New Email Virus

Thanks Gary, I'll make sure our NT people know of the 4160 patch.

Here's some info that might be of interest.

IDG News Service, 09/18/01

A new worm that can infect all 32-bit Windows computers and
propagates using multiple methods spread across the world Tuesday
morning, according to Roger Thompson, technical director of malicious
code at TruSecure.

The worm, called Nimda (admin spelled backwards), can spread via e-
mail attachments, HTTP or across shared hard disks inside networks,
Thompson said. The worm can infect all 32-bit Windows systems -
Windows 98, 2000, Millennium Edition, XP, NT - because it scans
systems for between 10 and 100 different vulnerabilities and exploits
them when found, he said.

"It looks like they've made a Swiss Army knife," Thompson said,
referring to the number of different tools the worm can use to attack
systems.

"Every Win32 system is going to be vulnerable, if not from one
(vulnerability), then from another," he said.

When spread by e-mail, Nimda arrives in inboxes as an attachment
called "Readme.exe" or sometimes Readme.eml, Thompson said. The
Readme file, however, has a malformed header (the data at the
beginning of a file that allows a system to identify its type) which
makes the computer think it is a WAV, or sound, file, he said.
However, Readme.exe is in fact a program and can be executed just
from the preview panel when viewing it without it being opened, he
said.

Once the worm has infected a system, be it by HTTP, e-mail or disk
sharing, it then scans its local subnet looking for vulnerable
systems, Thompson said. Though some systems - such as those that are
up to date on their patches, are protected behind firewalls or are
filtering .exe attachments - will be safe from some aspects of the
worm, and the fact that it spreads via three methods makes it more
difficult to stop, he said. The spread of the worm across shared
disks, which are more than likely entirely unprotected, "is going to
be a real pain," he said.

The worm was discovered by Thompson's worldwide network of "worm
catcher" systems at 9:08 a.m. ET Tuesday, he said. Within half an
hour, it had spread across the whole world, he said.

"(Nimda) is certainly much faster, much more aggressive and much
bigger" than Code Red, Thompson said. Code Red was another recent
worm that caused a good deal of damage and consternation for systems
administrators worldwide.

Though Code Red did not ultimately have an impact on Internet
performance despite some initial claims to the contrary, "we may
actually see a hit on the Internet (and its performance)" with Nimda,
Thompson said.

Computer security bodies the Computer Emergency Response
Team/Coordination Center and Incidents.org both issued alerts about
increased activity on the Internet Tuesday, stating that the activity
may be related to the worm.

The spread of Nimda comes after warnings from a number of groups
saying that attacks on networks and Web sites were possibilities
after last Tuesday's terrorist attacks against New York and the
Pentagon, outside of Washington, D.C.

Though Thompson declined to comment on a possible connection between
this worm and those attacks, saying it was inappropriate, the
advisory released by TruSecure said, "we cannot discount the
coincidence of the date and time of release, exactly one week to
(probably to the minute) as the World Trade Center attack."

The IDG News Service is a Network World affiliate.


--- In vantage@y..., "Gary Polvinale" <garyp@d...> wrote:
> To the guy who created this virus...
>
> You had better hope that you never get caught. You definitely
picked the
> wrong time to be playing games with the data communications of the
free
> world. Unlike the corporate recruiting of most hackers that goes
on when
> they get caught, I believe you can expect to be drawn and
quartered - after
> the really bad stuff is done to you. And for a real treat, we
could have
> the government turn you loose in the streets of New York with a 30
second
> head start.
>
> Gary
We were hit this morning by "W32 Nimda". Symantec knows about it but
no fix that we've heard.

Anyone have any info?

Lonnie
I recieved an e-mail containing garbage characters in the subject and body,
and the attachment

"cfgwiz32.exe"

This filename has been linked to at least two or three known viruses, but it
got through our Norton Corporate setup on the exchange server, and on my
client, even after I manually scanned the file.

What was the name of the attachment in your virus, Lonnie?

-----Original Message-----
From: Lonnie Drew [mailto:lonniedrew@...]
Sent: Tuesday, September 18, 2001 4:41 PM
To: vantage@yahoogroups.com
Subject: [Vantage] New Email Virus


We were hit this morning by "W32 Nimda". Symantec knows about it but
no fix that we've heard.

