<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Antivirus Guy Blog</title>
	<atom:link href="http://antivirusguy.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://antivirusguy.wordpress.com</link>
	<description>Keeping people up to date with antivirus and security information</description>
	<lastBuildDate>Sun, 11 Nov 2007 14:34:39 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='antivirusguy.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/401ded1d1375a2fc50f21a1d7a84a8e1?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>The Antivirus Guy Blog</title>
		<link>http://antivirusguy.wordpress.com</link>
	</image>
			<item>
		<title>SANS Internet Storm Center &#8211; &quot;Malicious&quot; Websites</title>
		<link>http://antivirusguy.wordpress.com/2007/11/11/sans-internet-storm-center-quot-malicious-quot-websites/</link>
		<comments>http://antivirusguy.wordpress.com/2007/11/11/sans-internet-storm-center-quot-malicious-quot-websites/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 14:34:39 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2007/11/11/sans-internet-storm-center-quot-malicious-quot-websites/</guid>
		<description><![CDATA[&#160;
&#8220;Malicious&#8221; Websites  
Published: 2007-11-10,Last Updated: 2007-11-10 21:26:57 UTCby Koon Yaw Tan (Version: 1)  
Previously, we often warn people from visiting unknown/suspicious websites as they could contain malicious content. But nowadays, even visiting known websites, you could be affected. It was reported that the India Times website contains hundreds of malicious files that could [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=91&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>&nbsp;</p>
<blockquote><p><a href="http://www.isc.sans.org/diary.html?storyid=3631">&#8220;Malicious&#8221; Websites</a>  </p>
<p>Published: 2007-11-10,<br />Last Updated: 2007-11-10 21:26:57 UTC<br />by Koon Yaw Tan (Version: 1)  </p>
<p>Previously, we often warn people from visiting unknown/suspicious websites as they could contain malicious content. But nowadays, even visiting known websites, you could be affected. It was reported that the India Times website contains hundreds of malicious files that could infected those visit the website.<br />http://www.theregister.co.uk/2007/11/10/india_times_under_attack/<br />Legitimate websites containing malicious content is not something new as it has already happened a couple of times. Web administrators must be prudent to ensure their websites are properly secure. Hackers are now clever enough not to deface your websites to alert you but rather plant malicious content on them and wait for victims. Periodically running a vulnerability scan on your web systems is necessary to avoid known holes. Let us know if you have other good tips for the web admin.</p>
</blockquote>
<p><a href="http://www.isc.sans.org/diary.html?storyid=3631">SANS Internet Storm Center; Cooperative Network Security Community &#8211; Internet Security &#8211; isc</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/91/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/91/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/91/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=91&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2007/11/11/sans-internet-storm-center-quot-malicious-quot-websites/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS &#8211; Internet Storm Center &#8211; CME-24 (Blackworm) Analysis: The destruction does not appear to spread across Windows network shares</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-cme-24-blackworm-analysis-the-destruction-does-not-appear-to-spread-across-windows-network-shares/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-cme-24-blackworm-analysis-the-destruction-does-not-appear-to-spread-across-windows-network-shares/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 03:04:28 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-cme-24-blackworm-analysis-the-destruction-does-not-appear-to-spread-across-windows-network-shares/</guid>
		<description><![CDATA[
CME-24 Analysis: The destruction does not appear to spread  across Windows network shares (NEW)

