Home Search Contact Us



Questions

Anyone that works with computers knows that asking questions is just part of the process. Client's of Ask and Receive enjoy the benefit of having a
place to go for answers.

 

 

Virus Information:

W32/Sober.d@MM is a Medium Risk mass-mailing worm posing as an official Microsoft patch for the Mydoom virus. Watch for telltale subject lines in English or German with the text "Microsoft Alarm: Please Read!" or "Microsoft Alarm: Bitte Lessen!" Note: Microsoft does not email patches.

The worm arrives as an executable attachment or inside a Zip archive. When run, it displays fake Windows warnings and error alerts. Using its own SMTP engine, W32/Sober.d@MM also mails itself to email addresses found on the infected computer.

Caution: An infected email can come from addresses you recognize.

A competition between computer-virus writers is responsible for more than a dozen recent variants of the Mydoom, Netsky and Bagle viruses in the past week.

That includes the most recent, W32/Bagle.j@MM, another Medium Risk mass-mailing worm with characteristics similar to its predecessors—including a potentially dangerous backdoor component.

W32/Netsky.c@MM is a Medium Risk mass-mailing worm that also copies itself to folders named "share" or "sharing" on an infected system.

It spreads by stealing email addresses, spoofing or forging the "from: field". Like its earlier counterpart, the worm tries to deactivate the W32/Mydoom.a@MM and W32/Mydoom.b@MM viruses on the host computer.


Upon infection, W32/Netskyk.c@MM will also spread via P2P programs like KaZaa, Bearshare and Limewire that use shared folder names containing the words "share" or "sharing".

Note: The attachment may be either a ZIP file (with the worm) or an executable, with a single (.doc, .htm, .rtm, .text) or double file extension (.com, .exe, .pif, .scr). Filenames that are carried within the worm include:

3D Studio Max 3dsmax.exe
Adobe Photoshop 9 full.exe
Adobe Premiere 9.exe
Ahead Nero 7.exe
Best Matrix Screensaver.scr

Caution—An infected email can come from addresses you recognize and may contain the following information:

Subject/Body: Varies. Examples include:

Your provider will be disabled!
Atell me more about your document!
explain!
do not visit the pages on the list I sent!
do not open the attachment!
Attachment: Varies. Examples include:

454543403
aboutyou
associal
attach2
auction
transfer

A variant of the original Mydoom virus, W32/Mydoom.f@MM is a Medium Risk mass-mailing worm that can open up hacker backdoors on infected systems and launch denial-of-service attacks that target www.microsoft.com and www.riaa.com domains.

Note: Unlike previous versions of Mydoom, Mydoom.f can also delete image, movie, Excel and Word files on an infected machine.

Like other mass-mailing viruses, W32/Mydoom.f@MM steals email addresses from an infected machine, then mails itself to other computers, often spoofing the "from field." The worm arrives with random subject lines, such as "Please read," "Something for you" or "Please reply". The body of the e-mail contains an executable file often disguised as a text file.

Caution: An infected email can come from addresses you recognize.


What to look for:

From: Randomly generated
Subject: Varies. Examples include:

Announcement
ApprovedNews
Attention
automatic responder
Bug
Body: Varies. Examples include:

Check the attached document.
Details are in the attached document. You need Microsoft Office to open it.
Greetings
Here is the document.
Here it is
I have your password :)
Attachment: Varies [.cmd, .bat, .exe, .pif, .cmd, .scr] but often arrives in a ZIP archive. 34,686 bytes. Examples include:
creditcard.bat, creditcard.zip, paypal.zip, photo.zip, textfile.zip

W32/Mydoom@MM
Dangerous virus that is sophisticated enough to trick users into opening the attachment. Click here to read more about the virus

 

Bagle A or "Beagle"
E-mail subject line: "hi"
Message text: "test : )"

Accompanying attachment: The file name is a random word, but the file extension is .exe
The disguise: The attachment is designed to look like a Microsoft calculator.
What happens? If the attachment is downloaded and executed, the worm will attempt to mail itself to every e-mail address in the user's address book. Reuters reports that the Bagle virus appears to be the handiwork of spammers who want to collect thousands of e-mail addresses they can re-sell to other spam e-mail marketers or keep for their own use. The virus contains code that could turn an infected computer into a zombie "spamming" machine that the spammers could control remotely. Bagle, which only affects computers running Microsoft Windows, is programmed to stop working on Jan. 28. That means, a new variant could be released soon after.

W32.Swen.A@mm virus
I received the Swen virus in the
following emails:


Many users are likely to open these
attachments as they appear to be
from Microsoft.

Special Thanks to Mike Camp for the following
Virus Updates and Tips for keeping your computer
free from viruses.


Date: 20 Sep 2003
From: "Mike Camp"

Subject: Bogus Windows Security Update

E-Mail Bears New Worm
A new worm called Swen is taking advantage of Windows users anxious to get security updates. It began making the rounds on Thursday, several anti-virus firms confirmed. It can pose as an e-mail from Microsoft bearing a bogus security update as a file attachment.

It spreads in several ways, including the traditional mass-mailing method of stealing addresses from address books on compromised machines, but also propagates over Internet Relay Chat (IRC) and peer-to-peer networks such as KaZaA. Successful infections attempt to steal account information, including usernames and passwords.

