<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>MVP Jubo Security Blog : Latest Virus Threats</title><link>http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx</link><description>Tags: Latest Virus Threats</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>An Online ticket?!?</title><link>http://msmvps.com/blogs/jubo/archive/2008/09/22/1648754.aspx</link><pubDate>Mon, 22 Sep 2008 14:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1648754</guid><dc:creator>jubo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1648754</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/09/22/1648754.aspx#comments</comments><description>&lt;p&gt;What a surprise... This morning I was happily working at the office, hhmm... okay, from home..., when Outlook notified me that I had received an email. When I checked it was from an unknown company USA3000 Airlines. When I read the email they even had a ticket for me and had charged the credit card for $646.27. I thought, that should be at least a ticket to fly across the pond. Well, could have been a surprise from my wife since she&amp;#39;s visiting family in the USA. But no, I unzipped the file and there was a file called: &amp;quot;eTicket.doc.exe&amp;quot; and... not detected by McAfee&amp;#39;s antivirus program... yet... Submitted the file to &lt;a target="_blank" href="http://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt;&amp;nbsp;and you can find the result &lt;a target="_blank" href="http://www.virustotal.com/analisis/47fc08723f21ca1450717d5b0855c9fe"&gt;here&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Then I also submitted the file to McAfee&amp;#39;s &lt;a href="http://www.webimmune.net/"&gt;WebImmune&lt;/a&gt;&amp;nbsp;and they found a &amp;quot;new detection&amp;quot; and named it &amp;quot;&lt;a target="_blank" href="http://us.mcafee.com/virusInfo/default.asp?id=description&amp;amp;virus_k=141745"&gt;spy-agent.bw&lt;/a&gt;&amp;quot;. Not really a new one but a new variant. Not long after that I received an &amp;quot;Extra.dat&amp;quot; file from &lt;a target="_blank" href="http://www.avertlabs.com/"&gt;AvertLabs&lt;/a&gt; for some extra protection. See also McAfee&amp;#39;s Avert Labs Blog: &lt;a target="_blank" href="http://www.avertlabs.com/research/blog/index.php/2008/07/25/invoice-spam-takes-flight/"&gt;Invoice Spam Takes Flight&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;No e-ticket for me this morning... but the computer is still safe. Now I only wonder how it came through the company&amp;#39;s security. They run Symantec stuff...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1648754" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Spyware/default.aspx">Spyware</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Olympic attachment?</title><link>http://msmvps.com/blogs/jubo/archive/2008/08/08/1643892.aspx</link><pubDate>Fri, 08 Aug 2008 06:36:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1643892</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1643892</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/08/08/1643892.aspx#comments</comments><description>&lt;p&gt;Not only the Olympic games have started, but also the malware games related to the Olympics. One of the latest is that if you receive an attachment named as: &amp;quot;ioc_guidelines_for_persons_accredited_at_the_xxix_olympiad.pdf&amp;quot; then delete this immediately. If you open it then it could execute a malicious JavaScript that exploits a patched Adobe Reader vulnerability. And it follows to install a backdoor detected as &lt;a href="http://vil.nai.com/vil/content/v_143081.htm" target="_blank"&gt;BackDoor-DMG&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;McAfee has named this one: &amp;quot;Exploit-PDF.b&amp;quot;; for more detailed information about it check this article: &lt;a href="http://vil.nai.com/vil/content/v_144105.htm" target="_blank"&gt;Exploit-PDF.b&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Aliases:&lt;/strong&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.trendmicro.com/vinfo/emea/virusencyclo/default5.asp?VName=EXPL_PIDIEF.O" target="_blank"&gt;EXPL_PIDIEF.O&lt;/a&gt; (TrendMicro)&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2008-020915-1008-99" target="_blank"&gt;Trojan.Pidief.C&lt;/a&gt; (Symantec)&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;If you do not have Adobe Reader version 9 installed, then you can download it from the &lt;a href="http://www.adobe.com/products/acrobat/readstep2.html?promoid=BUIGO" target="_blank"&gt;Adobe Download&lt;/a&gt;. Unfortunately it comes with Adobe AIR, which you can uninstall through Windows &amp;quot;Add/Remove Programs&amp;quot;. Also, during the installation process you might want to uncheck the option to install the Google toolbar.