Published: 2006-02-02,
Last Updated: 2006-02-02  17:39:40 UTC by Lorna Hutcheson (Version: 1) 
I wanted to share some of the results of some long  hours spent looking at this malware.  When the infection occurs, it immediately  places copies of itself  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=89&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.isc.sans.org/diary.php?storyid=1090"><p><a href="http://www.isc.sans.org/diary.php?storyid=1090"></p>
<h2><font size="3"><em>CME-24 Analysis: The destruction does not appear to spread  across Windows network shares <font color="green">(NEW)</font></em></font></h2>
<p></a></p>
<div><em>Published: 2006-02-02,<br />
Last Updated: 2006-02-02  17:39:40 UTC by Lorna Hutcheson (Version: 1) </em></div>
<div><em>I wanted to share some of the results of some long  hours spent looking at this malware.  When the infection occurs, it immediately  places copies of itself  locally on each share and on each share/mapped drive  that it finds.  Based on this behavior, my initial thoughts were that the  destructive payload would be carried out via shares and/or mapped drives as  well.</p>
<p>I now have changed my initial thoughts on how the destruction would  occur.  Here are some of my notes from my testing of this concept.  Here is the  MD5 from the file I was using:<br />
1c66904ecb846da5b1fb2072f9ea6e0e *New WinZip  File.exe</p>
<p>The first test I did led me to believe that the destruction  would be carried out via the shares and mapped drives.  In my intial test, I had  two infected systems (one XP and one W2K) with drives mapped to each other.  I  infected each box, changed the system time to Feb 2 at 11:50pm, launched  ethereal, filemon and ran the the first shot using RegShot.  After an hour, I  stopped the captures and launched my second shot of the hard drive with  RegShot.  All my data files were now over written, zip files were corrupted,  etc.  Everything was happening as I thought it would.  All my mapped drives had  corrupted files. The security logs from each box showed accesses from the  other.</em></div>
</blockquote>
<p>For  the rest of this in depth analysis, go here: <a href="http://www.isc.sans.org/diary.php?storyid=1090">SANS &#8211; Internet Storm  Center &#8211; Cooperative Cyber Threat Monitor And Alert System</a>.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/89/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/89/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/89/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=89&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-cme-24-blackworm-analysis-the-destruction-does-not-appear-to-spread-across-windows-network-shares/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>F-Secure : News from the Lab &#8211; Nyxem on a world map</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-nyxem-on-a-world-map/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-nyxem-on-a-world-map/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 03:03:00 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-nyxem-on-a-world-map/</guid>
		<description><![CDATA[Nyxem  on a world map    Posted by Mikko @ 14:31 GMT

We have been co-operating with RCN,  the company running the counter site that is used by the Nyxem worm. Last night  we got the web access statistics, listing all the IP addresses that have  accessed the Nyxem counter.
After filtering out the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=88&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.f-secure.com/weblog/archives/archive-022006.html#00000800"><p><strong>Nyxem  on a world map    Posted by Mikko @ 14:31 GMT<br />
</strong></p>
<p align="justify"><em>We have been co-operating with RCN,  the company running the counter site that is used by the Nyxem worm. Last night  we got the web access statistics, listing all the IP addresses that have  accessed the Nyxem counter.</em></p>
<p align="justify"><em>After filtering out the addresses of bots that have been  hammering the counter lately, we used our WORLDMAP technology to map the  addresses to a map. As a result we have a global view of the machines that will  run into trouble unless they are disinfected before tomorrow:</em></p>
<p align="justify"><a href="http://www.f-secure.com/weblog/archives/NyxemLatLonBig.png"><em><img border="0" alt="Nyxem.E worldmap" src="http://www.f-secure.com/weblog/archives/NyxemLatLonSmall.png" /></em></a><br />
<em>- click the map for a high-resolution version &#8211;  </em>
</p>
<p align="justify"><em>Nyxem.E starts to overwrite files half an hour after the  infected machines are started on the 3rd of the month.</em></p>
<p align="justify"><em>We&#8217;d like to thank Jason Nealis and Chris Jackman at RCN  for their generous help with this issue. </em></p>
<p><a href="http://www.f-secure.com/weblog/archives/archive-022006.html#00000800">F-Secure  : News from the Lab &#8211; February of 2006</a>.</p></blockquote>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/88/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/88/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=88&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-nyxem-on-a-world-map/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>

		<media:content url="http://www.f-secure.com/weblog/archives/NyxemLatLonSmall.png" medium="image">
			<media:title type="html">Nyxem.E worldmap</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS &#8211; Internet Storm Center &#8211; Prepraring for Feb 3rd(CME-24\Blackworm)</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-prepraring-for-feb-3rdcme-24blackworm/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-prepraring-for-feb-3rdcme-24blackworm/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 03:01:17 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-prepraring-for-feb-3rdcme-24blackworm/</guid>
		<description><![CDATA[

Prepraring for Feb 3rd(CME-24) (NEW)