Anyone have any info?

Lonnie



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
Here is the text of a message I received from McAfee (who does have a fix):
McAfee ASaP VIRUS ALERT

===================================================================

The W32/Nimda@MM virus has been identified

====================================================================

The W32/Nimda@MM virus, with a classified subtype of an Internet worm, began
propagating rapidly on September 18, 2001, and has been assessed as a HIGH
RISK threat. Continue to read McAfee ASaP virus updates on W32/Nimda@MM at
http://hq.mcafeeasap.com/dispVirus.asp?virus_k=99209.

This is a mass-mailing worm, which also spreads via open shares and a
Microsoft Web Folder Transversal vulnerability. Upon execution, this worm
may attempt to compromise IIS Web servers using a known Unicode Web
Traversal vulnerability.

The email attachment name appears to be limited to Readme.exe and uses the
icon for an Internet Explorer HTML document. The virus contains the string:
Concept Virus (CV) V.5, Copyright (C) 2001 R.P.China. This worm has the
ability to cause a significant increase in HTTP traffic, which can result in
a denial of service attack.

Use the provided McAfee Extra Dats for detection and removal.

Extra.Dat: http://download.nai.com/products/mcafee-avert/minda.zip

SDatMinda.Exe: http://download.nai.com/products/mcafee-avert/sdatminda.exe

Sincerely,

McAfee ASaP

======================
Steve Sanders
Delta Centrifugal Corp

-----Original Message-----
From: Thad Jacobs [mailto:tjacobs@...]
Sent: Tuesday, September 18, 2001 4:46 PM
To: vantage@yahoogroups.com
Subject: RE: [Vantage] New Email Virus


I recieved an e-mail containing garbage characters in the subject and
body,
and the attachment

"cfgwiz32.exe"

This filename has been linked to at least two or three known viruses, but
it
got through our Norton Corporate setup on the exchange server, and on my
client, even after I manually scanned the file.

What was the name of the attachment in your virus, Lonnie?

-----Original Message-----
From: Lonnie Drew [mailto:lonniedrew@...]
Sent: Tuesday, September 18, 2001 4:41 PM
To: vantage@yahoogroups.com
Subject: [Vantage] New Email Virus


We were hit this morning by "W32 Nimda". Symantec knows about it but
no fix that we've heard.

Anyone have any info?

Lonnie



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must
have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/


Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must
have already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service.



[Non-text portions of this message have been removed]
Thad,

I'm not sure how it got through, or what file started this.

The description matches that at
www.symantec.com/avcenter/venc/data/w32.nimda.a/mm.html (if I read
the handwriting of the web address correctly). Evidently the virus
will immediately prompt to open an attachment with an ".EML"
extension. It replicated itself to 78kb files with EML extension,
2000+ on one machine. Also infected DLLs.

Just received a fix for 95/98/2000- this one didn't work on NT.

Lonnie


--- In vantage@y..., Thad Jacobs <tjacobs@k...> wrote:
> I recieved an e-mail containing garbage characters in the subject
and body,
> and the attachment
>
> "cfgwiz32.exe"
>
> This filename has been linked to at least two or three known
viruses, but it
> got through our Norton Corporate setup on the exchange server, and
on my
> client, even after I manually scanned the file.
>
> What was the name of the attachment in your virus, Lonnie?
>
> -----Original Message-----
> From: Lonnie Drew [mailto:lonniedrew@c...]
> Sent: Tuesday, September 18, 2001 4:41 PM
> To: vantage@y...
> Subject: [Vantage] New Email Virus
>
>
> We were hit this morning by "W32 Nimda". Symantec knows about it
but
> no fix that we've heard.
>
> Anyone have any info?
>
> Lonnie
>
>
>
> Useful links for the Yahoo!Groups Vantage Board are: ( Note: You
must have
> already linked your email address to a yahoo id to enable access. )
> (1) To access the Files Section of our Yahoo!Group for Report
Builder and
> Crystal Reports and other 'goodies', please goto:
> http://groups.yahoo.com/group/vantage/files/.
> (2) To search through old msg's goto:
> http://groups.yahoo.com/group/vantage/messages
> (3) To view links to Vendors that provide Vantage services goto:
> http://groups.yahoo.com/group/vantage/links
>
> Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
>Just received a fix for 95/98/2000- this one didn't work on NT.

