Sponsor Our Community
Go Back   The Reef Tank > General Forums > Margaritaville

Have a question?

Our experts have the answer!


Margaritaville If you'd like to share news, photos, or talk about something non-reef related, please post your thread here.


Registered Members don't see these ads. Register now it's free!

Reply
 
Thread Tools
Old 01-17-2003, 09:59 PM   #1
MontanaRocknReefer
Nothing to See Here
 
MontanaRocknReefer's Avatar
 
Join Date: Feb 2001
Location: Montana
Posts: 5,815
Images: 1

Virus!


To: Johnnypatriots



Trend Micro Weekly Virus Report
(by TrendLabs Global Antivirus and Research Center)

Date: January 17, 2003
Issue Preview:

1. Trend Micro Updates - Pattern File & Scan Engine Updates
2. It's Huge - WORM_SOBIG.A (Medium Risk)
3. 10 Most Prevalent In-the-Wild Malware Surveyed by Trend Micro US

1. Trend Micro Updates - Pattern File and Scan Engine Updates

PATTERN FILE: 443
SCAN ENGINE: 6.510

2. It's Huge - WORM_SOBIG.A (Medium Risk) WORM_SOBIG.A is a memory-resident, multi-threaded worm that propagates via email and shared network folders. It sends copies of itself via email using its own Simple Mail Transfer Protocol (SMTP) engine and obtains its target recipients from addresses found in files with the following extensions:

WAB
DBX
HTM
HTML
EML
TXT

The details of the email that it sends are as follows:

Sender: big@boss.com
Subject:

Re: Movies
Re: Sample
Re: Document
Re: Here is that sample


Attachment:

Movie_0074.mpeg.pif
Document003.pif
Untitled1.pif
Sample.pif

The worm also copies itself to shared folders on the Local Area Network that contain the following folders: :

Windows\All Users\Start Menu\Programs\StartUp\
Documents and Settings\All Users\Start Menu\Programs\Startup

WORM_SOBIG.A downloads files from remote Web sites, and saves them to the Windows folder as DWN.DAT. This download contains a link to another file on the Internet. The worm downloads this file, which may be changed anytime, and then executes it on the host system. If you would like to scan your computer for WORM_SOBIG.A or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at:http://housecall.trendmicro.comWORM_SOBIG.A is detected and cleaned by Trend Micro pattern file #436 and above.

3. 10 Most Prevalent In-the-Wild Malware Surveyed by Trend Micro US
(week of: January 6, 2003 to January 12, 2003)

WORM_KLEZ.H
WORM_YAHA.K
JS_EXCEPTION.GEN
JS_NOCLOSE.E
JS_SEEKER.E1
WORM_OPASERV.E
WORM_BUGBEAR.A
WORM_OPASERV.H
WORM_OPASERV.A
WORM_OPASER
Registered Members don't see these ads. Register now it's free!
MontanaRocknReefer is offline   Reply With Quote
Old 01-17-2003, 11:30 PM   #2
cyberchef
Stress Monger
 
cyberchef's Avatar
 
Join Date: Jan 2002
Location: Las Vegas, NV
Posts: 3,186
Images: 11
Johnny I have Trend Micros PC Cillin on my computer and it has already stopped to emails from the emial addy (big@boss.com) your post mentions.
__________________
cyberchef
Executive Chef Montgomery Country Club
Coral Fragging Plugs
cyberchef is offline   Reply With Quote
Old 01-18-2003, 12:10 AM   #3
asmith
Jedi Master
 
asmith's Avatar
 
Join Date: Jul 2000
Location: Orlando, FL
Posts: 1,435
Images: 1
Hmm. I have been recieving lots of messages from that address. I didn't realize it was a virus. I always delete emails from people I don't know, or with strange subject lines. I am glad I deleted those emails. Thanks for the heads up!

Andrew
__________________
I'm living so far beyond my income that we may almost be said to be living apart. e.e.cummings

asmith is offline   Reply With Quote
Old 01-18-2003, 08:12 AM   #4
Rick O
Good boy
 
Rick O's Avatar
 
Join Date: Jan 2000
Location: Marietta, GA, USA
Posts: 7,883
Images: 54
Norton interceped an e-mail this week that contained the W32-Klez virus. I don't remember the sender but it had an off the wall subject line and an attachment. I never open attachments unless I know the sender and there is text in their e-mail that assures me it's from them.
__________________
Rick O is offline   Reply With Quote
Old 01-18-2003, 10:38 AM   #5
cyberchef
Stress Monger
 
cyberchef's Avatar
 
Join Date: Jan 2002
Location: Las Vegas, NV
Posts: 3,186
Images: 11
Yeah I don't open email from anyone I don't recognize either. But it looks like there is someone out there who must have a vi*us and my email addy. I've been getting at least 1 email a day now that is stopped by PcCillin because of Kle* or some other vi*us...
__________________
cyberchef
Executive Chef Montgomery Country Club
Coral Fragging Plugs
cyberchef is offline   Reply With Quote
Old 01-18-2003, 10:58 AM   #6
FishDaddy
Super Moderator
 
FishDaddy's Avatar
 
Join Date: Jan 2000
Location: TN, USA
Posts: 8,937
Can I get it by reading this thread????

I just sprayed my monitor with Lysol just to be sure!!!

I haven't received any of those but hope Norton is on guard!

Thanks for the warning, Johnny.
Dick
__________________
Every day is a good day!!
http://users.zoominternet.net/~kathywerner/gifs/jumping_fish.gif
FishDaddy is offline   Reply With Quote
Old 01-18-2003, 04:04 PM   #7
ShirleyM
Sailfin
 
ShirleyM's Avatar
 
Join Date: Jan 2000
Location: Noblesville, Indiana
Posts: 2,441
Images: 2
Quote:
Originally posted by FishDaddy
Can I get it by reading this thread????
I just sprayed my monitor with Lysol just to be sure!!!
You crack me up, Dick! I just told someone yesterday that if they don't wipe their Norton icon with a Q-tip dipped in alcohol at least once a week, it wouldn't stop the viruses anymore. (they told me Norton wasn't working and yes that it was on their taskbar and turned on)

Anyhow, MY Norton has Q'd about 5 of the Klez virus in the past three weeks.

Shirley
ShirleyM is offline   Reply With Quote
xFeatured Products
Elephant's Ear Mushrooms

$30 to $39

at 6 sellers

Sea Apple Cucumber

$47 to $70

at 3 sellers

Medusa Soft Coral

$16 to $27

at 7 sellers

Eheim Pro Filter External Canister Aquarium Filter 2229

$250 to $440

at 10 sellers

Hagen Radiant Heater 100W 10 Inch

$8 to $10

at 7 sellers

AquaC EV-180 with JG Fitting Protein Skimmer

$345 to $345

at 4 sellers

Eheim Jager Heater Aquarium Heater 200W

$20 to $44

at 31 sellers

Reply

Bookmarks



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Sitemap:1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192
Sponsor Our Community

All times are GMT -5. The time now is 11:05 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Our lawyer tells us that, by pressing the "New Thread" or "New Reply" button, you acknowledge that the opinions and information expressed in your article are yours alone and not those of thereeftank.com, dba The Reef Tank. Further, you agree to indemnify The Reef Tank, its moderators, administrators and agents from any and all liability which may arise as a result of your article. (C)opyright 2006 TheReefTank.com