Published: 2006-02-02,
Last Updated: 2006-02-02  16:07:43 UTC by Pedro Bueno (Version: 1)
Prepraring for Feb 3rd(CME-24)
We received a lot of  suggestions about measures against CME-24. In other words,
how to prepare  for Feb 3rd, in despite of the Anti-virus.
What follows bellow is a  compiled list of those. Some were tested, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=87&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.isc.sans.org/diary.php?storyid=1088">
<div><a href="http://www.isc.sans.org/diary.php?storyid=1088"></p>
<h2>Prepraring for Feb 3rd(CME-24) <font color="green">(NEW)</font></h2>
<p></a></p>
<div>Published: 2006-02-02,<br />
Last Updated: 2006-02-02  16:07:43 UTC by Pedro Bueno (Version: 1)</div>
<div>Prepraring for Feb 3rd(CME-24)</p>
<p>We received a lot of  suggestions about measures against CME-24. In other words,<br />
how to prepare  for Feb 3rd, in despite of the Anti-virus.</p>
<p>What follows bellow is a  compiled list of those. Some were tested, but some not.</p>
<p>- The rule  bellow, made by Per Kristian Johnsen with Telenor Security Center,<br />
is said  to detect attempts to copy WINZIP_TMP.exe to shares. According to the author,<br />
they are being able to detect infected machines where the already published<br />
snort/sourcefire rule couldn&#8217;t:</p>
<p>alert tcp any any -&gt; any 135:139  (msg:&#8221;Nyxem attempting to copy WINZIP_TMP.exe to shares&#8221;;  flow:to_server,established; content:&#8221;|57 00 49 00 4e 00 5a 00 49 00 50 00 5f 00  54 00 4d 00 50 00 2e 00 65 00 78 00 65|&#8221;;  reference:url,www.lurhq.com/blackworm.html; classtype:trojan-activity;  sid:5000173; rev:1;)</p>
<p>- <font color="#ff0000"><strong>We had another user  that used sms to scan drives files with a size of 95,690 named <font color="#000000">(Bloggers note: I have been doing this query too, but missed the  files size  part)</font></p>
<p>%Windir%\Rundll16.exe<br />
%System%\scanregw.exe<br />
%System%\Winzip.exe<br />
%System%\Update.exe<br />
%System%\WINZIP_TMP.EXE<br />
%System%\SAMPLE.ZIP<br />
%System%\New  WinZip File.exe<br />
movies.exe<br />
Zipped Files.exe<br />
</strong></font></p>
<p>- A  security Dweeb at a large California municipal government agency wrote a batch  script that:</p>
<p>&#8220;1) looks for the infected file names existence<br />
on  %windir% and %sysdir% using simple DIR /B commands. Output is sent  to<br />
uniquely named text file (with a non-standard extension).  Infected<br />
workstations will show a non-zero file size. Batch file is below;  uses<br />
environment vars that are unique to user and computer name.<br />
2) The  batch file will be placed in the login script for all<br />
computers.<br />
3) Ensure  that verified backups are completed tonight (Wed).</p>
<p>Batch file:<br />
@echo  off<br />
dir /b %WinDir%\system\\Winzip.exe &gt;&gt;  %username%_%computername%.rgh<br />
dir  /b %WinDir%\system\Update.exe  &gt;&gt;  %username%_%computername%.rgh<br />
dir /b  %WinDir%\system\scanregw.exe  &gt;&gt;  %username%_%computername%.rgh<br />
dir  /b %WinDir%\Rundll16.exe  &gt;&gt;  %username%_%computername%.rgh<br />
dir  /b %WinDir%\winzip_tmp.exe  &gt;&gt;  %username%_%computername%.rgh<br />
dir  /b c:\winzip_tmp.exe  &gt;&gt;  %username%_%computername%.rgh<br />
dir  /b  %Temp%\word.zip                                        .exe   &gt;&gt;<br />
%username%_%computername%.rgh</p>
<p>Although dangerous, we think we  have a very low chance of a problem.<br />
According to LURQ, there are only 15K  computers in US that have<br />
contacted the &#8220;counter&#8221; site. And we have other  protections in place<br />
(blocking of all executables in mail attachments,  current anti-virus<br />
updates,  etc.)&#8221;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Handler  on Duty: Pedro Bueno ( pbueno //&amp;&amp;// isc. sans. org  )</p></div>
</div>
<p><a href="http://www.isc.sans.org/diary.php?storyid=1088">SANS &#8211; Internet Storm  Center &#8211; Cooperative Cyber Threat Monitor And Alert  System</a>.</p></blockquote>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/87/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/87/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=87&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-prepraring-for-feb-3rdcme-24blackworm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Security Advisory Notification &#8211; Update for Security Advisory (904420) &#8211; Win32/Mywife.E@mm</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-notification-update-for-security-advisory-904420-win32mywifeemm/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-notification-update-for-security-advisory-904420-win32mywifeemm/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 02:57:09 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-notification-update-for-security-advisory-904420-win32mywifeemm/</guid>
		<description><![CDATA[ ***************************************
Title: Microsoft Security Advisory Notification
Issued: February 1, 2006
***************************************
Security Advisories Updated or Released Today  ==============================================
* Security Advisory (904420) 
- Title: Win32/Mywife.E@mm
- Reason For Update: Additional information about the blank password  restriction functionality in Windows XP Service Pack 1, 
Windows XP Service Pack 2, Windows Server 2003, and Windows Server 2003  Service Pack [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=86&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><font size="2"> </font><font size="2">***************************************</font></p>
<p><font size="2">Title: Microsoft Security Advisory Notification</font></p>
<p><font size="2">Issued: February 1, 2006</font></p>
<p><font size="2">***************************************<br />
Security Advisories Updated or Released Today  ==============================================</font></p>
<p><font size="2">* Security Advisory (904420) </font></p>
<p><font size="2">- Title: Win32/Mywife.E@mm</font></p>
<p><font size="2">- Reason For Update: Additional information about the blank password  restriction functionality in Windows XP Service Pack 1, </font></p>
<p><font size="2">Windows XP Service Pack 2, Windows Server 2003, and Windows Server 2003  Service Pack 1. Added link to Virus Information </font></p>
<p><font size="2">Alliance member Sophos. </font></p>
<p><font size="2">- Web site: </font><a href="http://go.microsoft.com/fwlink/?LinkId=50423"><u><font size="2" color="#0000ff">http://go.microsoft.com/fwlink/?LinkId=50423</font></u></a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/86/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/86/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/86/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/86/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/86/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=86&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-notification-update-for-security-advisory-904420-win32mywifeemm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>F-Secure : News from the Lab &#8211; First reports of Nyxem damage</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-first-reports-of-nyxem-damage/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-first-reports-of-nyxem-damage/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 02:55:08 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-first-reports-of-nyxem-damage/</guid>
		<description><![CDATA[
Tuesday, January 31, 2006



