilities.

Modifies files: Modifies the hosts file.
Releases confidential info: Steals CD keys from a number of computer games.
Compromises security settings: Gives a remote attacker back door access to the computer via IRC.
Ports: TCP ports 80, 135, 445, and 6777. UDP port 1434.
Target of infection: Targets computers vulnerable to various system exploits.

Read the full Symantec report here

Download the Removal Tool here


W32.Maslan.A@mm
Discovered December 07, 2004

Systems Affected: All Windows32 Systems

W32.Maslan.A@mm is a mass-mailing worm that opens a back door and exploits system vulnerabilities on the compromised computer. The worm also steals passwords and uses rootkit techniques.

Payload: Allows unauthorized remote access.
Large scale e-mailing: Sends a mass-mailing to email addresses collected on the infected computer.
Releases confidential info: Logs keystrokes entered into windows which match various banking/financial sites.
Compromises security settings: Terminate processes related to security products.
Name of attachment: PlayGirls2.exe
Size of attachment: 54,272 bytes
Ports: TCP port 135

Read the full Symantec report here


W32.Maslan.C@mm
Discovered December 09, 2004

Systems Affected: All Windows32 Systems

W32.Maslan.C@mm is a mass-mailing worm that opens a back door and exploits system vulnerabilities on the compromised computer. The worm also steals passwords and uses rootkit techniques.

Payload: Allows unauthorized remote access.
Large scale e-mailing: Sends a mass-mailing to email addresses gathered from the infected computer.
Modifies files: Overwrites certain files.
Releases confidential info: Logs keystrokes.
Compromises security settings: Terminate processes related to security products.
Subject of email: 12345
Name of attachment: PlayGirls_2.exe
Size of attachment: 54,272 bytes
Ports: TCP port 135

Read the full Symantec report here


VBS.Junkmail@mm
Discovered December 10, 2004

Systems Affected: All Windows32 Systems

VBS.Junkmail@mm is a generic VBS, mass-mailing worm, which copies itself to files on the C drive.

Payload: Copies itself to files on the C drive.
Large scale e-mailing: Sends a mass-mailing.
Subject of email: Varies.
Name of attachment: XAUDIO_SOUND.MP3.VBE

Read the full Symantec report here


W32.Janx
Discovered December 11, 2004

Systems Affected: Windows 2000, Windows XP

W32.Janx is a worm that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability (Microsoft Security Bulletin MS04-011). The worm spreads by randomly scanning IP addresses for vulnerable systems. The worm also connects to an IRC server and waits for commands.

Degrades performance: Excessive network access occurs.
Compromises security settings: Allows unauthorized access to an infected computer.
Ports: TCP ports 445, 5533, 5534.
Target of infection: Other vulnerable Windows machines

Read the full Symantec report here


W32.Qeds@mm
Discovered December 13, 2004

Systems Affected: All Windows32 Systems

W32.Qeds@mm is a mass-mailing worm that sends a copy of itself as an attachment to the email addresses that it gathers from the files on an infected computer.

Payload Trigger: Downloads remote files.
Large scale e-mailing: Sends a mass-mailing.
Deletes files: 14,848 bytes
Subject of email: Displayed in Chinese characters
Name of attachment: Displayed in Chinese characters with a .zip file extension

Read the full Symantec report here


VBS.Sorpe.A@mm
Discovered December 14, 2004

Systems Affected: All Windows32 Systems

VBS.Sorpe.A@mm is a mass-mailing worm that sends itself to email addresses gathered from files on the infected computer.

Large scale e-mailing: Sends a mass-mailing.
Causes system instability: Terminates processes.
Subject of email: Varies
Name of attachment: MsNews.vbs

Read the full Symantec report here


W32.Erkez.D@mm
Discovered December 14, 2004

Systems Affected: All Windows32 Systems

W32.Erkez.D@mm is a mass-mailing worm that sends itself to email addresses gathered from the infected computer. The worm may also attempt to lower security settings, terminate processes, and open a back door on the compromised computer.

Payload: Opens a back door
Large scale e-mailing: Mass-mailing
Degrades performance: Terminates processes
Compromises security settings: Terminates security related processes.
Subject of email: Varies
Name of attachment: Varies with a .bat, .cmd, .com, .pif, or .zip extension.
Ports: TCP port 8181

Read the full Symantec report here

Download the Removal Tool here


VBS.Sorpe.B@mm
Discovered December 14, 2004

Systems Affected: All Windows32 Systems

VBS.Sorpe.B@mm is a mass-mailing worm that sends itself to the email addresses gathered from the files on an infected computer. The worm also disables various system utilities including the Registry Editor and Microsoft Notepad.

Large scale e-mailing: Sends a mass-mailing.
Deletes files: Deletes files from the Desktop and from the Internet Explorer Favorites folder.
Modifies files: Disables the Registry Editor.
Subject of email: Varies
Name of attachment: Scmhlpr.vbs

Read the full Symantec report here


W32.Atak.F@mm
Discovered December 15, 2004

Systems Affected: All Windows32 Systems

W32.Atak.F@mm is a mass-mailing worm that sends itself to addresses collected from the infected computer. The email has a variable subject and attachment name. The attachment will have a .zip file extension.

