|
Post by vegitoth on Mar 22, 2004 17:28:39 GMT -5
(source ansem report) Two new mass-emailing viruses have swept the internet, with high distribution ratings. Name W32.Beagle and W32.Netsky, both are moderately malicious. Similar in nature to the recent MyDoom virus, both Beagle and Netsky send themselves as email attatchments, and can also be unknowingly downloaded through the KaZaA and iMesh filesharing services. Email messages may contain any number of 1 line messages, ranging from "I found your picture on the net!" to "Argh I hate the plaintext " The most recent 3 Beagle strings have not had a virus-removal tool developed for them yet, so, as always, we suggest updating your Anti-Virus program twice daily until the threat subsides. The removal tool for the first 4 strains of Beagle can be found here: securityresponse.symantec.com/avcenter/venc/data/w32.beagle@mm.removal.tool.html The removal tool for the most recent Netsky strains can be found here: securityresponse.symantec.com/avcenter/venc/data/w32.netsky@mm.removal.tool.html For more information on each virus, please visit securityresponse.symantec.comcont. This new strain of virus is capable of sending emails from seemingly reputable companies, INCLUDING THE ANSEM REPORT, telling you that you have a virus and that they have included the removal tool. THESE EMAILS ARE FALSE! DO NOT OPEN ANY EMAILS CONTAINING ATTACHMENTS! Please, always excercise EXTREME caution when downloading files. If you didn't request the file that you recieved, always double check it by asking the sender if they sent the email themself.
|
|
|
Post by vegitoth on May 3, 2004 22:13:56 GMT -5
We got another virus called sasser:W32.Sasser.B.Worm is a variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly selected IP addresses of vulnerable systems.
W32.Sasser.B.Worm differs from W32.Sasser.Worm as follows:
Uses a different mutex: Jobaka3. Uses a different file name: avserve2.exe. Has a different MD5. Creates a different value in the registry: "avserve2.exe."
|
|