Alerte Virus watch


Securelist / Active Alerts

Securelist / Alerts

  • MS08-067) in Microsoft Windows to spread via local networks and removable storage media.

    The worm disables system restore, blocks access to security websites, and downloads additional malware to infected machines.

    Users are strongly recommended to ensure their antivirus databases are up to date. A patch for the vulnerability is available from Microsoft.

    Detailed descriptions of Net-Worm.Win32.Kido.bt, Net-Worm.Win32.Kido.dv and Net-Worm.Win32.Kido.fx are available in the Virus Encyclopaedia. A dedicated removal tool is available here.]]>">Net-Worm.Win32.Kido

  • Virus.Win32.Gpcode.ak.

    The new Gpcode variant encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key.

    After encrypting files, the virus leaves a text file in the folder next to the encrypted files with following message:

    Your files are encrypted with RSA-1024 algorithm.
    To recovery your files you need to buy our decryptor.
    To buy decrypting tool contact us at: ********@yahoo.com

    Currently, we detect the new variant, but we are unable to crack the 1024-bit key. Our analysts are continuing to work on both the key and the virus to resolve this issue.

    Kaspersky Lab recommends that all Internet users enable maximum protection from malicious code and network attacks on their computers, refrain from executing suspicious programs received from untrustworthy sources and back up any important information on their computers.

    Detection of Virus.Win32.Gpcode.ak was added to Kaspersky Anti-Virus signature databases yesterday, on June 4th, at 15:39 GMT. Please make sure to update if you haven’t already.

    If you have fallen victim to Gpcode.ak, try to contact us using another computer connected to the Internet. DO NOT RESTART or POWER DOWN the potentially infected machine. Contact us by email stopgpcode@kaspersky.com and tell us the exact date and time of infection, as well everything you did on the computer in the 5 minutes before the machine was infected: which programs you have executed, which websites you have visited, etc. We'll try and help you recover any data that has been encrypted.

    For more information about the malicious program, please read our weblog.]]>">Virus.Win32.Gpcode.ak

  • Email-Worm.Win32.Warezov.nf is now available in the Virus Encyclopaedia.]]>">Email-Worm.Win32.Warezov.nf
  • Email-Worm.Win32.Warezov.mx
  • Email-Worm.Win32.Warezov.ms
  • Zhelatin.u, Zhelatin.r and Zhelatin.t

    New variants may be functionally similar to each other and to previous variants.

    Users are reminded to keep their antivirus protection up to date, and to scan any suspicious emails with an antivirus solution.

    If you are using Kaspersky Anti-Virus or Kaspersky Internet Security 6.0, enable Proactive Protection, and new variants will be detected without the need to update antivirus databases.

    A detailed description of Email-Worm.Win32.Zhelatin.o is available in the Virus Encyclopaedia.]]>">Email-Worm.Win32.Zhelatin

  • Email-Worm.Win32.Zhelatin.u
  • Email-Worm.Win32.Zhelatin.r
  • Zhelatin.a.

    The Kaspersky anti-virus databases have been updated and users are recommended to update as soon as possible.

    Possible subjects in infected emails:

    • I Always Knew
    • I Am Lost In You
    • I Believe
    • I Can't Function
    • I Dream of you
    • I Give to You
    • I Love Thee
    • I Love You Mower
    • I Love You So
    • I Love You Soo Much
    • I Love You with All I Am
    • I Still Love You
    • I Think of You
    • I Win with You
    • I Woof You

    Possible names for attachments containing the body of the worm:

    • Postcard.exe
    • flash postcard.exe
    • greeting card.exe
    • greeting postcard.exe

    Possible texts in the emails:

    • You + Me
    • You Are My Guiding Star
    • You Asked Me Why
    • You Brighten My Day
    • You Lucky Duck!
    • You Rock Me!
    • You Were Worth the Wait
    • You and I
    • You and I Forever
    • You are out of this world
    • You're My Hero
    • You're Soo kissable
    • You're so Far Away
    • You're the One
    • Your Love Has Opened
    • Your Silly Smile
    • flash postcard.exe
    • greeting card.exe
    • greeting postcard.exe

    A detailed description of Email-Worm.Win32.Zhelatin.o is now available in the Kaspersky Virus Encyclopaedia.]]>">Email-Worm.Win32.Zhelatin.o

  • Email-Worm.Win32.Warezov
Securelist / Descriptions

iddn © 1997-2010 - Eur'Net - F 27220 LA BOISSIERE
Maj - V 3.3.3.0
(Protection des données personnelles)