The worm also exploits a two-year-old vulnerability in Windows -- for which a fix is available from Microsoft -- that allows it to auto-execute on unpatched PCs. In those situations, the receiving system is infected even if its user doesn't open the attached file.

"Swen preys upon the good nature of individuals who want to patch their computer in the wake of new vulnerability and virus announcements," said Ken Dunham, the malicious code intelligence manager at security firm iDefense.

Antivirus software suppliers have already posted updates to their products' definition files to detect Swen. Windows updates are available at http://windowsupdate.microsoft.com


Date: 29 Aug 2003
From: Mike Camp
Subject: McAfee Stinger Anti-Virus Utility

McAfee has released a new tool for those who suspect they may be infected with one of the recent viruses.

McAfee AVERT Stinger

Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist when dealing with an infected system. Stinger utilizes next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations.
To download and view instructions, go to: http://vil.nai.com/vil/stinger/

Date: 28 Aug 2003
From: "Mike Camp"
Subject: Viruses, worms, and the network
** High Priority **

Recently, some of the e-mail users have gotten unusual messages. The suspect messages are actually not from the sources they appear to be from. These messages are generated by an computer infected by a virus (a Sobig worm variant).

A direct quote from McAfee's Website:
"A new variant of W32/Sobig, W32/Sobig.f@MM is a High Risk mass-mailing worm. It arrives as an email attachment with a .pif or .scr extension. When run, it infects the host computer, then emails itself (using its own SMTP engine) to harvested email addresses from the victim's machine.
In addition, when it propagates, the worm "spoofs" the "from: field", using one of the harvested email addresses. So exercise care when opening emails with attachments. An infected email can come from addresses you recognize.
Because it sends so many emails, a worm like Sobig also saps bandwidth and slows network performance. Worse, it can also open up a user's computer port, making it vulnerable to hackers, who can plant dangerous Trojans. These malicious programs often let unauthorized users remotely take over a system, steal personal information or use the infected PC to send spam."

You may also get returned mail, undeliverable mail, or replies to e-mail you never sent. This is because the virus "spoofs" e-mail addresses. It doesn't mean that your computer is infected, but that someone somewhere is infected with the virus, and that virus is spoofing your e-mail (as well as countless other e-mail addresses).

This worm uses a technique known as "spoofing." When it performs its email routine, it can use a randomly chosen address that it finds on an infected computer as the "From:" address. Numerous cases have been reported in which users of uninfected computers received complaints that they sent an infected message to someone else.

For example, Linda Anderson is using a computer that is infected with W32/Sobig.f@MM. Linda is not using an anti-virus program or does not have current virus definitions. When Sobig performs its emailing routine, it finds the email address of Harold Logan. It inserts Harold's email address into the "From:" portion of an infected message that it then sends to Janet Bishop. Janet then contacts Harold and complains that he sent her an infected message, but when Harold scans his computer, McAfee Anti-Virus does not find anything--as would be expected--because his computer is not infected.

The subject line, message bodies, and attachment file names are random. The "From" address is randomly chosen from email addresses that the worm finds on the infected computer The worm will search files on the infected computer for email addresses.

This worm searches the Windows address book, the ICQ database, and local files for email addresses. The worm sends an email message to these addresses with itself as an attachment. The worm contains its own SMTP engine and attempts to guess at available SMTP servers. For example, if the worm encounters the address user@abc123.com it will attempt to send email via the server smtp.abc123.com.

As long as we use computers for communication, and as long as there are programmers who write malicious code, then there will be viruses. The best policy is to continue to practice safe computing, which involves:

1. Do not open an attachment from ANYONE (even someone you know) unless you are expecting it - or you have verified that it truly is from the indicated sender.

2. Any email you weren't expecting should be treated with suspicion, even if it comes from someone you know. It is worth calling whoever sent it to you to check that they intended to send you the email.

3. Do not run, download or forward any unsolicited executables, documents, spreadsheets, etc. Anything that runs on your PC should be virus checked and approved first.

4. Do not open any files with a double file extension, (e.g. report.doc.vbs). Under normal circumstances you should never need to receive or use these.

5. Do not download executables (.exe) or documents from the internet. These are often used to spread computer viruses.

6.Although JPG, GIF and MP3 files cannot be infected with a virus, viruses can be disguised as these file types. Jokes, pictures, graphics, screensavers and movie files should be treated with the same amount of suspicion as other file types.

7. If you have to work at home ensure that you follow the same procedures there as you do at work. Viruses can easily be brought into an organization along with work that has been done on a home PC.

8. If you use diskettes or "Zip disks" then scan them regularly for viruses.

9. Make copies of your important files. This will provide you with a backup in case a virus damages your computer.

10. If you think you have been infected with a virus, contact me immediately. If in doubt, always ask for advice; do not open the file or email.

11. Always use an antivirus software such as norton or mcafee and be sure to keep it updated.


But to be accurate, anti-virus software can't predict a virus, it can only respond to viruses that have been identified, dissected and responded to in an update. It usually takes weeks for this process to happen. It is the nature of anti-virus software to be reactive; it cannot be proactive. This means that there is always a chance that a virus could affect us even when all current patches and updates have been applied.

Testimonial

I have been so pleased with the computer instruction I have received from Stacey. She understands my needs and my level of efficiency so her help is tailored for my comprehension.This makes my computer education stress free! On top of that her response to my call is immediate!

Lanny Webster

Services Contact Us Samples Ask & Receive Hosting FAQ Pricing Home