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1643892" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/McAfee+Security/default.aspx">McAfee Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Mass Hack Attack</title><link>http://msmvps.com/blogs/jubo/archive/2008/03/14/1542633.aspx</link><pubDate>Fri, 14 Mar 2008 07:31:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1542633</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=1542633</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2008/03/14/1542633.aspx#comments</comments><description>&lt;p&gt;Really cool video at the McAfee&amp;#39;s Avert Labs blog site about the latest mass hack attack at phpBB web sites. See how it looks like from an end user&amp;#39;s perspective: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/03/13/follow-up-to-yesterdays-mass-hack-attack/" target="_blank"&gt;Mass Hack Attack&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Source: &lt;a href="http://www.avertlabs.com/research/blog/" target="_blank"&gt;McAfee Avert Labs Blog&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1542633" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/McAfee+Security/default.aspx">McAfee Security</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category><category domain="http://msmvps.com/blogs/jubo/archive/tags/News/default.aspx">News</category></item><item><title>Email with subject: "Israel Just Have Started World War III"</title><link>http://msmvps.com/blogs/jubo/archive/2007/04/10/778340.aspx</link><pubDate>Tue, 10 Apr 2007 09:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:778340</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=778340</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/04/10/778340.aspx#comments</comments><description>&lt;p&gt;Late last night I found a strange email in my email Inbox; from a person I didn&amp;#39;t know. It even had an attachment called: &amp;quot;News.exe&amp;quot;. I could even save it to my hard drive without any antivirus program jumping up. Decided to submit it to McAfee&amp;#39;s &lt;a target="_blank" href="https://www.webimmune.net/default.asp"&gt;Avert Labs&lt;/a&gt;&amp;nbsp;and a few minutes later I received the following results:&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://msmvps.com/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/jubo.images/Nuwar_5F00_McScan.jpg"&gt;&lt;img height="240" width="320" src="http://msmvps.com/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/jubo.images/Nuwar_5F00_McScan.jpg" align="left" alt="Avert Labs" hspace="5" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(Click the Image for a larger view)&lt;/p&gt;
&lt;p&gt;It shows you that DAT version 5004 didn&amp;#39;t detect this &amp;quot;&lt;a target="_blank" href="http://vil.nai.com/vil/content/v_140835.htm"&gt;Nuwar&lt;/a&gt;&amp;quot; virus, but they already had an &amp;quot;Extra.dat&amp;quot; available, which detect this virus. Hopefully this &amp;quot;Extra.dat&amp;quot; is included in today&amp;#39;s DAT update.&lt;/p&gt;
&lt;p&gt;Then I also submitted the &amp;quot;News.exe&amp;quot; file to &lt;a target="_blank" href="http://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt;&amp;nbsp;to see if any of the other antivirus vendors would find the virus. See this screen shot for their results:&lt;/p&gt;
&lt;p&gt;&lt;a target="_blank" href="http://msmvps.com/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/jubo.images/Nuwar_5F00_VirusTotal.jpg"&gt;&lt;img height="240" width="320" src="http://msmvps.com/cfs-filesystemfile.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/jubo.images/Nuwar_5F00_VirusTotal.jpg" align="left" alt="Avert Labs" hspace="5" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(Click the image for a larger view)&lt;/p&gt;
&lt;p&gt;Even though many of the antivirus vendors found the virus some of the bigger comapnies, like Sophos, Microsoft, McAfee and Panda didn&amp;#39;t find the virus.&lt;/p&gt;
