EmailEmail
PrintPrint
Worry Watch: Sober.Y raises an orange alert
Saturday, October 15, 2005

 
 

WEEKLY REPORTS

Latest security updates

Top 10 Threats

   
 

There is a new member in the Sober family of computer viruses. The new addition, Sober.Y, has infected so many computers in the past week that anti-virus company Panda Software raised its Global ThreatWatch meter from green to orange.

According to Panda, Sober.Y had rapidly infected computers around the world just hours after it was first discovered.

The threat spreads using two different e-mail messages to trick recipients. The first is in English with the subject of "Your new password," and convinces users to open an infected attachment in order to check the personal data related to a password change. The second is in German and claims that the attached file contains a picture of old school friends. In both cases, the e-mail attachments are actually a copy of the worm itself. If the file is run, an error message is displayed, but the worm still harvests the e-mail addresses from your computer and sends itself to them.

As usual, experts advise caution when opening e-mails from unknown senders.


Worry Watch Plus Online only:

Information, Prevention and Protection -- The new Sober threat
Panda Software Definition

Panda Software TruPrevent


Microsoft's Latest Security Releases:

Name

Link to Number

For Users of

Priority

Vulnerability in DirectShow Could Allow Remote Code Execution

KB904706

Windows 98, 2000 (SP4), ME, XP (SP1 and SP2)*

Critical

Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution

KB902400

Windows 2000 (SP4), XP (SP1 and SP2)*

Critical

Cumulative Security Update for Internet Explorer

KB896688

Internet Explorer on Windows 98, 2000 (SP4), ME, XP (SP1 and SP2)*

Critical

Vulnerability in the Client Services for Netware Could Allow Remote Code Execution

KB899589

Windows 2000 (SP4), XP (SP1 and SP2)*

Important

Vulnerability in Plug and Play Could Allow Remote Code Execution and Local Elevation of Privilege

KB905749

Windows 2000 (SP4), XP (SP1 and SP2)

Important

Vulnerability in the Microsoft Collaboration Objects Could Allow Remote Code Execution

KB907245

Windows 2000 (SP4), XP (SP1 and SP2)*

Important

Vulnerabilities in Windows Shell Could Allow Remote Code Execution

KB900725

Windows 2000 (SP4), XP (SP1 and SP2)*

Important

Vulnerability in Windows FTP Client Could Allow File Transfer Location and Tampering

KB905495

Windows XP (SP1)*

Moderate

Vulnerability in Network Connection Manager Could Allow Denial of Service

KB905414

Windows 2000 (SP4), XP (SP1 and SP2)*

Moderate

Windows Malicious Software Removal Tool

KB890830

Windows 2000, XP*

Go back

* Reading: Solutions, Prevention & Remedies
Additional summary information related to a specific type of solution or prevention that you should be considering. Depending upon the week, this section may have:
• Recent Windows security releases from Microsoft
• Recent updates to widely used anti-spyware programs
• Recent updates to widely used anti-virus programs
• Recent updates to other security programs & devices (ex: Firewalls, routers)
• Recent updates to various applications in wide use


Top 10 Threats:

Name

Type

Affects

Alert Level

Sdbot.ftp

Worm

Windows 95, 98, 2000, ME, NT, XP

Medium

Netsky.P

Worm

Windows 95, 98, 2000, ME, NT, XP*

Severe

Sdbot.FHG

Worm

Windows 95, 98, 2000, ME, NT, XP

High

Gaobot.gen

Worm

Windows 2000, NT, XP*

Medium

Qhost.gen

Trojan

Windows 2000, NT, XP*

Low

Mhtredir.gen

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Zlob.S

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Alcan.worm

Worm

Windows 95, 98, 2000, ME, NT, XP

Low

Qhost.CG

Trojan

Windows 95, 98, 2000, ME, NT, XP

Low

Cimuz.X

Trojan

Windows 95, 98, 2000, ME, XP*

Medium

Go back

Read: Top Threats
These are viruses that are currently on the watch lists of major anti-virus software companies.

Name
What the threat is called. We use the name given each virus by Panda Software. Sometimes other anti-virus companies give the same threat a different name. Usually they use similar names.

Type
There are different characteristics associated with different types of threats.
• Virus - has the ability to replicate or infect computers or other programs
• Trojan Horse (or Trojan) - appear to be harmless programs when you get them. They unleash their payload when you double-click, open, or execute them.
• Phishing - a Web site or e-maill message posing as another company - usually one you know to fool you into giving the sender personal information.
• Worm - self replicates onto additional disks, computers or networks
• Spyware - installs on your system to collect information about your activity, preferences or interests
• Hoax - false messages sent by e-maill to mislead the recipient
• Backdoors - opens a security hole that allows outsiders to take control of your computer
• Dialer - uses your telephone to dial an outside number - sometimes a number that costs you money when dialed

Affects
Not all viruses affect all types of systems. Some, for example may affect only Windows 98 and 95, but not Windows XP or NT. Others affect all Windows systems, but not Macintosh. In this column, we show you the consumer systems that the threat is known to affect. We don't always include the servers that operate in your company's backroom.

Alert level
The level of awareness that anti-virus vendors suggest you need to have for each threat listed.
For each threat listed, we'll post a corresponding link here, so you can get more information to help you recognize, diagnose, prevent, and repair the problem.

First published on October 15, 2005 at 12:00 am
Worry Watch is compiled by David Radin & Jes Scherder using data and reports from Microsoft, CERT, Panda, and other sources. To contact the compilers of Worry Watch, go to http://www.megabyteminute.com/contactdavid.html.
EmailEmail
PrintPrint