2006-05-18 11:02 Age: 6 yrs

[Virus Alert] 2 new worms found

Worm name: WORM_ARESES.AC

Risk rating: HIGH

Damage Potential: HIGH

Distribution Potential: HIGH

 

Description:

This worm spreads by attaching a copy of itself to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

 

The use of its own SMTP engine improves the propagation method of this worm since it does not require other messaging applications to send the email message described below:

 

Note that the file it attempts to download may change any time.

 

 

Worm name: TROJ_YABE.G

Risk rating: HIGH

Damage Potential: HIGH

Distribution Potential: HIGH

 

Description:

This Trojan usually arrives on a system as an attachment to spammed email messages. Users should therefore refrain from opening email messages that come from untrusted sources.

 

When executed, it drops the file ipf.exe in the Windows system folder. It adds a registry entry pointing to the said file so that it runs at every Windows startup.

 

This Trojan waits for an active Internet connection, then attempts to download possibly malicious files from several URLs. This routine may harm the system as routines of the said files may be exhibited on the affected computer.

 

 

 

References: http://www.trendmicro.com/vinfo/ (TrendMirco Virus Security Info)

http://www.trendmicro.com/vinfo/zh-tw/default.asp (Traditional Chinese TrendMicro Virus Security Info






  |    |