&lt;p&gt;If you get an email from an unknown person with a subject like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Missle Strike: The USA kills more then 1000 Iranian citizens&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Missle Strike: The USA kills more then 10000 Iranian citizens&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Missle Strike: The USA kills more then 20000 Iranian citizens&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;USA Missle Strike: Iran War just have started&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Israel Just Have Started World War III&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;USA Just Have Started World War III&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Iran Just Have Started World War III&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;USA Declares War on Iran&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;and it has an attachment like:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;More.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Read More.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Click Here.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Click Me.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Read Me.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Movie.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;News.exe&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Video.exe&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;then delete the email immediately and make sure you have an up-to-date antivirus signature files.&lt;/p&gt;
&lt;p&gt;And since this is &amp;quot;patch tuesday&amp;quot; also make sure your version of Windows is patched and has all the updates. If you don&amp;#39;t have the automatic updates enabled then check it at &lt;a target="_blank" href="http://update.microsoft.com"&gt;Microsoft Update&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information about this virus see McAfee&amp;#39;s writeup: &lt;a target="_blank" href="http://vil.nai.com/vil/content/v_140835.htm"&gt;W32/Nuwar&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=778340" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>McAfee added detection for fake IE7</title><link>http://msmvps.com/blogs/jubo/archive/2007/03/31/733432.aspx</link><pubDate>Sat, 31 Mar 2007 06:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:733432</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=733432</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/03/31/733432.aspx#comments</comments><description>&lt;P&gt;McAfee has added detection for the fake IE7 email. See their writeup: &lt;A class="" href="http://vil.nai.com/vil/content/v_141786.htm" target=_blank&gt;W32/Grum&lt;/A&gt;. You need at least DAT version 4996. So check if your version of McAfee is up-to-date. &lt;/P&gt;
&lt;P&gt;For Symantec see: &lt;A class="" href="http://www.symantec.com/home_homeoffice/security_response/writeup.jsp?docid=2007-033016-1857-99" target=_blank&gt;W32.Grum.A&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=733432" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Beware of fake IE7 Beta email</title><link>http://msmvps.com/blogs/jubo/archive/2007/03/30/729852.aspx</link><pubDate>Fri, 30 Mar 2007 12:35:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:729852</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=729852</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/03/30/729852.aspx#comments</comments><description>&lt;P&gt;There's a email out there, which says that it is coming from&amp;nbsp;admin@microsoft&amp;nbsp;with an attachment called: "IE7.0.exe". The subject of this email is: "Internet Explorer 7 Downloads" and it shows you an image of an IE7 Beta 2 download. Do NOT click on this image! If you do you are offered to download a trojan. &lt;/P&gt;
&lt;P&gt;Two reasons why you should know this email is fake:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Microsoft&amp;nbsp;NEVER sends out updates or downloads&amp;nbsp;by email.&lt;/LI&gt;
&lt;LI&gt;IE7 has been released and there's no Beta program&amp;nbsp;anymore.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;A screenshot of the email can be found at the &lt;A class="" href="http://sunbeltblog.blogspot.com/2007/03/beware-fake-ie-7-downloads.html" target=_blank&gt;Sunbelt Blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A class="" href="http://www.f-secure.com/weblog/#00001155" target=_blank&gt;F-Secure&lt;/A&gt; detects the file as: &lt;A class="" href="http://www.f-secure.com/v-descs/trojan-proxy_w32_grum_a.shtml" target=_blank&gt;Virus.Win32.Grum.A&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=729852" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>BootMerlin virus </title><link>http://msmvps.com/blogs/jubo/archive/2007/02/22/610358.aspx</link><pubDate>Thu, 22 Feb 2007 21:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:610358</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=610358</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/02/22/610358.aspx#comments</comments><description>&lt;P&gt;This is a virus written in MS VisualBasic that modifies the C:\Boot.ini file to display a Spanish message at boot time:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG title=BootMerlin style="WIDTH:474px;HEIGHT:232px;" height=232 alt=BootMerlin src="http://vil.nai.com/images/141514-1.gif" width=474&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Upon execution, it can also be displaying a Wizard animation "speaking" in the Spanish language:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;IMG style="WIDTH:278px;HEIGHT:257px;" height=257 src="http://vil.nai.com/images/141514-2.gif" width=278&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;W32/BootMerlin can make copies of itself bearing the MS Word icon, in the following location(s):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;%Windir%\System\csrss.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;%Windir%\System32\dllcache\G-Vulcan-III.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\Recuerda que te quiero.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\LINEAS TELEFONICAS SIJIN VIEJA.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\PODER SALDARRIAGA1.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\SOLICITUD A MI GENERAL.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\SEGURO BTA EQUIPOS.exe &lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;X:\CURSO CONSTITUCIONAL.copia.exe&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;(Where X: are the drive letter(s) used on the infected machine; %Windir% is the Windows folder, e.g. C:\Windows. A legitimate copy of csrss.exe may reside in %Windir%\System32 which is a part of the Windows operating system)&lt;/P&gt;
&lt;P&gt;It installs the following registry key(s) to start at Windows boot up:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ "WinSound" = "%Windir%\System\csrss.exe"&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The C:\Boot.ini should be restored manually to the original settings (see removal section).&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Method of infection:&lt;/STRONG&gt; W32/BootMerlin is a worm that can make copies of itself over mounted network drives. It may infected other systems using the same network drives.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Removal: &lt;/STRONG&gt;This virus can C:\boot.ini to display anti-MS Windows messages in Spanish. These messages can be removed using a text editor, for example:&lt;/P&gt;
&lt;P&gt;multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="AUN Usas Windows..?"/fastdetect&lt;/P&gt;
&lt;P&gt;edit it to become:&lt;/P&gt;
&lt;P&gt;multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="{your original operating system name}" /fastdetect {your original boot up options where applicable}&lt;/P&gt;
&lt;P&gt;Do not modify any other parts of the C:\boot.ini file. Also check under My Computer-&amp;gt;Properties-&amp;gt;Advanced-&amp;gt;Startup and Recovery Settings that It is pointing to the default operating system that was originally configured for.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Source: &lt;A class="" href="http://vil.nai.com/vil/content/v_141514.htm" target=_blank&gt;McAfee Virus Library&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=610358" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Be aware for Valentine Day's e-greetings emails!</title><link>http://msmvps.com/blogs/jubo/archive/2007/02/10/562904.aspx</link><pubDate>Sat, 10 Feb 2007 17:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:562904</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=562904</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2007/02/10/562904.aspx#comments</comments><description>&lt;P&gt;If you receive emails with&amp;nbsp;variable subjects such as: "&lt;EM&gt;Together You and I&lt;/EM&gt;, &lt;EM&gt;Everyone Needs Someone&lt;/EM&gt; or &lt;EM&gt;Cyber Love&lt;/EM&gt;, then delete them immediately. They're ususally sent by a female using different names. The attached file that contains the worm is an executable file with names such as &lt;EM&gt;flash postcard.exe&lt;/EM&gt; or &lt;EM&gt;greeting postcard.exe&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;According to &lt;A class="" href="http://www.pandasoftware.com/about_panda/press_room/ORANGE_ALERT_Nurech.A_worm_spreads_rapidly.htm" target=_blank&gt;Pandalabs&lt;/A&gt;, this virus is spreading rapidly and they have named it: &lt;A class="" href="http://www.pandasoftware.com/com/virus_info/encyclopedia/overview.aspx?idvirus=149000&amp;amp;sitepanda=particulares" target=_blank&gt;Nurech.A&lt;/A&gt;. Other malicious codes currently infecting users include &lt;A class="" href="http://www.pandasoftware.com/com/virus_info/encyclopedia/overview.aspx?IdVirus=147717&amp;amp;sind=0&amp;amp;sitepanda=particulares" target=_blank&gt;Nuwar.D&lt;/A&gt;. This worm arrives in messages with subjects like “&lt;EM&gt;5 reasons I love you&lt;/EM&gt;” or “&lt;EM&gt;A kiss for you&lt;/EM&gt;”.&lt;/P&gt;
