martymas Posted October 22, 2004 Report Share Posted October 22, 2004 hi team if this hasnet been posted before just recieved it this morningmarty2. What's a WOOT? – WORM_WOOTBOT.BJ (Low Risk)3. Top 10 Most Prevalent Global Malware 4. Trend Micro PC-cillin Internet Security 2005 Now AvailableNOTE: Long URLs may break into two lines in some mail readers. Should this occur, please copy and paste the URL into your browser window.************************************************************************1. Trend Micro Updates - Pattern File & Scan Engine Updates ------------------------------------------------------------------------PATTERN FILE: 2.208.00 http://www.trendmicro.com/download/pattern.aspSCAN ENGINE: 7.100 http://www.trendmicro.com/download/engine.asp 2. What's a WOOT? – WORM_WOOTBOT.BJ (Low Risk)------------------------------------------------------------------------WORM_WOOTBOT.BJ is a non-destructive worm that takes advantage of theWindows LSASS vulnerability in order to propagate. It drops a copy ofitself into default shared folders of unpatched machines. It steals the CDkeys of popular game applications, Microsoft Windows Product IDs, and YahooMessenger IDs. It updates itself by creating the file 1.BAT and executingit afterwards. This batch file downloads a copy of the worm from theInternet and then executes it on the compromised system. This worm iscurrently spreading in-the-wild and infecting systems that are running on Windows95, 98, ME, NT, 2000, and XP. Upon execution, this worm drops a copy of itself as SERVICED.EXE in theWindows system folder. It executes its dropped copy and then deletesitself afterwards. It then adds several registry entries, that allow it torun automatically at every system startup.This worm exploits the Windows LSASS vulnerability to propagate. Thisvulnerability is a buffer overrun that allows remote code execution andallows an attacker to gain full control of infected systems. Thisvulnerability is discussed in more detail on the Trend Micro Security Advisories pageat: http://www.trendmicro.com/en/security/advi...es/ms04-011.htmThis worm copies and executes itself on vulnerable systems and searchesfor the following default network shares: ADMIN$ C$ D$ IPC$ It steals Microsoft Windows Product IDs and Yahoo Messenger IDs, as wellas the CD keys of the following popular games: Battlefield 1942 Battlefield 1942: Secret Weapons Of WWII Battlefield 1942: The Road To Rome Battlefield 1942: Vietnam Black and White Command and Conquer: Generals Command and Conquer: Generals: Zero Hour Command and Conquer: Red Alert2 Command and Conquer: Tiberian Sun Counter-Strike FIFA 2002 FIFA 2003 Freedom Force Global Operations Gunman Chronicles Half-Life Hidden and Dangerous 2 IGI2: Covert Strike Industry Giant 2 James Bond 007: Nightfire Medal of Honor: Allied Assault Medal of Honor: Allied Assault: Breakthrough Medal of Honor: Allied Assault: Spearhead Nascar Racing 2002 Nascar Racing 2003 Need For Speed: Hot Pursuit 2 Need For Speed: Underground Neverwinter Nights NHL 2002 NHL 2003 Ravenshield Shogun: Total War: Warlord Edition Soldier Of Fortune 2 Soldiers Of Anarchy The Gladiators Unreal Tournament 2003 Unreal Tournament 2004 This worm appears to possess backdoor capabilities. It updates itself bycreating and executing the file 1.BAT. which downloads a copy of theworm from the Internet and then executes it on the compromised system. If you would like to scan your computer for WORM_WOOTBOT.BJ or thousandsof other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://housecall.trendmicro.com/WORM_WOOTBOT.BJ is detected and cleaned by Trend Micro pattern file#2.206.00 and above. For additional information about WORM_WOOTBOT.BJ please visit: http://www.trendmicro.com/vinfo/virusencyc...WORM_WOOTBOT.BJ3. Top 10 Most Prevalent Global Malware (from October 15, 2004 to October 21, 2004)------------------------------------------------------------------------1. WORM_NETSKY.P2. PE_ZAFI.B3. HTML_NETSKY.P4. WORM_NETSKY.D5. JAVA_BYTEVER.A6. WORM_NETSKY.B7. WORM_NETSKY.C8. WORM_ANIG.A9. WORM_NETSKY.Q10. HTML_CITIFRAUD.C4. Trend Micro PC-cillin Internet Security 2005 Now Available------------------------------------------------------------------------ Trend Micro™ PC-cillin™ Internet Security 2005 protects your PC andhome network against all types of viruses, worms, Trojans, and blendedthreats—including network viruses such as MYDOOM and SASSER. It also blockshackers, detects and removes spyware, guards against phishing attacks,filters unwanted content, and minimizes spam. New features include HomeNetwork Control and Wi-Fi Intrusion Detection which extends desktop security toyour home and wireless networks.Key Features:-Comprehensive Virus Security-Enhanced Spyware Detection and Removal-Anti-Phishing –New!-Home Network Control –New!-Wi-Fi Intrusion Detection –New!-Improved Spam Filtering -Personal Firewall Read more about Trend Micro PC-cillin Internet Security 2005:http://www.trendmicro.com/en/products/desk...te/overview.htm***********************************************************************************______________________________________________________________________This message was sent by Trend Micro's Newsletters Editor using ResponsysInteract .To unsubscribe from Trend Micro's Newsletters Editor: http://trendnewsletter.rsc03.net/servlet/o...RFpgLmDgLmDgSE0To update your subscription preference, or to change your email address:http://trendnewsletter.rsc03.net/servlet/w...kNlyLihkm_UT_VVTo view our permission marketing policy: http://www.rsvp0.netCopyright 1989-2004 Trend Micro, Inc. All rights reservedTren Quote Link to post Share on other sites
tg1911 Posted October 22, 2004 Report Share Posted October 22, 2004 Thanks for theupdate, Marty. Quote Link to post Share on other sites
thesidekickcat Posted October 22, 2004 Report Share Posted October 22, 2004 Thanks for the info, Marty.Each time I hear of these new and ever more destructive things, I wonder why the people who write them can't put their computer talents towards benefiting others. Why do they need to do bad things to people to be satisfied with their sorry lives? How can they live with themselves knowing the trouble they cause? What a waste of talent/knowledge. How sad that they don't do good instead of harm. Shame on them for what they do to harm others. God bless everyone. Quote Link to post Share on other sites
martymas Posted October 23, 2004 Author Report Share Posted October 23, 2004 yes i agree with that i wished i had one tenth of that talent.isnt it human nature to take advantage of the not so talented we only have to lookat around us wars killings ect and these people who write virus and spy ware.just as well people like you i and are street wise .i have a friends whos son is trying to learn hacking.and i get so angry.he keeps at me to inquire on the board.but no way will i do that marty Quote Link to post Share on other sites
sultan_emerr Posted October 24, 2004 Report Share Posted October 24, 2004 Thanks Marty Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.