More Viruses, Trojans, Worms..
There are several new offenders spreading. Below summarized the
offenders and what they do:
W32.Anset.Worm
Alert Code - Alert Amber
Dubbed "Anset". You will receive an email with the subject line "ANTS Version 3.0"
and contains the following content:
"Attached you will find the brand new Version 3.0 of ANTS, the unique
freeware Trojan scanner. To install ANTS simply run the attached setup
file."
Mails copies of itself via Outlook, and makes a copy in the root Windows
installation folder. Saves its code in a randomly generated filename.
Has the ability to communicate with mail servers directly rather than
relying on Outlook's mail-transfer capabilities.
W32.Nimda.E@mm
Alert Code - Alert Amber
New version of W32.Nimda.A@mm. Contains bug-fixes
and other modifications designed to prevent detection
of this variant by AV software.
Differences from the original version includes:
Attachment has been changed to "sample.exe"
Dropped .dll file is now "httpodbc.dll"
Copies itself to \windows\system folder as "csrss.exe" instead of "mmc.exe".
W32.Klez.A@mm or W32.Poverty.A@mm
Alert Code - Alert RED ** Malicious **
Another mass-mailing email worm. Attempts to copy itself
into folders on both your local machine and network drives.
Exploits a vulnerability in MS Outlook and Outlookg Express,
so it will try to open itself when you open or even preview
the message.
Information and patch for this vulnerability can be found at:
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp
It also inserts the virus W32.ElKern.3326, and W32.ElKern.3326 can
also infect W32.Klez.A@mm.
Executes its payload on the 13th of every month. This will cause
files on local and mapped network drives to be zero bytes in
size.
W32.ElKern.3326
Alert Code - Alert RED ** Malicious **
Infects files over shared/mapped drives/directories. Will also try to
infect all executables in the \windows\system folder.
Windows NT/200 users - this virus will crash when first activated
Windows 9x users - if you have mapped network shares that is write-protected, this
virus will crash your computer after a short period.
Some files that become infected with this virus will not change in size.
Please contact your Online Technology account manager or system engineer
for assistance if you are hit by the above offenders.