&lt;P&gt;See for more information: &lt;A class="" href="http://www.pandasoftware.com/about/press/viewNews.htm?noticia=8234&amp;amp;entorno=&amp;amp;ver=&amp;amp;pagina=&amp;amp;producto=&amp;amp;sitepanda=particulares" target=_blank&gt;ORANGE VIRUS ALERT The Nurech.A worm spreads rapidly, infecting hundreds of computers&lt;/A&gt;&amp;nbsp;and &lt;A class="" href="http://www.pandasoftware.com/about/press/viewNews.aspx?noticia=8245&amp;amp;sitepanda=particulares" target=_blank&gt;Valentine’s Day: a powerful lure for spreading malware&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Symantec calls it: &lt;A class="" href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-011917-1403-99" target=_blank&gt;Trojan.Peacomm&lt;/A&gt;, aka "Storm Trojan". &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I just stick with &lt;A class="" href="http://www.americangreetings.com/" target=_blank&gt;AmericanGreetings&lt;/A&gt;... &lt;img src="http://msmvps.com/emoticons/emotion-5.gif" alt="Wink" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=562904" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Critical 0-Day Internet Explorer Exploit Discovered In The Wild</title><link>http://msmvps.com/blogs/jubo/archive/2006/09/20/134128.aspx</link><pubDate>Wed, 20 Sep 2006 10:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:134128</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=134128</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2006/09/20/134128.aspx#comments</comments><description>&lt;p&gt;A lot of web sites are already talking about it. There&amp;#39;s a critical 0-day exploit discovered in the wild for Internet Explorer. According to the Microsoft &lt;a href="http://www.microsoft.com/technet" target="_blank"&gt;TechNet&lt;/a&gt;&amp;nbsp;web site, it&amp;#39;s a vulnerability in the Microsoft Windows implementation of Vector Markup Language (VML).&lt;/p&gt;&lt;p&gt;Microsoft is aware of the issue and will&amp;nbsp;have a security update to address this vulnerability ready on Tuesday, October 10, 2006 or sooner depending on customers needs. &lt;/p&gt;&lt;p&gt;More information at:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/925568.mspx" target="_blank"&gt;Microsoft Security Advisory (925568)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2006/09/19/457560.aspx" target="_blank"&gt;Microsoft Security Response Center Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html" target="_blank"&gt;Sunbelt Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.avertlabs.com/research/blog/?p=90" target="_blank"&gt;McAfee Avert Labs Blog&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;For &lt;a href="http://www.windowsonecare.com/" target="_blank"&gt;Windows Live OneCare&lt;/a&gt; users, if your current status is green then you&amp;#39;re already protected from malware that uses this vulnerability. All other users, please&amp;nbsp;keep your antivirus software up to date.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=134128" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Microsoft word document spam</title><link>http://msmvps.com/blogs/jubo/archive/2006/09/05/Microsoft-word-document-spam.aspx</link><pubDate>Tue, 05 Sep 2006 19:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:114829</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=114829</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2006/09/05/Microsoft-word-document-spam.aspx#comments</comments><description>&lt;p&gt;McAfee Avert Labs has recently seen spammers start to use Microsoft Word documents and HTML attachments to deliver their advertising payload. By moving the advertising content, most importantly the URL link, into an attached document rather than the body of the email message, spammers are able to evade some of the Anti-Spam vendors&amp;rsquo; content filtering techniques. This is because most vendors don&amp;rsquo;t scan content inside attachments because this has previously not been necessary. &lt;/p&gt;&lt;p&gt;Microsoft Word is a convenient format because it supports clickable links and most recipients will have Word installed or would be able to open the document with another compatible word processor. &lt;/p&gt;&lt;p&gt;The spammer is varying the attachment file name, email body text and subject in nearly every batch of the messages sent, for example: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Subject: Billing Update, Bill #90023&lt;br /&gt;Forward original invoice with attached invoice transmittal sheet to the contracting officer.