nellie2 Posted March 8, 2004 Report Share Posted March 8, 2004 I got this in Freds Langa List todayAnother *&^%@* WormThere's a malicious worm that's been around for a while, but that exploded last week; it masquerades as a message from an ISP or web site--- Verizon, AOL, and others; even from me ("Dear user of Langa.com e- mail..." or something similar).The email usually arrives with a password-protected Zip file attachment that contains executable files. The email text tells you how to open it to "protect yourself from spam" or to "reset your email account" or some such.DO NOT OPEN THE FILE! It's not really from me--- or Verizon, or AOL, or whomever. No responsible party will *ever* send you an executable file, unasked for, out of the blue. I certainly will never, ever do so.In this case, the file is a trojan designed to infect your system. The worm-writers placed the payload in a password-protected file to try to hide from some anti-virus tools. They also crafted the worm to do an unusually good job of spoofing the formats and headers--- it can look quite legitimate, at first glance.Funnily enough, I got an email today supposedly from NTL, this is what it said, Subject: Important notify about your e-mail account.> Hello user of NTLWORLD.COM e-mail server,>> Some of our clients complained about the spam (negative e-mail content)> outgoing from your e-mail account. Probably, you have been infected by> a proxy-relay trojan server. In order to keep your computer safe,> follow the instructions.>> For details see the attach.>> In order to read the attach you have to use the following password:70877.Norton removed the nastyNorton AntiVirus removed the attachment: Attach.zip.The attachment was infected with the W32.Beagle.J@mm virus.Got another email yesterday along the same lines only this time it went something like thisThank you for emailing [email protected]Please reply to this message to confirm to us that your email address is valid. The content of your email reply to this message is ignored; it is only the unique reply address to which it is sent that matters.Unless you reply to this message your original email (attached) will not be delivered.This automatic response protects us against SPAM, the vast majority of which comes from invalid email addresses. You should only have to confirm your email address to us once. After that all your email to us will get through.Further details:Your message appeared to come from the email address: [email protected]To release your message for delivery, please send an empty message to the following address, or use your mailer's "Reply" feature. [email protected]If you do not respond to this confirmation request within 60 days, your message will not be delivered.If you did not send the attached email message, it is likely that someone is using your email address as the from address on SPAM messages. Unfortunately there is not a lot you can do to prevent this from happening.This message was created automatically by TMDA software - www.tmda.net.Norton removed that one tooNorton AntiVirus removed the attachment: document_excel.pif.The attachment was infected with the W32.Netsky.D@mm virus.Please please be aware and on the lookout and don't open anything that looks even a little bit dodgy Quote Link to comment Share on other sites More sharing options...
andsome Posted March 9, 2004 Report Share Posted March 9, 2004 a² NewsDear Keith Jones,Worm.Win32.Sober.D alert!After the many new NetSky and MyDoom variants of the last weeks, a new variant of the Sober Worm arrived. Worm.Win32.Sober.D - so it's official name - uses the publicity of the MyDoom Worm as well as the confusion about the many new worms at the users to spread.Sober.D masks itself as a warning email for the MyDoom Worm. In German speaking countries it sends itself in German language. In all other regions English is used. The email subject is:Microsoft Alarm: Bitte Lesen!orMicrosoft alert: Please Read!The english email body text is:New MyDoom Virus Variant Detected! A new variant of the W32.Mydoom (W32.Novarg) worm spread rapidly through the Internet. Anti-virus vendor Central Command claims that 1 in 45 e-mails contains the MyDoom virus. The worm also has a backdoor Trojan capability. By default, the Trojan component listens on port 13468. Protection: Please download this digitally signed attachment. This Update includes the functionality of previously released patches.The email contains an attachment like all other current worms which is the worm. If you open the attachments, the Worm is activated and begins to spread itself.If you run the worm, you will get the message:This patch has been successfully installed.orThis patch does not need to be installed on this system.Sober.D can be detected and removed with a² with the latest signature updates loaded. The a² background guard blocks the worm immediately if it is started.A more detailed description of the worm can be found at the a² Malware Database:http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.DSincerley yours,Your a² Teamhttp://www.emsisoft.com Quote Link to comment Share on other sites More sharing options...
trackrat Posted March 9, 2004 Report Share Posted March 9, 2004 Just had the same E-Mail Andsome. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.