<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Manifest : Viruses (Very Urgent)</title><link>http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Very+Urgent_2900_/default.aspx</link><description>Tags: Viruses (Very Urgent)</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>OUTBREAK: Zotob.E (IRCBot) worm hitting unpatched systems</title><link>http://msmvps.com/blogs/trafton/archive/2005/08/16/62937.aspx</link><pubDate>Tue, 16 Aug 2005 22:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:62937</guid><dc:creator>trafton</dc:creator><slash:comments>0</slash:comments><description>&lt;P&gt;A new worm utilizing the MS05-039 vulnerability has became a major outbreak.  More coverage upcoming.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Details&lt;BR&gt;&lt;/STRONG&gt;IRCBot is a fast-spreading worm affecting systems not patched for the MS05-039 vulnerability.  Infected machines will reboot frequently, as well as connect to an IRC server and await further instructions&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Protection&lt;BR&gt;&lt;/STRONG&gt;Detection of this worm, as it is an outbreak, should be released very soon, if it is not already out.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Gist&lt;BR&gt;&lt;/STRONG&gt;IRCBot is an urgent outbreak and all systems should be patched that have not already been.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Links&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://vil.mcafeesecurity.com/vil/content/v_135491.htm"&gt;McAfee&lt;/A&gt; - Write-up.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=62937" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/VIRUSES/default.aspx">VIRUSES</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/SECURITY/default.aspx">SECURITY</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Security+_2800_Medium_2900_/default.aspx">Security (Medium)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Security+_2800_Urgent_2900_/default.aspx">Security (Urgent)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Medium_2900_/default.aspx">Viruses (Medium)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Urgent_2900_/default.aspx">Viruses (Urgent)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Security+_2800_Very+Urgent_2900_/default.aspx">Security (Very Urgent)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Very+Urgent_2900_/default.aspx">Viruses (Very Urgent)</category></item><item><title>Outbreak Alert for New MyDoom Variant</title><link>http://msmvps.com/blogs/trafton/archive/2004/07/26/10684.aspx</link><pubDate>Tue, 27 Jul 2004 00:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:10684</guid><dc:creator>trafton</dc:creator><slash:comments>8</slash:comments><description>&lt;H3&gt;&lt;FONT color=#ff0000&gt;BREAKING NEWS:&lt;/FONT&gt; Mydoom Variant Medium-High Risk&lt;/H3&gt;
&lt;P&gt;At 9:25 AM Pacific Time, security company Secunia released a Medium risk alert for the latest variant of the Mydoom family, which is known by various names, including MyDoom.L, MyDoom.M, MyDoom.N, MyDoom.O, and MyDoom.R. The following are various vendor's aliases for this worm:&lt;BR&gt;&lt;BR&gt;Computer Associates: Win32.Mydoom.O&lt;BR&gt;F-Secure: Mydoom.M&lt;BR&gt;Network Associates: W32/Mydoom.o@MM&lt;BR&gt;Panda Software: Mydoom.N&lt;BR&gt;Sophos: W32/MyDoom-O&lt;BR&gt;Symantec: W32.Mydoom.M@mm&lt;BR&gt;Trend Micro: WORM_MYDOOM.M&lt;BR&gt;&lt;BR&gt;Contrary to the Secunia bulletin, Panada Software's Mydoom.M is an unrelated worm.&lt;BR&gt;&lt;BR&gt;The following are vendor risks:&lt;BR&gt;&lt;BR&gt;Computer Associates: High (4/5)&lt;BR&gt;F-Secure: Medium (2/3)&lt;BR&gt;Network Associates: Medium-On-Watch (2.5/3.5)&lt;BR&gt;Panda Software: High (3/4)&lt;BR&gt;Sophos: Unassigned&lt;BR&gt;Symantec: High (4/5)&lt;BR&gt;Trend Micro: Medium (2/3)&lt;BR&gt;OVERALL: Medium-High (7.3/10)&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Worldwide Spread&lt;BR&gt;&lt;/STRONG&gt;Trend Micro reports significant spread from Germany, Singapore, and the United States, indicating that it is likely this worm has already became common in all continents.&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Recognition&lt;BR&gt;&lt;/STRONG&gt;Email messages appear similar to the following, although may be variable:&lt;BR&gt;&lt;IMG src="http://vil.nai.com/images/127033-a.gif" border=0&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;More Information&lt;BR&gt;&lt;/STRONG&gt;&lt;A href="http://forums.mcafeehelp.com/viewtopic.php?t=29566"&gt;McAfeeHelp Forums (thanks to CD)&lt;/A&gt;&lt;BR&gt;&lt;A href="http://vil.nai.com/vil/content/v_127033.htm"&gt;NAI Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.sarc.com/avcenter/venc/data/w32.mydoom.m@mm.html"&gt;Symantec Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MYDOOM.M"&gt;Trend Micro Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?IdVirus=50107&amp;amp;sind=0"&gt;Panda Software Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.f-secure.com/v-descs/mydoom_m.shtml"&gt;F-Secure Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www3.ca.com/threatinfo/virusinfo/virus.aspx?id=39711"&gt;Computer Associates Description&lt;/A&gt;&lt;BR&gt;&lt;A href="http://www.sophos.com/virusinfo/analyses/w32mydoomo.html"&gt;Sophos Description&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=10684" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/VIRUSES/default.aspx">VIRUSES</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Medium_2900_/default.aspx">Viruses (Medium)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Urgent_2900_/default.aspx">Viruses (Urgent)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Very+Urgent_2900_/default.aspx">Viruses (Very Urgent)</category></item><item><title>Symantec Goes High on Sasser.B</title><link>http://msmvps.com/blogs/trafton/archive/2004/05/02/5797.aspx</link><pubDate>Sun, 02 May 2004 16:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:5797</guid><dc:creator>trafton</dc:creator><slash:comments>21</slash:comments><description>&lt;h3&gt;&lt;font color="#ff0000"&gt;BREAKING NEWS: &lt;/font&gt;Symantec Upgrades Sasser.B to HIGH (4)&lt;/h3&gt;
&lt;p&gt;Symantec has just upgraded Sasser.B to a HIGH risk (4). This is due to increased spread. The worm, which appeared yesterday, has now achieved higher spread than the original, according to Symantec.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sarc.com/avcenter/venc/data/w32.sasser.b.worm.html"&gt;http://www.sarc.com/avcenter/venc/data/w32.sasser.b.worm.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=5797" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/trafton/archive/tags/VIRUSES/default.aspx">VIRUSES</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/SECURITY/default.aspx">SECURITY</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/FOLLOW-UPS/default.aspx">FOLLOW-UPS</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Medium_2900_/default.aspx">Viruses (Medium)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Urgent_2900_/default.aspx">Viruses (Urgent)</category><category domain="http://msmvps.com/blogs/trafton/archive/tags/Viruses+_2800_Very+Urgent_2900_/default.aspx">Viruses (Very Urgent)</category></item></channel></rss>