&lt;br /&gt;DATED MATERIAL,INVOICE ATTACHED &lt;br /&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Subject: Your receipt for Invoice #25826&lt;br /&gt;Credit memo attached to deleted payment receipt cannot be applied to different invoice.&lt;br /&gt;Software order has a Related invoice attached with prepayment information. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;And other subjects. The conclusion, according to Avert Labs, is that to keep up with this, Anti-Spam vendors may need to add attachment scanning to their solutions, which would require additional processing power on customers email servers. In addition, the attachments mean spam is getting bigger. The messages in the current campaign are only 35k in size, but Word documents are well known for growing very quickly in size. A rise in document spam would mean recipients&amp;rsquo; mailboxes and servers clog up faster, worsening the burden that spam puts on us all. &lt;/p&gt;&lt;p&gt;For more information and screen shots about this, check the &lt;a href="https://www.avertlabs.com/research/blog/wp-trackback.php?p=80" target="_blank"&gt;Avert Labs blog&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=114829" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Santa IM Worm Installs Rootkit Payload</title><link>http://msmvps.com/blogs/jubo/archive/2005/12/22/79623.aspx</link><pubDate>Thu, 22 Dec 2005 10:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79623</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=79623</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2005/12/22/79623.aspx#comments</comments><description>
&lt;div&gt;

A new Christmas-themed worm attack is underway, delivering an offensive rootkit payload over the AOL, MSN, Windows Messenger, ICQ and Yahoo instant messaging networks.&lt;br&gt;
&lt;br&gt;
The worm, identified as IM.GiftCom.All, was discovered by researchers at IMLogic Inc.'s Threat Center spreading via IM and attempting to trick users into clicking on a malicious URL.&lt;br&gt;
&lt;br&gt;
The link lures the target into visiting a harmless Santa Claus Web site, but actually installs a rootkit payload to the victim's machine, IMLogic said in an advisory.&lt;br&gt;
&lt;br&gt;
"The rootkit payload is often named gift.com and when executed hides itself on the user's system, attempts to shutdown desktop anti-virus software and starts collecting the infected user's information for broadcast over the Internet," the company explained.&lt;br&gt;
&lt;br&gt;
Source and full article: &lt;a href="http://www.eweek.com/article2/0,1759,1904112,00.asp?kc=EWRSS03129TX1K0000614" target="_blank"&gt;eWeek.com&lt;/a&gt;&lt;br&gt;
See also: &lt;a href="http://forums.mcafeehelp.com/viewtopic.php?t=65385"&gt;
Messenging users, keep away from "Santa Claus"&lt;/a&gt;&lt;br&gt;
&lt;br&gt;

&lt;/div&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79623" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>Latest Virus Threat: Zafi.D</title><link>http://msmvps.com/blogs/jubo/archive/2004/12/16/25867.aspx</link><pubDate>Thu, 16 Dec 2004 11:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:25867</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=25867</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2004/12/16/25867.aspx#comments</comments><description>&lt;DIV&gt;
&lt;DIV&gt;Zafi.D&lt;/DIV&gt;&lt;BR&gt;&lt;STRONG&gt;Aliases:&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;Email-Worm.Win32.Zafi.d 
&lt;LI&gt;Nocard.A@mm 
&lt;LI&gt;W32.Erkez.D@mm 
&lt;LI&gt;W32/Zafi-D 
&lt;LI&gt;W32/Zafi.D.worm 
&lt;LI&gt;W32/Zafi.d@MM 
&lt;LI&gt;Win32.Zafi.D 
&lt;LI&gt;Win32.Zafi.D!ZIP 
&lt;LI&gt;Win32/Zafi.D.Worm 
&lt;LI&gt;WORM_ZAFI.D 
&lt;LI&gt;Zafi.D &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;F-SECURE&lt;/STRONG&gt;&lt;BR&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.f-secure.com/v-descs/zafi_d.shtml" target=_blank&gt;Zafi.D&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;A new variant of Zafi worm - Zafi.D is spreading. While the original Zafi.A uses only Hungarian, the new Zafi.D spreads in email in English, Italian, Spanish, Russian, Swedish and several other languages. &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;NETWORK ASSOCIATES&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://vil.nai.com/vil/content/v_130371.htm" target=_blank&gt;W32/Zafi.d@MM&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;The risk assessment of this threat was raised to Medium due to increased prevalence. The 4414 DATs were released early for this threat. &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;SOPHOS&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.sophos.com/virusinfo/analyses/w32zafid.html" target=_blank&gt;W32/Zafi-D&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;COMPUTER