Internet.com
Get your
ISP-News
courtesy of
internetnews.com




Search ISP-Lists
Search:
ISP Channel
CLEC-Planet
ISP Glossary
ISP News
ISP-Planet
ISP-Lists
E-mail Newsletters
Opt-in Announcements
Discussion Forums
internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

The ISP-Lists.com Email Discussion List Community

<- Previous Message | Next Message ->
Thread Index
Re: [isp-wireless] ANybody else getting virus emails?
Dear Trend Micro customer,

As of January 27, 2005 1:42 AM PST (Pacific Standard Time/GMT -8:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_BAGLE.AZ. TrendLabs has received several infection reports indicating that this malware is spreading in US, China, and Japan.

This WORM_BAGLE variant arrives on a system as an email attachment. It sends copies of itself to all email addresses it gathers from files with certain extensions but skips those addresses that contain particular strings.

===============================
Users must be wary of the email it sends that have the following details:

Subject: (any of the following) Delivery service mail Delivery by mail Registration is accepted Is delivered mail You are made active Thanks for use of our software. Before use read the help
Message body: (any of the following) Delivery service mail Delivery by mail Registration is accepted Is delivered mail You are made active Thanks for use of our software. Before use read the help
Attachments: (any of the following file names) guupd02.exe Jol03.exe siupd02.exe upd02.exe viupd02.exe wsd01.exe zupd02.exe
(with any of the following extensions) COM CPL EXE SCR ===============================

The email is spoofed and may appear to have come from a familiar email address. As a general rule, users should avoid opening the attachments of unsolicited email.

This worm drops a copy of itself using the following file names into the Windows system folder:

sysformat.exe sysformat.exeopen sysformat.exeopenopen It also looks for folders that have the string shar then drops copies of itself using file names with EXE extensions into those folders.

In addition, this worm terminates several processes, most of which are related to antivirus and security programs.

TrendLabs has uploaded the following:
TMCM Outbreak Prevention Policy 140 Official Pattern Release 2.375.00 Damage Cleanup Template 495




For more information on WORM_BAGLE.AZ, you can visit our Web site at:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_BAGLE.AZ
Contact av_query@... for inquiries and to report infections in your regi





** ISPCON Spring 2005 - Baltimore Convention Center **
    ** The ISP and WISP event - http://www.ispcon.com **
    ** Exhibit Hall Pass FREE until Feb 11 * Sign up today,
                    use customer code ISP-WIR**





To unsubscribe via postal mail, please contact us at:
Jupitermedia Corp.
Attn: Discussion List Management
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.

Copyright 2005 Jupitermedia Corporation All Rights Reserved.

Replies
RE: [isp-wireless] ANybody else getting virus emails?, Jeff Broadwick
Re: [isp-wireless] ANybody else getting virus emails?, geowires
Re: [isp-wireless] ANybody else getting virus emails?, Richard Munoz
<- Previous Message | Next Message ->
Thread Index

ISP Glossary
Find an ISP Term

Need Help?


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers