Virus Page 1

Home
                                                                        Virus Page 2   Virus Page 3   Virus Page 4  Virus Page 5

New Virus: W32/Petik-K      Aliases: Troj/Petik-K
    Subject: "Loft Story News..."
    Message body: "The last video of the program"
    Attached file: loft_story.exe   Do not open!!

Virus  W32/Sircam-A

     Aliases:    W32.Sircam.Worm@mm, W32/SirCam@mm,  Backdoor.SirCam

Do not open the attachment
If you recive an E-mail that has any of the following
starting with the line,
How are you?"
"I send you this file in order to have your advice"
"I hope you like the file that I sendo you"
"I hope you can help me with this file that I send" or
"This is the file with the information you ask for"

                     The last line of the message always reads:  "See you later. Thanks"
There is a fix for this virus .

Another virus to watch for.
Don't open it
Description:

VBS/PeachyPDF uses a feature in the full version of Adobe Acrobat to execute its code from a PDF file.
The PDF file will arrive by email and the subject will contain one of the following:

  "You have one minute to find the peach"
  "Find the peach"
  "Find"
  "Peach"

The text of the message will be one of the following:

  "Try finding the peach"
  "Try this"
  "Interesting search"
  "I don't usually send this things, but..."

The attachment will be called one of the following:

  "find.pdf"
  "peach.pdf"
  "find the peach.pdf"
  "find_the_peach.pdf"
  "joke.pdf"
  "search.pdf"

When the user opens the attachment, a PDF with the title "You have one minute to find the peach" is displayed.

If the user follows the instructions in the PDF, using the full version of Acrobat, Acrobat will extract the worm and run it. It will display an image with the text "Line1,picture6" while it is using Outlook to mail itself out.

  I Don't have a fix  yet
 
 

New Antivirus Tool  NOT

              Name:           W32/Allgro-A
              Aliases          W32/Atirus@m, W32.Allgro@mm, All3gro
              Type:           Win32 worm

 W32/Allgro-A is an email-aware worm which sends itself using MAPI functions.
 The worm arrives in an email with the subject " New antivirus tool". The message body contains the text

" Hey, checkout this new antivirus tool which checks your system for viruses ".
The attached filename is antivirus.exe.
When the attachment is run, the worm copies itself into the Windows System directory with the filename setup30.exe.

On  September 16 the worm displays the message box
"System protected by  I-Worm.Antivirus Copyright [c] 2001 by aLL3gRo".

   Virus Page2

Virus Page3

Virus Page4

  Home Page