ASSOCIATES&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www3.ca.com/threatinfo/virusinfo/virus.aspx?id=41012" target=_blank&gt;Win32.Zafi.D&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;Win32.Zafi.D is a worm that spreads via e-mail and peer-to-peer file sharing. It has been distributed as a 11,745-byte, FSG-packed Windows executable, which may be inside a ZIP archive. When run, Zafi.D displays a simulated error message &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;PANDA ANTIVIRUS&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?IdVirus=56161&amp;amp;sind=0" target=_blank&gt;Zafi.D&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;It opens the port 8181, waits for a file to be transferred through it, and executes this file. &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;SYMANTEC&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.sarc.com/avcenter/venc/data/w32.erkez.d@mm.html" target=_blank&gt;W32.Erkez.D@mm&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;W32.Erkez.D@mm is a mass-mailing worm that sends itself to email addresses gathered from the infected computer. The worm may also attempt to lower security settings, terminate processes, and open a back door on the compromised computer. &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;&lt;STRONG&gt;TREND MICRO&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_ZAFI.D" target=_blank&gt;WORM_ZAFI.D&lt;/A&gt; 
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;BR&gt;As of December 14, 2004 8:13 AM (PST), TrendLabs has declared a MEDIUM risk virus alert to control the spread of this mass-mailing worm. It has been found spreading in Germany, France, and Spain. &lt;/LI&gt;&lt;/UL&gt;&lt;BR&gt;Source: &lt;A href="http://secunia.com/virus_information/13871/zafi.d/" target=_blank&gt;Secunia&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=25867" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>MyDoom seeks to destroy antivirus firms</title><link>http://msmvps.com/blogs/jubo/archive/2004/10/19/16109.aspx</link><pubDate>Tue, 19 Oct 2004 11:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:16109</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=16109</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2004/10/19/16109.aspx#comments</comments><description>
&lt;DIV&gt;&lt;BR&gt;
&lt;DIV&gt;Antivirus companies are perplexed by a spate of recent viruses that contain messages in which the writers threaten to attack them.&lt;/DIV&gt;&lt;BR&gt;Worm writers are threatening to attack antivirus companies F-Secure, Symantec, Trend Micro and McAfee. &lt;BR&gt;In the latest version of MyDoom--MyDoom.AE--the authors embedded a message ridiculing rival worm Netsky and promising to attack the antivirus companies. &lt;BR&gt;&lt;BR&gt;The message has left antivirus companies unsure of what to expect. &lt;BR&gt;&lt;BR&gt;"It remains to be seen what they mean by threatening to attack us," said Mikko Hypponen, director of antivirus research for F-Secure. "That might mean a denial-of-service attack. We've been a target before, but they haven't tried any recently."&lt;BR&gt;&lt;BR&gt;Full article: &lt;A href="http://news.zdnet.com/2100-1009_22-5415086.html?tag=default" target=_blank&gt;ZDNet &lt;/A&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=16109" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>W32/Zafi.b@MM</title><link>http://msmvps.com/blogs/jubo/archive/2004/06/12/8045.aspx</link><pubDate>Sat, 12 Jun 2004 13:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:8045</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=8045</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2004/06/12/8045.aspx#comments</comments><description>&lt;DIV&gt;&lt;BR&gt;&lt;A href="http://vil.nai.com/vil/content/v_126242.htm" target=_blank&gt;W32/Zafi.b@MM&lt;/A&gt; (McAfee/NAI)&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Virus Characteristics:&lt;/STRONG&gt; &lt;BR&gt;This is a mass-mailing worm that constructs messages using its own SMTP engine, spoofing the From: address. It also attempts to propagate via P2P, via copying itself to folders on the local system (containing "share" or "upload" in the folder name). &lt;BR&gt;While the original Zafi.A uses only Hungarian, the new Zafi.B spreads in email in English, Italian, Spanish, Russian, Swedish etc. &lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Installation &lt;/STRONG&gt;&lt;BR&gt;When executed, the worm copies itself twice to the %windir%\system32 folder using a random name and .EXE and .DLL extension.&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt; 
