martymas Posted February 17, 2005 Report Share Posted February 17, 2005 hi team this is a low risk warning .tho still importantmartyAs of February 16, 2005, 05:31 PM (GMT - 08:00, Pacific Standard Time)TrendLabs has declared a Medium Risk Virus Alert to control the spread ofWORM_MYDOOM.BB.Trendlabs received numerous infection reports indicating that this malwareis spreading in Singapore and U.S. This worm was previously detectedas WORM_MYDOOM.M. It has very similar characteristics as with WORM_MYDOOM.M. However,this new MYDOOM worm comes compressed with MEW compression tool, whereasWORM_MYDOOM.M is compressed using UPX.Like earlier MYDOOM variants, this worm spreads via email through SMTP(Simple Mail Transfer Protocol), gathering target recipients from the WindowsAddress Book, the Temporary Internet Files folder, and certain fixeddrives. It uses social engineering techniques by sending out email messageswith a spoofed sender's name and poses as a failure delivery notification.The email message it sends has varying subjects, message bodies, andattachment file names.Apart from simply spreading via email, this worm also carries backdoorfunctionalities that leaves the infected machine vulnerable to remoteaccess. It drops a backdoor component named SERVICES.EXE in the Windows folder,which opens TCP port 1034 and waits for outside connections. Thisroutine virtually hands over control of the affected machine to a remoteattacker.TrendLabs will be releasing the following EPS deliverables:TMCM Outbreak Prevention Policy 149Official Pattern Release 2.416.00Damage Cleanup Template 520For more information on WORM_MYDOOM.BB, you can visit our Web site at:http://www.trendmicro.com/vinfo/virusencyc...=WORM_MYDOOM.BBYou can modify subscription settings for Trend Micro newsletters at:http://www.trendmicro.com/subscriptions/default.asp----------------------------------------------o0o----IMPORTANT NOTE!TrendLabs will also be releasing a 3-digit pattern file 989 thatcorresponds with the pattern indicated in this email. This 3-digit pattern is aspecial release for users running non-NPF compliant products (i.e., old3-digit pattern format) and is designed to provide protection against themost current malware threats. Users running non-NPF compliant products arestill urged to apply the NPF solution <http://www.trendmicro.com/en/support/npf/overview.htm>. These users may also upgrade to the latestproduct version. Only NPF-compliant products will be able to update withregular pattern releases.______________________________________________________________________This message was sent by Trend Micro's Newsletters Editor using ResponsysInteract .To unsubscribe from Trend Micro's Newsletters Editor: http://trendnewsletter.rsc03.net/servlet/o...RFpgLmDgLmDgSE0To update your subscription preference, or to change your email address:http://trendnewsletter.rsc03.net/servlet/w...vyf_f5.2evvf_88To view our permission marketing policy: http://www.rsvp0.netCopyright 1989-2004 Trend Micro, Inc. All rights reservedTrend Micro, Inc., 10101 N. De Anza Blvd., Suite 200, Cupertino, CA95014 Quote Link to post Share on other sites
thesidekickcat Posted February 18, 2005 Report Share Posted February 18, 2005 Thanks Marty, Your news items from Trend (Micro) labs are so useful to let us know the latest attempts to do us damage.My Norton had an antivirus update last night, second big one for day, that covered this new threat. They rate it on scale of 1-5 as a 3. They call it MyDoom AX, Click on it for more info including a removal tool for it if anyone gets infected with it. But better to get whatever brand of antivirus you have updated now folks and avoid this and all the other junk that is out to get us.Symantec Security ResponseGod bless everyone. Quote Link to post Share on other sites
bar5 Posted February 18, 2005 Report Share Posted February 18, 2005 Thanks Marty.I have Pc-cillin 2005, and it has updated 3 times today.They update almost every day. This is my first experience with Trend Micro, and so far am really impressed.Take careBarb Quote Link to post Share on other sites
martymas Posted February 18, 2005 Author Report Share Posted February 18, 2005 hi barb ive used it for several years .do you have the alert button on your tool button .unfortunately it dosent intercept viruses in or out but if you get one it is one of the few scanners that cleans without having to use safe mode.it dosent take up any space until you use it.some thing i notice it detected a potential highjack on my address bar.which i removed with microsoft anti spyware.can remember it doing that in the past. marty Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.