First  reports of Nyxem damage
Posted by Mikko @ 16:24 GMT






The destructive deadline of the Nyxem.E  worm is based on the clock of the infected machine. So if you&#8217;re infected and  your clock is not set right, things could start to happen at any time &#8211; even  though the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=85&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.f-secure.com/weblog/archives/archive-012006.html#00000797">
<p align="left"><strong>Tuesday, January 31, 2006</strong></p>
<p><a name="00000797"></a></p>
<table width="100%" cellspacing="0" cellpadding="0" border="0">
<tr>
<td align="left"><strong><a href="http://www.f-secure.com/weblog/archives/archive-012006.html#00000797">First  reports of Nyxem damage</a></strong></td>
<td align="left">Posted by Mikko @ 16:24 GMT</td>
</tr>
<tr>
<td colspan="2">
<hr /></td>
</tr>
</table>
<p align="justify">The destructive deadline of the Nyxem.E  worm is based on the clock of the infected machine. So if you&#8217;re infected and  your clock is not set right, things could start to happen at any time &#8211; even  though the official activation time is the 3rd of the month. We&#8217;ve already  received first reports from users who&#8217;ve had files on their system overwritten  by the worm.</p>
<p align="justify"><img border="0" alt="nyxem_killed" src="http://www.f-secure.com/weblog/archives/nyxem_killed.gif" /></p>
<p align="justify">When Nyxem activates, it will overwrite all of your  DOC/XLS/PPT/ZIP/RAR/PDF/MDB files. This is nasty, as this is done on all mounted  drives, ie. any drive that has a drive letter. So it might affect your USB thumb  drives, external hard drives and network drives! Also, if you&#8217;re taking daily  automatic backups you might end up backing up the corrupted files over good  files.</p>
<p align="justify">The number of machines that have been hit by this worm is over  300,000. Many of those have been disinfected already, though. But thousands of  computers will get their files overwritten on February 3rd &#8211; most of them in  India, Turkey and Peru.</p>
<p align="justify">This worm family has been around since March 2004. The worm is  named &#8220;Nyxem&#8221; because the original <a href="http://www.f-secure.com/v-descs/nyxem.shtml">Nyxem.A</a> variant launched  a DDoS attack against the New York Mercantile Exchange website (www.nymex.com).  We don&#8217;t know why.</p>
<p align="justify">We have <a href="http://www.f-secure.com/v-descs/nyxem_e.shtml">a free tool</a> available  to help disinfect machines before the deadline passes.</p>
<p><a href="http://www.f-secure.com/weblog/archives/archive-012006.html#00000797">F-Secure  : News from the Lab &#8211; January of 2006</a>.</p></blockquote>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/85/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/85/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/85/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/85/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/85/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=85&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/f-secure-news-from-the-lab-first-reports-of-nyxem-damage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>

