|
W32.Mimail.D@mm is a variant of W32.Mimail.C@mm that spreads by email. It is packed with UPX.
|
|
|
Full View / NID: 1649 / Submitted by: TACKtech Team
|
|
Symantec Security Response has developed a removal tool to clean infections of W32.Mimail.A@mm, W32.Mimail.C@mm, W32.Mimail.D@mm, and W32.Mimail.E@mm.
|
|
|
Full View / NID: 1648 / Submitted by: TACKtech Team
|
|
W32.Mimail.C@mm is a variant of W32.Mimail.A@mm that spreads by email and steals information from infected computers.
|
|
|
Full View / NID: 1634 / Submitted by: TACKtech Team
|
|
W32.Swen.A@mm is a mass-mailing worm that uses its own SMTP engine to spread itself. It attempts to spread through file-sharing networks, such as KaZaA and IRC, and attempts to kill antivirus and personal firewall programs running on a computer.
|
|
|
Full View / NID: 1330 / Submitted by: TACKtech Team
|
|
This virus exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026). This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and execute it. This effects Windows NT, Windows 2000, Windows XP, and Windows Server 2003
|
|
|
Full View / NID: 1199 / Submitted by: TACKtech Team
|
|
This virus exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) and Exploits the WebDav vulnerability (described in Microsoft Security Bulletin MS03-007). This effects Windows NT, Windows 2000, Windows XP, and Windows Server 2003
|
|
|
Full View / NID: 1147 / Submitted by: Travis
|
|
W32.Dumaru@mm is a mass-mailing worm that inserts an IRC Trojan onto the infected machine. The worm gathers email addresses from certain file types and uses its own SMTP engine to email itself.
|
|
|
Full View / NID: 1146 / Submitted by: Travis
|
|
This virus exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026). This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and execute it. This effects Windows NT, Windows 2000, Windows XP, and Windows Server 2003
|
|
|
Full View / NID: 1136 / Submitted by: TACKtech Team
|
|
This virus exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026). This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and execute it. This effects Windows NT, Windows 2000, Windows XP, and Windows Server 2003
|
|
|
Full View / NID: 1131 / Submitted by: TACKtech Team
|
|
This virus exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026). This worm attempts to download the msblast.exe file to the %WinDir%\system32 directory and execute it. This effects Windows NT, Windows 2000, Windows XP, and Windows Server 2003
|
|
|
Full View / NID: 1114 / Submitted by: TACKtech Team
|
|
W32.Mimail@mm is a worm that spreads by email. This threat takes advantage of a known vulnerability. Information about this vulnerability and a Microsoft patch is located at: Microsoft Knowledge Base Article - 330994. System administrators are encouraged to apply the Microsoft patch to prevent infection by this worm. The worm is packed with UPX. Also Known As: WORM_MIMAIL.A [Trend], W32/Mimail@MM [McAfee], Win32.Mimail.A [CA], W32/Mimail-A [Sophos].
|
|
|
Full View / NID: 1080 / Submitted by: TACKtech Team
|
|
W32.Sobig.E@mm is a mass-mailing worm that sends itself to all the email addresses that it finds in the files with the following extensions: .wab, .dbx, .htm, .html, .eml, and .txt. The email falsely purports that Yahoo sent it (support@yahoo.com). (NOTE: W32.Sobig.E@mm spoofs this field. It could be any address.)
|
|
|
Full View / NID: 904 / Submitted by: TACKtech Team
|
|
W32.Bugbear.B@mm is a Category 4 mass-mailing, polymorphic worm that also spreads through network shares. This worm infects a select list of executable files, has keystroke-logging and backdoor capabilities and will attempt to terminate the processes of various antivirus and firewall programs.
|
|
|
Full View / NID: 832 / Submitted by: TACKtech Team
|
|
W32.HLLW.Lovgate.I@mm is a variant of W32.HLLW.Lovgate@mm. It is also a mass mailing worm that attempts to email itself to all the email addresses that it finds in the files whose extensions start with "ht." The subject and attachment of the incoming email are chosen from a predetermined list.
|
|
|
Full View / NID: 752 / Submitted by: Zero_Tolerance
|
|
W32/Palyh.A-mm
|
|
|
Full View / NID: 732 / Submitted by: Zero_Tolerance
|
|
Just a Reminder - Keep Your Virus Database Current! -
While surfing through the web, I came alone a site with it's usual crapola of cookie monster ads, and porn sites ( which I of course despise). After I finished, my AntiVirus came up, giving me this messages stating that I had to do this and this, or my computer would explode and jump off a cliff. Knowing I couldn't let this happen, I advanced towards .. the list and spotted w.32/Delo contained would you like to:
-Delete
-Remove
-Quarrentine
-Or Skip
|
|
|
Full View / NID: 721 / Submitted by: Zero_Tolerance
|
|
- UPDATE your Anti - Virus Software
|
|
|
Full View / NID: 704 / Submitted by: Zero_Tolerance
|
|
A recently discovered virus codenamed Win32.NiceHello.A@mm is spreading as an e-mail attachment and targets MSN Messenger users.
The virus sends email messages (in the format described above) to the user's MSN/.NET Messenger's contacts to mass-multiply itself. It also tries to send a notification email:
|
|
|
Full View / NID: 701 / Submitted by: Zero_Tolerance
|
|
A little more on what we reported about the Internet problems. The Inquirer is back up. Their host has apparantly patched their servers. We had already patches our servers prior to the attack.
|
|
|
Full View / NID: 498 / Submitted by: Travis
|
|
Winevar-A, the latest mass mailing virus, adds insult to injury for infected victims. As well as attempting to delete files and sending repeating HTTP requests to Symantec's Web site (an unsophisticated DDoS ploy), Winevar also displays a rude message.
|
|
|
Full View / NID: 398 / Submitted by: TheComputerDoc
|