Computing News
F E B R U A R Y 2 0 0 2

Computing News

Computing News
Back Issues

Computer Security

Computing Infrastructure Support (CIS)

CIS Services

Computing Standards

Software Downloads


CIS Computer
Help Desk

CIS Help
Request Form


Unix Services

ISS

IMAP4

Calendaring


   
Monthly Virus Update - What the VirusWall is Catching; Alerts on Myparty and Shoho
 

Here's a look at the top viruses blocked by the LBNL viruswall in January:

Number
caught

Percent
of total

Virus

More
info

1469

48%

MyParty

See below

532

18%

BadTrans

November CN

345

11%

Magistr

no article

331

11%

Sircam

September CN

178

6%

Nimda

September CN

81

3%

Shoho

See below

Myparty

Windows users: the Myparty virus (W32/Myparty@MM) is now circulating around the Internet. If a message with the subject: "New photos from my party" arrives in your mail queue, don't be fooled. The message contents direct those who receive it to go to www.myparty.yahoo.com. If you try to go to this site, instead of going to what appears to be a web address, your system will run an attached executable file that will infect your system.

Identifying marks:
Subject: "New photos from my party"
Message: "How are you? When I saw this screen saver, i immediately thought of you. I am in a harry, I promise you will love it!" www.myparty.yahoo.com
Attachment: "www.myparty.yahoo.com"

For more information.


Shoho

Windows users: Shoho is an email worm that spreads by sending itself through an email attachment. The worm also can send out other files (steal information) and perform destructive actions. Email addresses are obtained from the files on local disks with those extensions: .eml, .wab, .dbx, *.mbx, *.xls, *.xlt, *.mdb. The worm has a destructive payload -- It deletes all files in the current directory. It can also delete files in the Windows root directory after rebooting.

Identifying marks:
Subject: "Welcome to Yahoo! Mail"
Body: "Welcome to Yahoo! Mail"
Attachment: "readme.txt <lots of spaces> .pif"

For more information.


Top | Return to Computing News