		<media:content url="http://www.f-secure.com/weblog/archives/nyxem_killed.gif" medium="image">
			<media:title type="html">nyxem_killed</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Security Advisory (904420): Win32/Mywife.E@mm (aka Blackworm)</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-904420-win32mywifeemm-aka-blackworm/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-904420-win32mywifeemm-aka-blackworm/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 02:54:17 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-904420-win32mywifeemm-aka-blackworm/</guid>
		<description><![CDATA[For even more comprehensive information on this virus go here: http://www.isc.sans.org/blackworm
Microsoft Security Advisory (904420)

Win32/Mywife.E@mm
Published: January 30, 2006

Microsoft wants to make customers aware of the Mywife mass mailing  malware variant named Win32/Mywife.E@mm. The mass mailing malware tries to  entice users through social engineering efforts into opening an attached file in  an e-mail message. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=84&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>For even more comprehensive information on this virus go here: <a href="http://www.isc.sans.org/blackworm">http://www.isc.sans.org/blackworm</a></p>
<h1><font size="3"><em>Microsoft Security Advisory (904420)</em></font></h1>
<blockquote cite="http://www.microsoft.com/technet/security/advisory/904420.mspx">
<h2><font size="3"><em>Win32/Mywife.E@mm</em></font></h2>
<div><em>Published: January 30, 2006</em></div>
<div></div>
<p><em>Microsoft wants to make customers aware of the Mywife mass mailing  malware variant named Win32/Mywife.E@mm. The mass mailing malware tries to  entice users through social engineering efforts into opening an attached file in  an e-mail message. If the recipient opens the file, the malware sends itself to  all the contacts that are contained in the system’s address book. The malware  may also spread over writeable network shares on systems that have blank  administrator passwords. </em></p>
<p><em>Customers who are using the most recent and updated antivirus software  could be at a reduced risk of infection from the Win32/Mywife.E@mm malware.  Customers should verify this with their antivirus vendor. Antivirus vendors have  assigned different names to this malware but the Common Malware Enumeration  (CME) group has assigned it ID CME-24. </em></p>
<p><em>On systems that are infected by Win32/Mywife@E.mm, the malware is  intended to permanently corrupt a number of common document format files on the  third day of every month. February 3, 2006 is the first time this malware is  expected to permanently corrupt the content of specific document format files.  The malware also modifies or deletes files and registry keys associated with  certain computer security-related applications. This prevents these applications  from running when Windows starts. For more information, see the </em><a href="http://www.microsoft.com/security/encyclopedia/details.aspx?Name=Win32/Mywife.E@mm"><em>Microsoft  Virus Encyclopedia</em></a><em>.</em></p>
<p><em>As with all currently known variants of the Mywife malware, this variant  does not make use of a security vulnerability, but is dependant on the user  opening an infected file attachment. The malware also attempts to scan the  network looking for systems it can connect to and infect It does this in the  context of the user. If it fails to connect to one of these systems, it tries  again by logging on with &#8220;Administrator&#8221; as the user name together with a blank  password. </em></p></blockquote>
<p>Read the  rest of this advisory here: <a href="http://www.microsoft.com/technet/security/advisory/904420.mspx">Microsoft  Security Advisory (904420): Win32/Mywife.E@mm</a>.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/84/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/84/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/84/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/84/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/84/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=84&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/microsoft-security-advisory-904420-win32mywifeemm-aka-blackworm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS &#8211; Internet Storm Center &#8211; BlackWorm Summary &#8211; Updated Info</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info-2/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info-2/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 02:53:16 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info-2/</guid>
		<description><![CDATA[
BlackWorm Summary