Large scale e-mailing: Mails itself to the email addresses found on infected computer.
Modifies files: Adds an entry to win.ini.
Degrades performance: Email address searching and mass-mailing activity may degrade computer performance.
Subject of email: "Merry X-Mas!" or "Happy New Year!"
Name of attachment: Variable double extension ending in .zip.
Size of attachment: approx. 11 kb

Read the full Symantec report here


W32.Envid.B@mm
Discovered December 16, 2004

Systems Affected: All Windows32 Systems

W32.Envid.B@mm is a worm that sends email to all addresses found in the Microsoft Outlook Address Book. The email has a variable subject and no attachment. The email contains a link from which the worm is downloaded.

Large scale e-mailing: Sends a mass-mailing.
Compromises security settings: Terminates security processes.
Subject of email: Varies

Read the full Symantec report here

Download the Removal Tool here


W32.Looked
Discovered December 17, 2004

Systems Affected: All Windows32 Systems

W32.Looked is a worm that propagates through shared folders, downloads a file, and infects .exe files.

Modifies files: Infects files with .exe file extension.
Compromises security settings: Terminates the Zone Alarm firewall and various associated processes.
Target of infection: IPC$ and ADMIN$ network shares

Read the full Symantec report here


W32.Atak.G@mm
Discovered December 17, 2004

Systems Affected: All Windows32 Systems

W32.Atak.G@mm is a mass-mailing worm that uses its own SMTP engine to send itself as an attachment to the email addresses that it gathers from the files on the compromised computer.

Large scale e-mailing: Mails itself to the email addresses found on infected computer.
Subject of email: "Happy X-mas to u!" or "X-Mas Greeting!"
Name of attachment: Varies with .zip file extension

Read the full Symantec report here


W32.Mugly.C@mm
Discovered December 17, 2004

Systems Affected: All Windows32 Systems

W32.Mugly.C@mm is a worm that uses its own SMTP engine to spread by sending itself as an email attachment to addresses gathered from the compromised computer. The worm also drops and runs a W32.Spybot.Worm variant.

Large scale e-mailing: Sends a mass-mailing.
Compromises security settings: Blocks access to security related Web sites.
Subject of email: Varies.
Name of attachment: attached.zip
Opens a browser window to display the file %System%\uglym.jpg.


Read the full Symantec report here


Perl.Santy
Discovered December 21, 2004

Systems Affected: Unix

Perl.Santy is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11., which are vulnerable to the PHPBB Remote URLDecode Input Validation Vulnerability (BID 11672). Other systems are not affected. If successful, the worm copies itself to the server and overwrites files with the following extensions:


.asp
.htm
.jsp
.php
.phtm
.shtm

The worm uses the Google search engine to find potential new infection targets. Google has now implemented blocking Perl.Santy search requests, which is expected to greatly reduce the worm's ability to propagate and lower the risk of further infections.

Modifies files: Overwrites files with the following extensions: .asp, .htm, .jsp, .php, .phtm, and .shtm

Read the full Symantec report here


W32.Randex.CCF
Discovered December 21, 2004

Systems Affected: All Windows32 Systems

W32.Randex.CCF is a network-aware worm that opens a back door on an infected computer and may be remotely controlled via IRC channels.

Payload: Opens a back door.
Compromises security settings: Terminates security-related processes and blocks access to security-related Web sites.
Ports: TCP port 9000

Read the full Symantec report here


W32.Envid.C@mm
Discovered December 22, 2004

Systems Affected: All Windows32 Systems

W32.Envid.C@mm is a mass-mailing worm that sends an email to all the addresses in the Microsoft Outlook Address Book.

Large scale e-mailing: Sends emails to addresses in the Outlook Address Book.
Compromises security settings: Terminates security processes.
Subject of email: varies

Read the full Symantec report here


W32.Beaker.A@mm
Discovered December 22, 2004

Systems Affected: All Windows32 Systems

W32.Beaker.A@mm is a mass-mailing worm that sends a copy of itself by email and overwrites files on infected computers.

Large scale e-mailing: Emails itself to email addresses found on the infected computer.
Modifies files: Overwrites files with the text "-=breaKer_cUk- "
Degrades performance: Consumes large amounts of processor time
Causes system instability: May crash and cause system instability
Subject of email: Variable
Name of attachment: Variable
Size of attachment: Variable
Time stamp of attachment: Variable

Read the full Symantec report here


Perl.Santy.B
Discovered December 25, 2004

Systems Affected: Unix

Perl.Santy.B is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11, which are vulnerable to the PHPBB Remote URLDecode Input Validation Vulnerability (BID 11672). It uses AOL or Yahoo search to find potential new infection targets.

Compromises security settings: Downloads and executes script files that contain arbitrary code.

Read the full Symantec report here


Perl.Santy.C
Discovered December 25, 2004

Systems Affected: Unix

Perl.Santy.C is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11, which are vulnerable to the PHPBB Remote URLDecode Input Validation Vulnerability (BID 11672). It uses Google search to find potential new infection targets.

Compromises security settings: Downloads and executes script files that contain arbitrary code.

Read the full Symantec report here


W32.Protoride.B
Discovered December 28, 2004

Systems Affected: All Windows32 Systems

W32.Protoride.B is a worm that propagates through network shares and opens a backdoor that allows unauthorized access to a compromised machine.

Payload: Allows unauthorized remote access.
Ports: TCP port 6667
Shared drives: Attempts to spread to the $IPC share of remote network drives.

Read the full Symantec report here

 

 

 

   
         
     
© Copyright 1999 - 2004 The Computer Wizard