Its nice to know that upgrading an NT workstation 2000 now opens it up to 9x
based viruses.....

-----Original Message-----
From: Lonnie Drew [mailto:lonniedrew@...]
Sent: Tuesday, September 18, 2001 5:00 PM
To: vantage@yahoogroups.com
Subject: [Vantage] Re: New Email Virus


Thad,

I'm not sure how it got through, or what file started this.

The description matches that at
www.symantec.com/avcenter/venc/data/w32.nimda.a/mm.html (if I read
the handwriting of the web address correctly). Evidently the virus
will immediately prompt to open an attachment with an ".EML"
extension. It replicated itself to 78kb files with EML extension,
2000+ on one machine. Also infected DLLs.

Just received a fix for 95/98/2000- this one didn't work on NT.

Lonnie


--- In vantage@y..., Thad Jacobs <tjacobs@k...> wrote:
> I recieved an e-mail containing garbage characters in the subject
and body,
> and the attachment
>
> "cfgwiz32.exe"
>
> This filename has been linked to at least two or three known
viruses, but it
> got through our Norton Corporate setup on the exchange server, and
on my
> client, even after I manually scanned the file.
>
> What was the name of the attachment in your virus, Lonnie?
>
> -----Original Message-----
> From: Lonnie Drew [mailto:lonniedrew@c...]
> Sent: Tuesday, September 18, 2001 4:41 PM
> To: vantage@y...
> Subject: [Vantage] New Email Virus
>
>
> We were hit this morning by "W32 Nimda". Symantec knows about it
but
> no fix that we've heard.
>
> Anyone have any info?
>
> Lonnie
>
>
>
> Useful links for the Yahoo!Groups Vantage Board are: ( Note: You
must have
> already linked your email address to a yahoo id to enable access. )
> (1) To access the Files Section of our Yahoo!Group for Report
Builder and
> Crystal Reports and other 'goodies', please goto:
> http://groups.yahoo.com/group/vantage/files/.
> (2) To search through old msg's goto:
> http://groups.yahoo.com/group/vantage/messages
> (3) To view links to Vendors that provide Vantage services goto:
> http://groups.yahoo.com/group/vantage/links
>
> Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
McAfee's latest signature file 4160 that we downloaded last night contains
the fix.

Gary Polvinale
Denton ATD

-----Original Message-----
From: Thad Jacobs [mailto:tjacobs@...]
Sent: Tuesday, September 18, 2001 7:05 PM
To: 'vantage@yahoogroups.com'
Subject: RE: [Vantage] Re: New Email Virus


>Just received a fix for 95/98/2000- this one didn't work on NT.

Its nice to know that upgrading an NT workstation 2000 now opens it up to 9x
based viruses.....

-----Original Message-----
From: Lonnie Drew [mailto:lonniedrew@...]
Sent: Tuesday, September 18, 2001 5:00 PM
To: vantage@yahoogroups.com
Subject: [Vantage] Re: New Email Virus


Thad,

I'm not sure how it got through, or what file started this.

The description matches that at
www.symantec.com/avcenter/venc/data/w32.nimda.a/mm.html (if I read
the handwriting of the web address correctly). Evidently the virus
will immediately prompt to open an attachment with an ".EML"
extension. It replicated itself to 78kb files with EML extension,
2000+ on one machine. Also infected DLLs.

Just received a fix for 95/98/2000- this one didn't work on NT.

Lonnie


--- In vantage@y..., Thad Jacobs <tjacobs@k...> wrote:
> I recieved an e-mail containing garbage characters in the subject
and body,
> and the attachment
>
> "cfgwiz32.exe"
>
> This filename has been linked to at least two or three known
viruses, but it
> got through our Norton Corporate setup on the exchange server, and
on my
> client, even after I manually scanned the file.
>
> What was the name of the attachment in your virus, Lonnie?
>
> -----Original Message-----
> From: Lonnie Drew [mailto:lonniedrew@c...]
> Sent: Tuesday, September 18, 2001 4:41 PM
> To: vantage@y...
> Subject: [Vantage] New Email Virus
>
>
> We were hit this morning by "W32 Nimda". Symantec knows about it
but
> no fix that we've heard.
>
> Anyone have any info?
>
> Lonnie
>
>
>
> Useful links for the Yahoo!Groups Vantage Board are: ( Note: You
must have
> already linked your email address to a yahoo id to enable access. )
> (1) To access the Files Section of our Yahoo!Group for Report
Builder and
> Crystal Reports and other 'goodies', please goto:
> http://groups.yahoo.com/group/vantage/files/.
> (2) To search through old msg's goto:
> http://groups.yahoo.com/group/vantage/messages
> (3) To view links to Vendors that provide Vantage services goto:
> http://groups.yahoo.com/group/vantage/links
>
> Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
To the guy who created this virus...