Published: 2006-01-26,
Last Updated: 2006-01-27  02:01:42 UTC by Johannes Ullrich (Version: 3(click to  highlight changes))

About BlackWorm
Over the last week, &#8220;Blackworm&#8221; infected about  300,000 systems based on analysis of logs from the counter web site used by the  worm to track itself. This  worm is  different and more serious than other worms [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=83&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.isc.sans.org/"><p><a href="http://isc.sans.org/blackworm"></p>
<h2><font size="4">BlackWorm Summary</font></h2>
<p></a></p>
<div>Published: 2006-01-26,<br />
Last Updated: 2006-01-27  02:01:42 UTC by Johannes Ullrich (Version: <a href="http://www.isc.sans.org/diary.php?compare=1&amp;storyid=1067">3(click to  highlight changes)</a>)</div>
<div>
<h3>About BlackWorm</h3>
<p>Over the last week, &#8220;Blackworm&#8221; infected about  300,000 systems based on analysis of logs from the counter web site used by the  worm to track itself. This  worm is  different and more serious than other worms  for a number of reasons. In particular, it will overwrite a user&#8217;s files on  February 3rd.</p>
<p>At this point, the worm will be detected by up to date anti  virus signatures. In order to protect yourself from data loss on February 3rd,  you should use current (Jan 23rd or later) anti virus signatures.  Note,  however, that the malware attempts to disable/remove any anti-virus software on  the system (and does this every hour while the system is up), so if the machine  was infected before signatures were deployed, obviously, that anti-virus  software can&#8217;t be expected to clean up the infection for you.</p>
<p>The  following file types will be overwritten by the virus: DOC, XLS, MDE, MDB, PPT,  PPS, RAR, PDF, PSD, DMP, ZIP. The files are overwritten with an error message(  &#8216;DATA Error [47 0F 94 93 F4 K5]&#8216;).</p>
<p>We will try to post more detailed  cleanup instructions later. However, it is likely that you will have to rebuild  the system from scratch. Obtaining good backups is critical as a first  step.</p>
<p>The first thing you should do is to  update your anti virus signatures.</p>
<p>This page will be updated as  new information becomes available. Please see the end of the page for references  to other sites. Use only this url to link to this page: <a target="_self" href="http://isc.sans.org/blackworm">http://isc.sans.org/blackworm</a></p>
<h3>Naming</h3>
<p>As usual, this worm/virus has collected a number of names from  various vendors. It is so far known as: Blackmal, Nyxem, MyWife, Tearec among  other names. Update: we have been informed that the CME  number will be &#8216;CME-24&#8242;. <a target="_self" href="http://cme.mitre.org/">cme.mitre.org</a> should shortly list this number.</p>
<h3>How would I get infected?</h3>
<p>The worm spreads via e-mail attachments or  file shares. Once a system in your network is infected, it will try to infect  all shared file systems it has access to. You may see a new &#8220;zip file&#8221; icon on  your desktop.</p>
<h3>What will BlackWorm do to my system?</h3>
<p>It will disable most anti virus  products and delete them. The worm will e-mail itself using a variety of  extensions and file names. It will add itself to the list of auto-start programs  in your registry.</p>
<h3>Removal</h3>
<p>Anti virus vendors offer removal tools. Microsoft provides <a target="_self" href="http://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32%2fMywife.E%40mm">detailed instructions</a> for manual removal. However, there are  two important reasons to rebuild &#8220;from scratch&#8221;:</p>
<ol>
<li>BlackWorm uses the same tricks to install itself as other viruses/worms. It  may not be the only one on your system. Antivirus will not detect all viruses,  and the removal tool will only remove this specific worm.</li>
<li>BlackWorm will allow remote access to your system, and additional malware  may have been installed via this backdoor.</li>
</ol>
</div>
</blockquote>
<p>To read the rest of this  post, go here:   <a target="_blank" href="http://isc.sans.org/blackworm">SANS &#8211;  Internet Storm Center &#8211; Cooperative Cyber Threat Monitor And Alert  System.</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/83/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/83/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=83&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS &#8211; Internet Storm Center &#8211; BlackWorm Summary &#8211; Updated Info</title>
		<link>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info/</link>
		<comments>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info/#comments</comments>
		<pubDate>Fri, 03 Feb 2006 02:52:57 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
		
		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info/</guid>
		<description><![CDATA[
BlackWorm Summary

Published: 2006-01-26,
Last Updated: 2006-01-27  02:01:42 UTC by Johannes Ullrich (Version: 3(click to  highlight changes))

About BlackWorm
Over the last week, &#8220;Blackworm&#8221; infected about  300,000 systems based on analysis of logs from the counter web site used by the  worm to track itself. This  worm is  different and more serious than other worms [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=82&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.isc.sans.org/"><p><a href="http://isc.sans.org/blackworm"></p>
<h2><font size="4">BlackWorm Summary</font></h2>
<p></a></p>
<div>Published: 2006-01-26,<br />
Last Updated: 2006-01-27  02:01:42 UTC by Johannes Ullrich (Version: <a href="http://www.isc.sans.org/diary.php?compare=1&amp;storyid=1067">3(click to  highlight changes)</a>)</div>
<div>
<h3>About BlackWorm</h3>
<p>Over the last week, &#8220;Blackworm&#8221; infected about  300,000 systems based on analysis of logs from the counter web site used by the  worm to track itself. This  worm is  different and more serious than other worms  for a number of reasons. In particular, it will overwrite a user&#8217;s files on  February 3rd.</p>
<p>At this point, the worm will be detected by up to date anti  virus signatures. In order to protect yourself from data loss on February 3rd,  you should use current (Jan 23rd or later) anti virus signatures.  Note,  however, that the malware attempts to disable/remove any anti-virus software on  the system (and does this every hour while the system is up), so if the machine  was infected before signatures were deployed, obviously, that anti-virus  software can&#8217;t be expected to clean up the infection for you.</p>
<p>The  following file types will be overwritten by the virus: DOC, XLS, MDE, MDB, PPT,  PPS, RAR, PDF, PSD, DMP, ZIP. The files are overwritten with an error message(  &#8216;DATA Error [47 0F 94 93 F4 K5]&#8216;).</p>
<p>We will try to post more detailed  cleanup instructions later. However, it is likely that you will have to rebuild  the system from scratch. Obtaining good backups is critical as a first  step.</p>
<p>The first thing you should do is to  update your anti virus signatures.</p>
<p>This page will be updated as  new information becomes available. Please see the end of the page for references  to other sites. Use only this url to link to this page: <a target="_self" href="http://isc.sans.org/blackworm">http://isc.sans.org/blackworm</a></p>
<h3>Naming</h3>
<p>As usual, this worm/virus has collected a number of names from  various vendors. It is so far known as: Blackmal, Nyxem, MyWife, Tearec among  other names. Update: we have been informed that the CME  number will be &#8216;CME-24&#8242;. <a target="_self" href="http://cme.mitre.org/">cme.mitre.org</a> should shortly list this number.</p>
<h3>How would I get infected?</h3>
<p>The worm spreads via e-mail attachments or  file shares. Once a system in your network is infected, it will try to infect  all shared file systems it has access to. You may see a new &#8220;zip file&#8221; icon on  your desktop.</p>
<h3>What will BlackWorm do to my system?</h3>
<p>It will disable most anti virus  products and delete them. The worm will e-mail itself using a variety of  extensions and file names. It will add itself to the list of auto-start programs  in your registry.</p>
<h3>Removal</h3>
<p>Anti virus vendors offer removal tools. Microsoft provides <a target="_self" href="http://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32%2fMywife.E%40mm">detailed instructions</a> for manual removal. However, there are  two important reasons to rebuild &#8220;from scratch&#8221;:</p>
<ol>
<li>BlackWorm uses the same tricks to install itself as other viruses/worms. It  may not be the only one on your system. Antivirus will not detect all viruses,  and the removal tool will only remove this specific worm.</li>
<li>BlackWorm will allow remote access to your system, and additional malware  may have been installed via this backdoor.</li>
</ol>
</div>
</blockquote>
<p>To read the rest of this  post, go here:   <a target="_blank" href="http://isc.sans.org/blackworm">SANS &#8211;  Internet Storm Center &#8211; Cooperative Cyber Threat Monitor And Alert  System.</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/82/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/82/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/82/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/82/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/82/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=82&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/02/02/sans-internet-storm-center-blackworm-summary-updated-info/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS &#8211; Internet Storm Center &#8211; More on Nyxem</title>
		<link>http://antivirusguy.wordpress.com/2006/01/24/sans-internet-storm-center-more-on-nyxem/</link>
		<comments>http://antivirusguy.wordpress.com/2006/01/24/sans-internet-storm-center-more-on-nyxem/#comments</comments>
		<pubDate>Tue, 24 Jan 2006 12:24:11 +0000</pubDate>
		<dc:creator>antivirusguy</dc:creator>
				<category><![CDATA[Antivirus News]]></category>
		<category><![CDATA[Virus Outbreaks]]></category>

