Jump to content

Another *&^%@* Worm


nellie2
 Share

Recommended Posts

I got this in Freds Langa List today

Another *&^%@* Worm

There's a malicious worm that's been around for a while, but that exploded last week; it masquerades as a message from an ISP or web site-

-- Verizon, AOL, and others; even from me ("Dear user of  Langa.com e- mail..." or something similar).

The email usually arrives with a password-protected Zip file attachment that contains executable files. The email text tells you how to open it to "protect yourself from spam" or to "reset your email account" or some such.

DO NOT OPEN THE FILE! It's not really from me--- or Verizon, or AOL, or whomever. No responsible party will *ever* send you an executable file, unasked for, out of the blue. I certainly will never, ever do so.

In this case, the file is a trojan designed to infect your system. The worm-writers placed the payload in a password-protected file to try to hide from some anti-virus tools. They also crafted the worm to do an unusually good job of spoofing the formats and headers--- it can look quite legitimate, at first glance.

Funnily enough, I got an email today supposedly from NTL, this is what it said,

Subject: Important notify about your e-mail account.

> Hello user  of  NTLWORLD.COM  e-mail server,

>

> Some of our clients complained about the  spam  (negative  e-mail content)

> outgoing from  your  e-mail  account. Probably, you have  been infected by

> a proxy-relay trojan server. In  order to keep your computer safe,

> follow the instructions.

>

> For details see the attach.

>

> In order to  read  the attach you have to use  the following password:

70877.

Norton removed the nasty

Norton AntiVirus removed the attachment: Attach.zip.

The attachment was infected with the W32.Beagle.J@mm virus.

Got another email yesterday along the same lines only this time it went something like this

Thank you for emailing [email protected]

Please reply to this message to confirm to us that your email address is valid. The content of your email reply to this message is ignored; it is only the unique reply address to which it is sent that matters.

Unless you reply to this message your original email (attached) will not be delivered.

This automatic response protects us against SPAM, the vast majority of which comes from invalid email addresses. You should only have to confirm your email address to us once. After that all your email to us will get through.

Further details:

Your message appeared to come from the email address:

    [email protected]

To release your message for delivery, please send an empty message to the following address, or use your mailer's "Reply" feature.

    [email protected]

If you do not respond to this confirmation request within 60 days, your message will not be delivered.

If you did not send the attached email message, it is likely that someone is using your email address as the from address on SPAM messages. Unfortunately there is not a lot you can do to prevent this from happening.

This message was created automatically by TMDA software - www.tmda.net.

Norton removed that one too

Norton AntiVirus removed the attachment: document_excel.pif.

The attachment was infected with the W32.Netsky.D@mm virus.

Please please be aware and on the lookout and don't open anything that looks even a little bit dodgy

Link to comment
Share on other sites

a² News

Dear Keith Jones,

Worm.Win32.Sober.D alert!

After the many new NetSky and MyDoom variants of the last weeks, a new variant of the Sober Worm arrived. Worm.Win32.Sober.D - so it's official name - uses the publicity of the MyDoom Worm as well as the confusion about the many new worms at the users to spread.

Sober.D masks itself as a warning email for the MyDoom Worm. In German speaking countries it sends itself in German language. In all other regions English is used.

The email subject is:

Microsoft Alarm: Bitte Lesen!

or

Microsoft alert: Please Read!

The english email body text is:

New MyDoom Virus Variant Detected!

A new variant of the W32.Mydoom (W32.Novarg) worm spread rapidly through the Internet.

Anti-virus vendor Central Command claims that 1 in 45 e-mails contains the MyDoom virus.

The worm also has a backdoor Trojan capability.

By default, the Trojan component listens on port 13468.

Protection:

Please download this digitally signed attachment.

This Update includes the functionality of previously released patches.

The email contains an attachment like all other current worms which is the worm. If you open the attachments, the Worm is activated and begins to spread itself.

If you run the worm, you will get the message:

This patch has been successfully installed.

or

This patch does not need to be installed on this system.

Sober.D can be detected and removed with a² with the latest signature updates loaded. The a² background guard blocks the worm immediately if it is started.

A more detailed description of the worm can be found at the a² Malware Database:

http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.D

Sincerley yours,

Your a² Team

http://www.emsisoft.com

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy