Witty Worm

Saturday, March 8th, 2008

A new worm has been discovered exploiting the ISS/PAM ICQ module vulnerability. The worm payload is contained in a single 1025-byte UDP packet with a fixed source port of 4000 and a random destination port. Only the first 470 bytes of the payload are the working code of the worm; ...

W32.Sobig.F@mm Removal Tool

Saturday, March 8th, 2008

Symantec Security Response has developed a removal tool to clean the W32.Sobig.F@mm infections. The W32.Sobig.F@mm Removal Tool does the following: Terminates the W32.Sobig.F@mm viral processes. Deletes the W32.Sobig.F@mm files. Deletes the dropped files. Deletes the registry values that the worm added. http://www.symantec.com/avcenter/venc/data/[email protected]

W32.Blaster.Worm Removal Tool

Saturday, March 8th, 2008

W32.Blaster.Worm is a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. This worm attempts to download and run the Msblast.exe file. http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html W32.Blaster.Worm Removal Tool

New computer worm disguises itself as an e-mail from Microsoft

Saturday, March 8th, 2008

Antivirus vendors have warned about new computer worm which pretends to have been sent by Microsoft technical support. The e-mail containing the worm, dubbed Palyh (pronounced Pale-H) or Mankx, appears to come from [email protected], but is not from the software company. It contains a file which, upon execution, copies itself to ...