Infosec
English 繁體版 简体版 Text Only Version

Navigation Menu 1

General UsersYoungsters & StudentsParents and TeachersIT ProfessionalsSME
FAQ Search :
Change text size: Text Size: Default Size (A) Text Size: Larger (A) Text Size: Largest (A)
Infosec

Navigation Menu 2

 

Virus & Malicious Code Alerts  

 
 

Virus Alerts in 2004

  • W32.Erkez.D@mm (15 Dec 2004)
    W32.Erkez.D@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in a Christmas greeting email message written in different languages such as Hungarian or English with varying subjects, message bodies, spoofed sender addresses and an attachment with a .COM,.CMD, .PIF, .BAT or .ZIP file extension. The worm also spreads via peer-to-peer file-sharing networks. It opens a backdoor on TCP port 8181 and attempts to terminate various anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Sober.I@mm (19 Nov 2004)
    W32.Sober.I@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message written in either English or German with varying subjects, message bodies, spoofed sender addresses and an attachment with a .EXE, .SCR, .COM, .PIF, .BAT or .ZIP file extension. When infecting a computer, it displays a fake error message containing the text "WinZip_Data_Module is missing ~Error: {2A0DCCF6}". For more information about this virus, please refer to the following links:

  • W32.Beagle.AW@mm (30 Oct 2004)
    W32.Beagle.AW@mm is a mass-mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with spoofed sender addresses and the subject "Re:", "Re: Hello", "Re: Hi", "Re: Thank you!" or "Re: Thanks :)". The message body will be ":)" or ":))", and the attachment will have the name Price, price or Joke with a .COM, .CPL, .EXE or .SCR file extension. The worm also spreads via peer-to-peer file-sharing networks. When the worm is executed, it attempts to download a file from a list of websites. It opens a backdoor on TCP port 81 and attempts to terminate various anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.AV@mm (29 Oct 2004)
    W32.Beagle.AV@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with spoofed sender addresses and the subject "Re:", "Re: Hello", "Re: Hi", "Re: Thank you!" or "Re: Thanks :)". The message body will be ":)" or ":))", and the attachment will have the name Price, price or Joke with a .COM, .CPL, .EXE or .SCR file extension. When the worm is executed, it attempts to download a file from a list of websites. W32.Beagle.AV@mm also spreads via network shares, opens a backdoor on TCP port 81 and attempts to terminate various anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.AO@mm (10 Aug 2004)
    W32.Beagle.AO@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with a blank subject and spoofed sender addresses. The message body will be "New price" and the attachment has the name price.zip, price2.zip, price_new.zip, price_08.zip, 08_price.zip, newprice.zip, new_price.zip or new__price.zip. The ZIP file contains two files, an html file (price.html) and a downloader (price.exe). When price.exe is executed, it downloads the worm itself from a list of websites. W32.Beagle.AO@mm also spreads via peer-to-peer file-sharing networks, opens a backdoor on UDP and TCP port 80 and attempts to terminate several anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.AG@mm
    W32.Beagle.AG@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with varying subjects, message bodies, spoofed sender addresses and an attachment with a .EXE, .SCR, .COM, .CPL, or .ZIP file extension. If the attachment is a password-protected .ZIP file, the password is included in the message body. Upon execution, the worm copies itself into the Windows System directory as WinXP.exe. W32.Beagle.AG@mm also spreads via peer-to-peer file-sharing networks, opens a backdoor on TCP port 1080 and attempts to terminate several anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.AB@mm
    W32.Beagle.AB@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with varying subjects, message bodies, spoofed sender addresses and an attachment with a .EXE, .SCR, .COM, .CPL, or .ZIP file extension. If the attachment is a password-protected .ZIP file, the password is included in the message body. The worm also spreads via peer-to-peer file-sharing networks. W32.Beagle.AB@mm also opens a backdoor on TCP port 1080 and attempts to terminate several anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.Y@mm
    W32.Beagle.Y@mm is a mass mailing worm that uses its own SMTP engine to send itself to email addresses harvested from infected machines. It arrives in an email message with varying subjects, message bodies, spoofed sender addresses and an attachment with a .HTA, .VBS, .EXE, .SCR, .COM, .CPL, or .ZIP file extension. If the attachment is a password-protected .ZIP file, the password is included in the message body. The worm also spreads via peer-to-peer file-sharing networks. When infecting a computer, it displays a fake error message containing the text "Can't find a viewer associated with the file". W32.Beagle.Y@mm also opens a backdoor on TCP port 1234 and attempts to terminate several anti-virus and security related applications. For more information about this virus, please refer to the following links:

  • W32.Beagle.J@mm
    W32.Beagle.J@mm is a mass-mailing worm that arrives as a zipped attachment that contains the worm's executable with a random file name and an icon that makes the file looks like a WordPad file. It also spreads via peer-to-peer file-sharing networks. Furthermore, W32.Beagle.J@mm also contains a backdoor component.

  • W32.Netsky.D@mm
    W32.Netsky.D@mm is a mass-mailing worm that is a new variant of W32.Netsky.C@mm. The worm also attempts to deactivate the W32/Mydoom.a@MM and W32/Mydoom.b@MM worms. On Mar 02, between 6:00 and 9:00 am, the worm makes random beeping sounds with varying pitches and rhythm.

  • W32.Beagle.E@mm
    W32.Beagle.E@mm is a mass-mailing worm that arrives as a zipped attachment that contains the worm's executable with a random file name and an icon that makes the file looks like a text file. W32.Beagle.E@mm also contains a backdoor component.

  • W32.Beagle.C@mm
    W32.Beagle.C@mm is a mass-mailing worm that arrives as a zipped attachment that contains the worm's executable with a random file name and an icon that makes the file looks like an Excel spreadsheet. W32.Beagle.C@mm also contains a backdoor component.

  • W32.Netsky.C@mm
    W32.Netsky.C@mm is a mass-mailing worm that also spreads via network shares and peer-to-peer file-sharing networks. The worm also attempts to deactivate the W32/Mydoom.a@MM and W32/Mydoom.b@MM worms. On Feb 26, between 6:00 and 8:00 am, the worm makes random beeping sounds with varying pitches and rhythm.

  • W32.Mydoom.F@mm
    W32.Mydoom.F@mm is a mass-mailing worm that opens a backdoor on TCP port 1080. It also performs a Denial of Service (DoS) attack against www.microsoft.com and www.riaa.com between 17th and 22nd of any month.

  • W32.Netsky.B@mm
    W32.Netsky.B@mm is a mass-mailing worm that also spreads via network shares and peer-to-peer file-sharing networks. The worm also attempts to deactivate the W32/Mydoom.a@MM and W32/Mydoom.b@MM worms.

  • W32.Beagle.B@mm
    W32.Beagle.B@mm is a mass-mailing worm that includes a backdoor component. When infecting a computer, the worm deliberately launches the Windows Sound Recorder to hide its malicious intent.

  • W32.Mydoom.A@mm
    W32.Mydoom.A@mm is a mass-mailing and peer-to-peer file-sharing worm that includes a backdoor component. When infecting a computer, the worm deliberately launches Notepad with garbage data in it to pretend that it is harmless.

  • W32.Beagle.A@mm
    W32.Beagle.A@mm is a mass-mailing worm that includes a backdoor component. When infecting a computer, the worm deliberately launches the Calculator application to hide its malicious intent.

More Virus Alerts

Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) - Computer Virus

Selected virus alerts in recent years

 
 
     
Back back to topTop
 

Footer Menu

Sitemap | Contact Us | Privacy Policy | Important Notices
 
General Users Youngsters & Students Parents & Teachers IT Professionals SME