Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 01-31-2006, 07:55 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Win32/Mywife.E@mm

I recieved this in an email from Microsoft Technet:

Microsoft wants to make customers aware of the Mywife mass mailing malware variant named Win32/Mywife.E@mm. The mass mailing malware tries to entice users through social engineering efforts into opening an attached file in an e-mail message. If the recipient opens the file, the malware sends itself to all the contacts that are contained in the system’s address book. The malware may also spread over writeable network shares on systems that have blank administrator passwords.

Customers who are using the most recent and updated antivirus software could be at a reduced risk of infection from the Win32/Mywife.E@mm malware. Customers should verify this with their antivirus vendor. Antivirus vendors have assigned different names to this malware but the Common Malware Enumeration (CME) group has assigned it ID CME-24.

On systems that are infected by Win32/Mywife@E.mm, the malware is intended to permanently corrupt a number of common document format files on the third day of every month. February 3, 2006 is the first time this malware is expected to permanently corrupt the content of specific document format files. The malware also modifies or deletes files and registry keys associated with certain computer security-related applications. This prevents these applications from running when Windows starts. For more information, see the Microsoft Virus Encyclopedia.

As with all currently known variants of the Mywife malware, this variant does not make use of a security vulnerability, but is dependant on the user opening an infected file attachment. The malware also attempts to scan the network looking for systems it can connect to and infect It does this in the context of the user. If it fails to connect to one of these systems, it tries again by logging on with "Administrator" as the user name together with a blank password.

Customers who believe that they are infected with the Mywife malware, or who are not sure whether they are infected, should contact their antivirus vendor. Alternatively, Windows Live Safety Center Beta Web site provides the ability to choose “Protection Scan” to ensure that systems are free of infection. Additionally, the Windows OneCare Live Beta, which is available for English language systems, provides detection for and protection against the Mywife malware and its known variants.

For more information about the Mywife malware, to help determine whether you have been infected by the malware, and for instructions on how to repair your system if you have been infected, see the Microsoft Virus Encyclopedia. For Microsoft Virus Encyclopedia references, see the “Overview” section. We continue to encourage customers to use caution with unknown file attachments and to follow our Protect Your PC guidance of enabling a firewall, getting software updates, and installing antivirus software. Customers can learn more about these steps by visiting the Protect Your PC Web site.
Reply With Quote
Posted


  #2  
Old 01-31-2006, 10:32 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
This is the same as the Blackworm/Karma Sutra that I posted the other day.Same bug,different name.

http://www.cyberanswers.org/forum/sh...ad-t_2274.html
__________________
An Australian Member of
Eddy
===============================
Reply With Quote
  #3  
Old 01-31-2006, 10:35 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
And I wish that the Software companies could unite somehow in cataloging these things. This type of stuff happens all the time.
Reply With Quote
  #4  
Old 02-01-2006, 07:51 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
Microsoft Won't Issue Advance Kama Sutra Fix

Microsoft Won't Issue Advance Kama Sutra Fix

Infected PCs will be in danger on Friday. Microsoft said its next scheduled set of fixes--on Feb. 14--will detect and remove the worm.

By Gregg Keizer
TechWeb News

Jan 31, 2006 12:37 PM

Microsoft Monday posted a security advisory on the Kama Sutra/Blackworm/MyWife worm that's set to overwrite Office documents on infected PCs Friday, but the company has decided against updating its Windows Malicious Software Removal Tool before the next regularly-scheduled release of Feb. 14.
The security advisory -- a mechanism Microsoft uses to both alert users of impending threats and give them advice or workarounds to apply -- repeats recommendations that most security vendors have been offering since the worm debuted two weeks ago.
It also notes that infected PCs will be in danger on Friday, Feb. 3, when the worm will overwrite several popular file formats, including those of Microsoft Office, with useless data.
But according to the team in charge of Microsoft's Windows Software Removal Tool, that program won't be updated until after the Friday deadline passes.
"Microsoft releases a new version of the Windows Malicious Software Removal Tool every month on the second Tuesday of the month together with the other security updates," wrote developers on the group's blog. "The next version, targeted for release on February 14th, will detect and remove this worm."
The blog offered no explanation why the tool wouldn't be updated earlier, nor did Microsoft immediately respond to questions. Each month, Microsoft pushes a revised tool to Windows users who have Automatic Update enabled for Windows Update or Microsoft Update.
The Redmond, Wash.-based company has released the Malicious Software Removal Tool off-schedule once before, in August 2005, shortly after the Zotob worm began striking Windows 2000 systems. Both the company's free online security service, Windows Live Safety, and its in-beta OneCare Live software, however, will disinfect compromised computers, Microsoft said.
__________________
An Australian Member of
Eddy
===============================
Reply With Quote
  #5  
Old 02-01-2006, 08:22 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
I dont like the way this OneCare Live works....To install it makes you uninstall your firewall first...
__________________
An Australian Member of
Eddy
===============================
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 11:20 AM.


    Firefox 2