		<guid isPermaLink="false">http://antivirusguy.wordpress.com/2006/01/24/sans-internet-storm-center-more-on-nyxem/</guid>
		<description><![CDATA[
More on Nyxem 

Published: 2006-01-23,Last Updated: 2006-01-23 22:13:35 UTC by Bojan Zdrnja (Version: 1) 
Although Nyxem is comparatively less spread then worms like Sober or Netsky, it&#8217;s still doing a fair number of rounds.
The graph below is from one of the e-mail gateways with a decent number of e-mails processed daily (around 500.000+). You can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=81&subd=antivirusguy&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote cite="http://www.isc.sans.org/diary.php?storyid=1065"><p><a href="http://www.isc.sans.org/diary.php?storyid=1065"></p>
<h2>More on Nyxem </h2>
<p></a></p>
<div>Published: 2006-01-23,<br />Last Updated: 2006-01-23 22:13:35 UTC by Bojan Zdrnja (Version: 1) </div>
<p><div>Although Nyxem is comparatively less spread then worms like Sober or Netsky, it&#8217;s still doing a fair number of rounds.</p>
<p>The graph below is from one of the e-mail gateways with a decent number of e-mails processed daily (around 500.000+). You can see that Nyxem.E is the top malware instance detected in last 24 hours, with more than double the occurences then the next highest occuring worm (Netsky).</p>
<p><img alt="" src="http://isc.sans.org/diaryimages/nyxem_graph.png" /></p>
<p>This is not strange as the Web counter that the worm visits upon infecting the machine currently shows around 630,000 infections (we can&#8217;t be sure that this number is correct). Bert Rapp e-mailed us asking about the URL that the worm visits. This can help you in determining if a machine is infected, as it will visit the URL with the counter.</p>
<p>The counter is at:</p>
<p>h tt p:// webstats.web.rcn.net/ [REMOVED] / Count.cgi?df=765247</p>
<p>You can search your web logs for this host name (which looks as a legitimate site).</p>
<p>Other than that, Fortinet released their in-depth analysis of the Nyxem worm with some pretty interesting details (you can find the original analysis <a href="http://www.fortinet.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=viewVirusDetailsInfoDirectly&amp;fid=119856" target="_self">here</a>).<br />The most interesting part, which I haven&#8217;t seen in other analysis of the worm says:</p>
<p>&#8220;Additional Registry Changes</p>
<ul>
<li>The virus is coded to register the dropped ActiveX control through changes to the system registry. By creating the following registry entries, the control is considered &#8220;safe&#8221; and digitally signed.&#8221;</li>
</ul>
<p>The threat of worms like this will make them much more dangerous in the future. If a worm puts a fake CA certificate on an infected machine, MITM attacks become extremely easy. Of course, we all know that once the machine is infected you can&#8217;t trust it, but this looks like another (big) problem for the average user out there.</div>
<p><a href="http://www.isc.sans.org/diary.php?storyid=1065">SANS &#8211; Internet Storm Center &#8211; Cooperative Cyber Threat Monitor And Alert System</a>.</p>
</blockquote>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/antivirusguy.wordpress.com/81/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/antivirusguy.wordpress.com/81/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antivirusguy.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antivirusguy.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antivirusguy.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antivirusguy.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antivirusguy.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antivirusguy.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antivirusguy.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antivirusguy.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antivirusguy.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antivirusguy.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antivirusguy.wordpress.com&blog=31311&post=81&subd=antivirusguy&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://antivirusguy.wordpress.com/2006/01/24/sans-internet-storm-center-more-on-nyxem/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/36ebdbc8ac9ad020452ee8a9efed7a11?s=96&#38;d=identicon" medium="image">
			<media:title type="html">antivirusguy</media:title>
		</media:content>

		<media:content url="http://isc.sans.org/diaryimages/nyxem_graph.png" medium="image" />
	</item>
	</channel>
</rss>