&lt;UL&gt;
&lt;LI&gt;C:\WINNT\system32\jrbtgmqi.exe 
&lt;LI&gt;C:\WINNT\system32\enfrbatm.dll &lt;/LI&gt;&lt;/UL&gt;For McAfee the minimum DAT file: 4366, which will be released on: 06/16/2004. However, detection and removal is included in their DAILY DAT (beta) files, which can be downloaded from their &lt;A href="http://vil.nai.com/vil/virus-4d.asp" target=_blank&gt;DAT File Updates&lt;/A&gt; website.&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Other links:&lt;/STRONG&gt; &lt;BR&gt;&lt;STRONG&gt;CA:&lt;/STRONG&gt; &lt;A href="http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39333" target=_blank&gt;Win32.Zafi.B&lt;/A&gt;&lt;BR&gt;&lt;STRONG&gt;Sophos:&lt;/STRONG&gt; &lt;A href="http://www.sophos.com/virusinfo/analyses/w32zafib.html" target=_blank&gt;W32/Zafi-B&lt;/A&gt;&lt;BR&gt;&lt;STRONG&gt;F-Secure:&lt;/STRONG&gt; &lt;A href="http://www.f-secure.com/v-descs/zafi_b.shtml" target=_blank&gt;Zafi.B&lt;/A&gt;&lt;BR&gt;&lt;STRONG&gt;Symantec:&lt;/STRONG&gt; &lt;A href="http://www.sarc.com/avcenter/venc/data/w32.erkez.b@mm.html" target=_blank&gt;W32.Erkez.B@mm&lt;/A&gt;&lt;BR&gt;&lt;STRONG&gt;TrendMicro:&lt;/STRONG&gt; &lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_ZAFI.B" target=_blank&gt;PE_ZAFI.B&lt;/A&gt;&lt;BR&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=8045" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item><item><title>The Korgo Family</title><link>http://msmvps.com/blogs/jubo/archive/2004/05/31/7397.aspx</link><pubDate>Mon, 31 May 2004 15:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:7397</guid><dc:creator>jubo</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/jubo/rsscomments.aspx?PostID=7397</wfw:commentRss><comments>http://msmvps.com/blogs/jubo/archive/2004/05/31/7397.aspx#comments</comments><description>&lt;DIV&gt;&lt;BR&gt;&lt;STRONG&gt;W32.Korgo&lt;/STRONG&gt; is a worm that spreads via the Internet by exploiting the LSASS vulnerability, as described in &lt;A href="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx" target=_blank&gt;Microsoft Security Bulletin MS04-011&lt;/A&gt;, in remote computers. This vulnerability is critical for Windows XP/2000 operating systems that are not properly updated.&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;W32.Korgo&lt;/STRONG&gt; listens to the TCP ports 113, 3067 and 2041 and connects to several IRC servers through the port 6667.&lt;BR&gt;&lt;BR&gt;
&lt;DIV align=center&gt;The Korgo Family&lt;/DIV&gt;
&lt;TABLE cellSpacing=2 cellPadding=2 align=center&gt;

&lt;TR&gt;
&lt;TD align=left&gt;McAfee&lt;/TD&gt;
&lt;TD align=left&gt;Panda&lt;/TD&gt;
&lt;TD align=left&gt;Symantec&lt;/TD&gt;
&lt;TD align=left&gt;TrendMicro&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=47791" target=_blank&gt;Korgo.A&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.sarc.com/avcenter/venc/data/w32.korgo.a.html" target=_blank&gt;W32.Korgo.A&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KORGO.A" target=_blank&gt;WORM_KORGO.A&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;A href="http://vil.nai.com/vil/content/v_125933.htm" target=_blank&gt;W32/Korgo.worm.b&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=47792" target=_blank&gt;Korgo.B&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.b.html" target=_blank&gt;W32.Korgo.B&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KORGO.B" target=_blank&gt;WORM_KORGO.B&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=47827" target=_blank&gt;Korgo.C&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.c.html" target=_blank&gt;W32.Korgo.C&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KORGO.C" target=_blank&gt;WORM_KORGO.C&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.symantec.com/avcenter/venc/data/w32.korgo.d.html" target=_blank&gt;W32.Korgo.D&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.e.html" target=_blank&gt;W32.Korgo.E&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.f.html" target=_blank&gt;W32.Korgo.F&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;A href="http://vil.nai.com/vil/content/v_125994.htm" target=_blank&gt;W32/Korgo.worm.f&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.sarc.com/avcenter/venc/data/w32.korgo.f.html" target=_blank&gt;W32.Korgo.F&lt;/A&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_KORGO.F" target=_blank&gt;WORM_KORGO.F &lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;BR&gt;&lt;/DIV&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=7397" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jubo/archive/tags/Latest+Virus+Threats/default.aspx">Latest Virus Threats</category></item></channel></rss>