You had better hope that you never get caught. You definitely picked the
wrong time to be playing games with the data communications of the free
world. Unlike the corporate recruiting of most hackers that goes on when
they get caught, I believe you can expect to be drawn and quartered - after
the really bad stuff is done to you. And for a real treat, we could have
the government turn you loose in the streets of New York with a 30 second
head start.

Gary

-----Original Message-----
From: Thad Jacobs [mailto:tjacobs@...]
Sent: Tuesday, September 18, 2001 7:05 PM
To: 'vantage@yahoogroups.com'
Subject: RE: [Vantage] Re: New Email Virus


>Just received a fix for 95/98/2000- this one didn't work on NT.

Its nice to know that upgrading an NT workstation 2000 now opens it up to 9x
based viruses.....

-----Original Message-----
From: Lonnie Drew [mailto:lonniedrew@...]
Sent: Tuesday, September 18, 2001 5:00 PM
To: vantage@yahoogroups.com
Subject: [Vantage] Re: New Email Virus


Thad,

I'm not sure how it got through, or what file started this.

The description matches that at
www.symantec.com/avcenter/venc/data/w32.nimda.a/mm.html (if I read
the handwriting of the web address correctly). Evidently the virus
will immediately prompt to open an attachment with an ".EML"
extension. It replicated itself to 78kb files with EML extension,
2000+ on one machine. Also infected DLLs.

Just received a fix for 95/98/2000- this one didn't work on NT.

Lonnie


--- In vantage@y..., Thad Jacobs <tjacobs@k...> wrote:
> I recieved an e-mail containing garbage characters in the subject
and body,
> and the attachment
>
> "cfgwiz32.exe"
>
> This filename has been linked to at least two or three known
viruses, but it
> got through our Norton Corporate setup on the exchange server, and
on my
> client, even after I manually scanned the file.
>
> What was the name of the attachment in your virus, Lonnie?
>
> -----Original Message-----
> From: Lonnie Drew [mailto:lonniedrew@c...]
> Sent: Tuesday, September 18, 2001 4:41 PM
> To: vantage@y...
> Subject: [Vantage] New Email Virus
>
>
> We were hit this morning by "W32 Nimda". Symantec knows about it
but
> no fix that we've heard.
>
> Anyone have any info?
>
> Lonnie
>
>
>
> Useful links for the Yahoo!Groups Vantage Board are: ( Note: You
must have
> already linked your email address to a yahoo id to enable access. )
> (1) To access the Files Section of our Yahoo!Group for Report
Builder and
> Crystal Reports and other 'goodies', please goto:
> http://groups.yahoo.com/group/vantage/files/.
> (2) To search through old msg's goto:
> http://groups.yahoo.com/group/vantage/messages
> (3) To view links to Vendors that provide Vantage services goto:
> http://groups.yahoo.com/group/vantage/links
>
> Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/



Useful links for the Yahoo!Groups Vantage Board are: ( Note: You must have
already linked your email address to a yahoo id to enable access. )
(1) To access the Files Section of our Yahoo!Group for Report Builder and
Crystal Reports and other 'goodies', please goto:
http://groups.yahoo.com/group/vantage/files/.
(2) To search through old msg's goto:
http://groups.yahoo.com/group/vantage/messages
(3) To view links to Vendors that provide Vantage services goto:
http://groups.yahoo.com/group/vantage/links

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
According to some reports, this virus surfaced, within seconds of the time
of last weeks attack. I personally believe, there is a link.

Shirley H. Graver
(End User)
Systems Administrator
Rubber Associates Inc.



[Non-text portions of this message have been removed]