Trend Micro Weekly Virus Report - August 30, 2002

From: Trend Micro Virus Info <VirusInfo_at_trendmicro-newsletters.com>
Date: Sat 31 Aug 2002 - 02:30:45 CEST
Message-ID: <0dd974530001f82BLACKBOX4@blackbox4>

*********************************************************************
TREND MICRO WEEKLY VIRUS REPORT
    
(by TrendLabs Global Antivirus and Research Center)
*********************************************************************
------------------------------------------------------------------------
Date: August 30, 2002
------------------------------------------------------------------------
To read an HTML version of this newsletter, go to:
http://www.trendmicro.com/trendsetter/virus_report/

Issue Preview:

1. Trend Micro Updates - Pattern File, Scan Engine, and Antispam Updates
2. I Have a Hunch - WORM_HUNCH.A (Low Risk)
3. 10 Most Prevalent In-the-Wild Malware Surveyed by Trend Micro US
4. FREE Virus Scan - Clean your PC Online with Trend Micro's HouseCall

NOTE: Long URLs may break into two lines in some mail readers.
Should this occur, please copy and paste the URL into your browser window.

************************************************************************

1. Trend Micro Updates - Pattern File, Scan Engine, and Antispam Updates
------------------------------------------------------------------------
PATTERN FILE: 339 http://www.trendmicro.com/download/pattern.asp
SCAN ENGINE: 6.150 http://www.trendmicro.com/download/engines/
ANTISPAM RELEASES: 324, 325, 326, 327, 328, 329, 330, 331, 332, 333, 334,
335, 336, 337

2. I Have a Hunch - WORM_HUNCH.A (Low Risk)
------------------------------------------------------------------------
WORM_HUNCH.A is a destructive worm that disguises itself by using the JPEG file icon. It sends copies of itself using Messaging Application Programming Interface (MAPI) to all addresses in the infected user's Microsoft Outlook address book. The email arrives with the following details:

Subject: <No Subject Line>
Body: Mensaje importante para <Recipient Name> en el archivo adjunto
Attachment: <Worm Copy>

This worm deletes files located in the following directories:

Windows and its subfolders
Program Files and its subfolders
My Documents and its subfolders

It may also drop copies of itself in the Windows system directory using any of the following filenames:

CORA.EXE
SALSA.EXE
MSWORD.EXE
LOCAS.EXE
LORY.EXE
DEJAS.EXE
SEXO.EXE

This worm's destructive payload deletes up to five files with the same file extensions. It deletes files with the following extensions:

XLS
DOC
WAV
ASM
MPG
BAT
CDX
JPG
HTM
HLP
CHM
RPG
GIF
SCR
TTF
MID
MDB
DBF
ICO

If you would like to scan your computer for WORM_HUNCH.A or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free online virus scanner at: http://housecall.antivirus.com/

WORM_HUNCH.A is detected and cleaned by Trend Micro pattern file #338 and above.

For additional information about WORM_HUNCH.A please visit: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_HUNCH.A

3. 10 Most Prevalent In-the-Wild Malware Surveyed by Trend Micro US
(week of: August 19, 2002 to August 25, 2002)
------------------------------------------------------------------------
1. WORM_KLEZ.H
2. JS_NOCLOSE.A
3. JS_NOCLOSE.E
4. WORM_YAHA.E
5. JS_EXCEPTION.GEN
6. WORM_BADTRANS.B
7. REG_STARTPAGE.A
8. BKDR_NEWBIERO.A
9. PE_NIMDA.E
10. PE_MAGISTR.B
 
4. FREE Virus Scan - Clean your PC Online with Trend Micro's HouseCall
------------------------------------------------------------------------
Get a quick checkup with HouseCall, Trend Micro's online virus scanner, to see if a computer virus, worm, or Trojan has infected your system. HouseCall scans your computer for new infections and detects, cleans, and removes viruses for FREE. Try it now:

http://housecall.antivirus.com/housecall/start_corp.asp

Note: HouseCall is a one-time, manual virus scanner and does not provide you with continuous protection from viruses. For complete continuous protection, we recommend Trend Micro PC-cillin 2002.

To buy PC-cillin online** visit: http://www.digitalriver.com/dr/v2/ec_MAIN.Entry10?xid=16269&SP=10034&PN=1&V1=889300

**applies to customers in the U.S. and Canada only.

************************************************************************
You are receiving this email from Trend Micro, because you have either
downloaded a Trend Micro product or have signed up to receive the "Weekly Virus
Report." If you would like to change the way you receive email from
Trend Micro, please make changes in your account page at
http://www.trendmicro.com/subscriptions/default.asp?email=trendmicro_pattern@netzwerk-aktiv.com
 
To UNSUBSCRIBE go to:
http://www.trendmicro.com/subscriptions/default.asp?format=unsubscribe
 
For questions, comments, and suggestions about the Weekly Virus Report
please contact the Newsletters Editor at newsletters@trendmicro.com.
************************************************************************
Received on Sat Aug 31 02:15:26 2002

This archive was generated by hypermail 2.1.8 : Mon 29 May 2006 - 05:33:31 CEST