Register a free account

ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Security Alerts and vulnerabilities
The Software Store

Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 01-31-2006, 07:55 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,615
Send a message via MSN to Mobo
Win32/Mywife.E@mm

I recieved this in an email from Microsoft Technet:

Microsoft wants to make customers aware of the Mywife mass mailing malware variant named Win32/Mywife.E@mm. The mass mailing malware tries to entice users through social engineering efforts into opening an attached file in an e-mail message. If the recipient opens the file, the malware sends itself to all the contacts that are contained in the system’s address book. The malware may also spread over writeable network shares on systems that have blank administrator passwords.

Customers who are using the most recent and updated antivirus software could be at a reduced risk of infection from the Win32/Mywife.E@mm malware. Customers should verify this with their antivirus vendor. Antivirus vendors have assigned different names to this malware but the Common Malware Enumeration (CME) group has assigned it ID CME-24.

On systems that are infected by Win32/Mywife@E.mm, the malware is intended to permanently corrupt a number of common document format files on the third day of every month. February 3, 2006 is the first time this malware is expected to permanently corrupt the content of specific document format files. The malware also modifies or deletes files and registry keys associated with certain computer security-related applications. This prevents these applications from running when Windows starts. For more information, see the Microsoft Virus Encyclopedia.

As with all currently known variants of the Mywife malware, this variant does not make use of a security vulnerability, but is dependant on the user opening an infected file attachment. The malware also attempts to scan the network looking for systems it can connect to and infect It does this in the context of the user. If it fails to connect to one of these systems, it tries again by logging on with "Administrator" as the user name together with a blank password.

Customers who believe that they are infected with the Mywife malware, or who are not sure whether they are infected, should contact their antivirus vendor. Alternatively, Windows Live Safety Center Beta Web site provides the ability to choose “Protection Scan” to ensure that systems are free of infection. Additionally, the Windows OneCare Live Beta, which is available for English language systems, provides detection for and protection against the Mywife malware and its known variants.

For more information about the Mywife malware, to help determine whether you have been infected by the malware, and for instructions on how to repair your system if you have been infected, see the Microsoft Virus Encyclopedia. For Microsoft Virus Encyclopedia references, see the “Overview” section. We continue to encourage customers to use caution with unknown file attachments and to follow our Protect Your PC guidance of enabling a firewall, getting software updates, and installing antivirus software. Customers can learn more about these steps by visiting the Protect Your PC Web site.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Sponsored Links

  #2  
Old 01-31-2006, 10:32 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
This is the same as the Blackworm/Karma Sutra that I posted the other day.Same bug,different name.

[Only Registered and Activated Users Can See Links. Click Here To Register...]
__________________
An Australian Member of
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Eddy
===============================
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Reply With Quote
  #3  
Old 01-31-2006, 10:35 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,615
Send a message via MSN to Mobo
And I wish that the Software companies could unite somehow in cataloging these things. This type of stuff happens all the time.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #4  
Old 02-01-2006, 07:51 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
Microsoft Won't Issue Advance Kama Sutra Fix

Microsoft Won't Issue Advance Kama Sutra Fix

Infected PCs will be in danger on Friday. Microsoft said its next scheduled set of fixes--on Feb. 14--will detect and remove the worm.

By Gregg Keizer
[Only Registered and Activated Users Can See Links. Click Here To Register...]

Jan 31, 2006 12:37 PM

Microsoft Monday posted a security advisory on the Kama Sutra/Blackworm/MyWife worm that's set to overwrite Office documents on infected PCs Friday, but the company has decided against updating its Windows Malicious Software Removal Tool before the next regularly-scheduled release of Feb. 14.
The [Only Registered and Activated Users Can See Links. Click Here To Register...] -- a mechanism Microsoft uses to both alert users of impending threats and give them advice or workarounds to apply -- repeats recommendations that most security vendors have been offering since the worm debuted two weeks ago.
It also notes that infected PCs will be in danger on Friday, Feb. 3, when the [Only Registered and Activated Users Can See Links. Click Here To Register...] will overwrite several popular file formats, including those of Microsoft Office, with useless data.
But according to the team in charge of Microsoft's Windows Software Removal Tool, that program won't be updated until after the Friday deadline passes.
"Microsoft releases a new version of the Windows Malicious Software Removal Tool every month on the second Tuesday of the month together with the other security updates," wrote developers on the group's blog. "The next version, targeted for release on February 14th, will detect and remove this worm."
The [Only Registered and Activated Users Can See Links. Click Here To Register...] offered no explanation why the tool wouldn't be updated earlier, nor did Microsoft immediately respond to questions. Each month, Microsoft pushes a revised tool to Windows users who have Automatic Update enabled for Windows Update or Microsoft Update.
The Redmond, Wash.-based company has released the Malicious Software Removal Tool off-schedule once before, in August 2005, shortly after the [Only Registered and Activated Users Can See Links. Click Here To Register...] began striking Windows 2000 systems. Both the company's free online security service, [Only Registered and Activated Users Can See Links. Click Here To Register...], and its in-beta [Only Registered and Activated Users Can See Links. Click Here To Register...] software, however, will disinfect compromised computers, Microsoft said.
__________________
An Australian Member of
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Eddy
===============================
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Reply With Quote
  #5  
Old 02-01-2006, 08:22 PM
Pancake's Avatar
Pancake Pancake is offline
Administrator
 
Join Date: Sep 2004
Location: Victoria,Australia
Posts: 371
I dont like the way this OneCare Live works....To install it makes you uninstall your firewall first...
__________________
An Australian Member of
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Eddy
===============================
[Only Registered and Activated Users Can See Links. Click Here To Register...]
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 12:56 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved