Latest computer news. Enjoy --Ric
************************************************************* V I R U S R E P O R T (By Trend US Virus Research Group) ************************************************************* ------------------------------------------------------------- Date: 08.17.99 Issue: 8.3 ------------------------------------------------------------- Issue Preview: The Christmas/Grinch Virus, Jokes that are not funny, 10 Most Prevalent In-The-Wild Viruses, Top 10 Viruses Trend US Customers are concerned about, How to Give a Cat a Colonic HOAX, Bug's Life HOAX, X97M_EX-LAX. ************************************************************* 1. The Grinch that Stole Computer Data ------------------------------------------------------------- PE_KRIZ is a polymorphic and memory-resident virus, infecting all Win 32 executable files (*.EXE and *.DLL). It has a destructive payload that will be activated on Christmas day, December 25. When executed it will destroy the CMOS memory, the Flash BIOS and all files in all drives by overwriting data on them. In this sense, it is more destructive than the PE_CIH virus. When an infected program file is executed, the virus first infects the file KERNELL32.DLL and becomes memory resident for the whole Windows session. Every time Windows is started thereafter, the virus will be memory resident immediately and infect every Win 32 program executed. For more information on the virus, please see our web site at: http://www.antivirus.com/vinfo/security/sa08199.htm Our pattern file 574 can detect the virus. 2. Jokes that are not funny -------------------------------------------------------------- In recent month we have received many programs which look like viruses, yet do not contain any harmful payloads. Instead, they perform functions such as opening the CD and shaking the screen. Some programs even visually pretend to delete files or reformat the hard drive. While there is no actual threat to data, users often fear these phony virus alerts. To help our customers, we are proud to offer detection for these jokes. They can easily be identified by their name prefix, which is JOKE_. (Example: JOKE_WOW). To read about the most recent Joke programs, please visit our website at: http://www.antivirus.com/vinfo/virusencyclo/default3.asp?VCode=EN001319 for Joke_Wow) http://www.antivirus.com/vinfo/virusencyclo/default3.asp?VCode=30000002 for Joke_Geschenk) http://www.antivirus.com/vinfo/virusencyclo/default3.asp?VCode=30000189 for Joke_Wobbling) 3. 10 Most Prevalent In-The-Wild Viruses Surveyed by Trend US (week of: 08/09/99 to 08/15/99) -------------------------------------------------------------- 1. TROJ_SKA 2. W97M_ETHAN 3. JOKE_WOW 4. TROJ_GESCHENK 5. JOKE_WOBBLING 6. TROJ_DOH 7. NE_AOL_TROJAN.CJ 8. NE_SMALL_JOKE 9. PE_CIH 10. W97M_CLASS For the most prevalent viruses for the month of July'99, please visit our website at: http://www.antivirus.com/vinfo/most_prevalent.htm 4. Top 10 Viruses Customers are most Concerned About (where systems were not infected) -------------------------------------------------------------- 1. VBS_MONOPOLY 2. WOBBLER/CALIFORNIA Hoax 3. W97M_JACK_BOX 4. PE_CIH 5. TROJ_CATFOD.A 6. JOKE_WOBBLING 7. TROJ_SKA 8. TROJ_BARJAM 9. JOKE_GESCHENK 10. JOIN A CREW Hoax 5. How to Give a Cat a Colonic: Another HOAX -------------------------------------------------------------- This new hoax warns users about an email message with the subject: "HOW TO GIVE A CAT A COLONIC, DO NOT OPEN IT!!!!!!!!" This warning is a hoax and we advise all our customers not to distribute it to others. For details on this hoax, please visit our website at: http://www.trend.com/vinfo/hoaxes/cat_colonic.htm 6. Fact or Fiction: (or Bug's Life -- BUGGLST.ZIP HOAX) -------------------------------------------------------------- Another email hoax forwarded to us warns users about the Bug's Life screen saver. In addition, it tries to warn people not to run certain executables. While most of the warning is fiction, some of the executables mentioned in the bottom section are known to be carriers of known viruses. For example, the Happy99.exe file is known to be infected with the PE_SKA virus (also known as Happy99 virus). We advise users not to run executables that have not been scanned with the latest Trend pattern file. For additional information about this hoax, please visit our website at: http://www.trend.com/vinfo/hoaxes/bugs_life.htm 7. X97M_EX-LAX (a.k.a. X97M/Xal.A) -------------------------------------------------------------- Also reported this month was X97M_EX-LAX. This new Excel 97 infector is very simple and does not contain any payload. It infects files in the list of recently used files, as well as all other already opened workbooks. Since the X97_EX-LAX virus was distributed via email and is available on a publicly accessible website, we want to inform our customers that Trend pattern file 573 or later detects and cleans this virus. For additional virus information, please visit our website at: http://www.antivirus.com/vinfo/virusencyclo/default3.asp?VCode=30000286 8. Trend Virus Report Subscribers, get a 10% rebate on PC-cillin6 -------------------------------------------------------------- As a subscriber to this newsletter, Trend Micro would like to extend you a 10% discount on our top-rated desktop virus package, PC-cillin Give your desktop the best protection around, at a full 10% off either the download shipping copies. To buy PC-cillin at a discount, please visit our website at: For Windows 95-98 http://www.antivirus.com/offers/vb.htm For Windows NT http://www.antivirus.com/offers/vbnt.htm ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ If you would like to subscribe to this newsletter, go to : http://www.antivirus.com/subscriptions/sub_vreport.asp?[EMAIL PROTECTED] To unsubscribe to this newsletter, go to : http://www.antivirus.com/subscriptions/un_vreport.asp?[EMAIL PROTECTED] ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
