Virus Advisory:
The Sasser worm spreads with the file name: avserve2.exe . Unlike many recent worms, this virus does not spread via email. No user intervention is required to become infected or propagate the virus further. The worm works by instructing vulnerable systems to download and execute the viral code.
W32/Mydoom@MM (MyDoom) :
This is a mass-mailing and peer-to-peer file-sharing worm that bears the following characteristics:
contains its own SMTP engine to construct outgoing messages
contains a backdoor component and
a Denial of Service payload.
More info...
W32/Bagle@MM : This is a mass-mailing worm with a remote access component.
Click for info ...
Lovsan MSBlast worm: The purpose of this worm is to spread to as many machines as possible. By exploiting an unplugged hole in Windows, it is able to execute without requiring any action on the part of the user. The worm also creates a remote access point, allowing an attacker to run system commands at their choosing.
Get removal info at
McAfee
A new variant of the Bugbear virus,
W32/Bugbear.b@MM is a
HIGH RISK mass-mailing worm that contains numerous malicious elements, including a keylogger, network share propagator, remote access trojan, polymorphic parasitic file infector and terminator of security software. Find out more at
McAfee
.
W32/Fizzer@MM is a MEDIUM-ON-WATCH mass-mailing worm, which spreads by emailing itself to addresses in your Windows Address Book and others on your PC. It tries to terminate your AV software, contains a keylogger and attempts to spread using other programs, including IRC, AIM and Kazaa. It arrives as an executable email attachment, requiring users to double-click on the file to become infected.
W32/Klez.h@MM :
This worm mails itself to email addresses in the Windows Address Book, plus addresses extracted from files on the victim machine. It arrives in an email message whose subject and body is composed from a pool of strings carried within the virus.
For more virus info, and removal software visit
McAfee
W32/Nimda@MM : This virus
can infect all unprotected users of Win9x/NT/2000/ME.
W32/Nimda@MM is a HIGH RISK virus that is spread via email. The infected email can come from addresses that you recognize. It also spreads via open shares, the Microsoft Web Folder Transversal vulnerability (also used by W32/CodeBlue), and a Microsoft content-type spoofing vulnerability. The email attachment name varies and may use the icon for an Internet Explorer HTML document.
Once infected, your system is used to seek out others to infect over the web. As this creates a lot of port scanning, this can cause a network traffic jam. To protect against this virus, or to find out more about W32/Nimda, Sircam, Badtrans, Goner, Zacker and other viruses and worms visit McAfee.com