martymas Posted December 3, 2004 Report Share Posted December 3, 2004 hi team havent been on the board for some time so im not sure if this has been posted or not take care out there. martyTREND MICRO WEEKLY VIRUS REPORT(by TrendLabs Global Antivirus and Research Center) *********************************************************************------------------------------------------------------------------------Date: Friday December 3, 2004------------------------------------------------------------------------To read an HTML version of this newsletter, go to: http://www.trendmicro.com/en/security/report/overview.htmIssue Preview: 1. Trend Micro Updates - Pattern File & Scan Engine Updates2. Mass-mailing MUGLY – WORM_MUGLY.A (Low Risk)3. Top 10 Most Prevalent Global Malware 4. Trend Micro URL Filtering Module - Important Product Update NowAvailable5. Ask Santa for a Handheld Device & Protect it with Trend Micro MobileSecurityNOTE: Long URLs may break into two lines in some mail readers. Should this occur, please copy and paste the URL into your browser window.************************************************************************1. Trend Micro Updates - Pattern File & Scan Engine Updates ------------------------------------------------------------------------PATTERN FILE: 2.279.00 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VRSCAN ENGINE: 7.100 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VS2. Mass-mailing MUGLY – WORM_MUGLY.A (Low Risk)------------------------------------------------------------------------WORM_MUGLY.A is a non-destructive mass-mailing worm that arrives viaemail, as an attachment. This memory-resident worm searches the infected systemfor target email addresses in files with certain extension names. However,it avoids sending email messages to email addresses that contain specific strings,most of which are related to antivirus and security companies. It runs onWindows 95, 98, ME, NT, 2000, and XP.Upon execution, it drops a copy of itself in the Windows system folder asthe file XXX.TMP. It also drops the following files in the Windows systemfolder: ATTACHED.ZIP - a ZIP-compressed copy of itself WINIT.EXE - a worm that is detected by Trend Micro as WORM_SDBOT.AFE UGLYM.JPG - a normal .JPG file SVKP.SYS - an unpacker component used to register the SVK Protector,which this worm uses to unpack one of its dropped files that is compressed by SVKP ANSMTP.DLL - a standard SMTP (Simple Mail Transfer Protocol) mailingengine BSZIP.DLL - a standard archive engineIt creates three registry entries that allow it to automatically executeat every system startup. In addition, it registers a standard SMTP engineon the infected system, which allows it to perform its mass-mailing routine.This worm looks for target email recipients in files with the followingextensions: ADB ASP DBX DOC HTM HTML PHP SHT TBB TXT WAB However, it avoids sending email messages to addresses that contain any ofthe following strings: .gov Adaware Kaspersky Lavasoft Mcafee Symantec avguk grisoft nod32 pandasoftware sophos sophos trendmicro The email message that it sends out has the following details: From: <spoofed> Subject: (any of the following) • You have an Admirer • Your Pic On A Website!! • Rate My Pic....... • Hhahahah lol!!!! Message Body: (any of the following) • Someone has asked us on there behalf to send you this email and tellyou they think you are wonderfull!!! All the The mystery personsdetails you need are enclosed in the attachment please download and respondtelling us if you would like to make further contact with this person. Regards Hallmark Admirer Mail Admin. • I was looking at a website and came across this pic they look justlike you! infact im sure it is lol , did you send this pic into them ? or isit someonce else :S ? Ive Added the pic in a zip so download it and check& email me back! · Hi ive sent 5 emails now and nobody will rate mypic!! please download and tell me what you think out of 10 , dontworry if you dont like it just say i wont be offended p.s i was drunk when itwas taken • i found this on my computer from ages ago download it and see if youcan remember it lol i was lauging like mad when i saw it! email me backhaha... Attachment: (any of the following) • Pic_001.exe • Photo_01.pif • admire_001.exe • is_this_you.scr • love_04.scr • for_you.pif • Sexy_09.scrThis worms payload displays the dropped image file, UGLYM.JPG.If you would like to scan your computer for WORM_MUGLY.A or thousandsof other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VTWORM_MUGLY.A is detected and cleaned by Trend Micro pattern file#2.274.01 and above. For additional information about WORM_MUGLY.A please visit: http://www.trendmicro.com/vinfo/virusencyc...me=WORM_MUGLY.A3. Top 10 Most Prevalent Global Malware (from November 26, 2004 to December 2, 2004)------------------------------------------------------------------------1. WORM_NETSKY.P2. HTML_NETSKY.P3. WORM_SOBER.I4. JAVA_BYTEVER.A5. WORM_NETSKY.D6. TROJ_AGENT.FL7. WORM_NETSKY.B8. WORM_NETSKY.C9. HTML_SUNFRAUD.B10. WORM_NETSKY.Q4. Trend Micro URL Filtering Module - Important Product Update NowAvailable------------------------------------------------------------------------ Trend Micro URL Filtering, an optional module integrated with Trend MicroInterScan Web Security Suite, enables companies to manage employee Internetuse by restricting access to unwanted Web sites. If you have installed InterScan Web Security Suite with URL Filteringmodule, an important product update is now available:For Windows: InterScan Web Security Suite Patch for Windows v2.0 For Linux: InterScan Web Security Suite Patch for Linux v2.0 For Solaris: InterScan Web Security Suite Patch for Solaris v2.0 PLEASE NOTE: This is a mandatory patch, as all unpatched systems will beunable to receive URL Filtering updates after December 7, 2004.You may download the patch by visiting: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VUIf you have questions or need assistance, please contact Trend MicroTechnical Support in your area: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VW5. Ask Santa for a Handheld Device & Protect it with Trend Micro MobileSecurity------------------------------------------------------------------------ If you or someone you know receives a data-centric handheld device for theholidays, get into the holiday spirit and download free software to helpprotect your device from viruses!Owners of data-centric mobile devices using the Microsoft Windows Mobile2003 operating system (examples: Motorola MPx200, MPx220, Samsung SCH-i600,SPV E200 or C500) or the Symbian 7.0/UIQ operating system (Sony EricssonP800, P900 & P910, Motorola A920, A925 & A1000, etc) can protect theirdevices with Trend Micro Mobile Security - a new product that providesprotection from viruses and SMS spam. Trend Micro Mobile Security will be available for other devices using theSymbian 7.0/UIQ operating system (Sony Ericsson P900, P920, etc.) aswell as Microsoft Windows Mobile for PocketPC (Phone Edition) and MicrosoftWindows Mobile 2003 Second Edition in January 2005. Trend Micro Mobile Security version 1.0 provides free protection foryour data-centric mobile device through June 30, 2005. Read more about Trend Micro Mobile Security:www.trendmicro.com/mobilesecurityDownload your free copy of Trend Micro Mobile Security: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VY***********************************************************************************______________________________________________________________________This message was sent by Trend Micro's Newsletters Editor using ResponsysInteract .To unsubscribe from Trend Micro's Newsletters Editor: http://trendnewsletter.rsc03.net/servlet/o...RFpgLmDgLmDgSE0To update your subscription preference, or to change your email address:http://trendnewsletter.rsc03.net/servlet/w...pkNlyLihkm_UV_WTo view our permission marketing policy: http://www.rsvp0.netCopyright 1989-2004 Trend Micro, Inc. All rights reservedTrend Micro, Inc., 10101 N. De Anza Blvd., Suite 200, Cupertino, CA95014 Quote Link to post Share on other sites
tg1911 Posted December 3, 2004 Report Share Posted December 3, 2004 Thanks for the heads-up, Marty. Quote Link to post Share on other sites
echobay Posted December 3, 2004 Report Share Posted December 3, 2004 Thanks for the info marty... Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.