new worm in the wild

Discussion in 'malware problems & news' started by SecurityTech, Jun 13, 2004.

Thread Status:
Not open for further replies.
  1. SecurityTech

    SecurityTech Registered Member

    Joined:
    Oct 4, 2003
    Posts:
    8
    I'm trying to find some information about a new worm, or variation of an old worm that is out in the wild. Here is what I know.

    I personally have received three different suspicious e-mails today each with different formats and attachments (.att, .pif, and a .com).

    I became aware of this as my brother says he got infected from my aunt. The attachment he opened from her was a .pif... my e-mail from her was entirely different, with a .att attachment. My cousin got infected from the same aunt but the format of the e-mail was different than what my brother got and what I received.

    This is a mass mailing worm. Both my brother and cousin are inundated with delivery notifications.

    Norton did not catch this.
    AVG doesn't catch this.
    Housecall at Trendmicro doesn't catch this.
    TDS-3 doesn't catch this.

    I have scanned all three attachments that I have with these programs and found nothing.

    This worm also appears to disable NAV and it does not spoof the return address (at least not in the cases I've seen).

    How can I help these people clean a virus that I can't identify?

    What's the best way to submit these files to the appropriate people so these programs will pick up on it?
     
  2. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,475
    Location:
    The Netherlands
    SecurityTech,

    Please zip/RAR the files in question (password protected) and attach them to an email to me (my addy is in my profile - left bottom corner). I'll make sure it will be analyzed and submitted to all major AV/AT companies and provide results.

    regards.

    paul
     
  3. SecurityTech

    SecurityTech Registered Member

    Joined:
    Oct 4, 2003
    Posts:
    8
    Thanks Paul

    I've sent that off. I appreciate the help.
     
  4. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,475
    Location:
    The Netherlands
    My pleasure ;)

    regards.

    paul
     
  5. Stephan123

    Stephan123 Registered Member

    Joined:
    May 15, 2004
    Posts:
    135
    Location:
    The netherlands
    can you send me the samples to? my mailadress ****f3@xs4all.nl
     
    Last edited by a moderator: Jun 13, 2004
  6. SecurityTech

    SecurityTech Registered Member

    Joined:
    Oct 4, 2003
    Posts:
    8
    new update.

    AVG now identifies these files. The virus database 461 for 6/12/2004 identifies this as I-worm/Zafi.B

    Housecall and TDS-3 still don't pick this up.

    AVG doesn't identify the .ATT file... not entirely sure that it is a virus... but the whole e-mail was suspicious. Still checking it out.
     
  7. gerardwil

    gerardwil Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    4,748
    Location:
    EU
  8. Stephan123

    Stephan123 Registered Member

    Joined:
    May 15, 2004
    Posts:
    135
    Location:
    The netherlands
    Zafi.B in my email :eek:
     
  9. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    http://www.f-secure.com/v-descs/zafi_b.shtml
    http://www.f-secure.com/news/items/news_2004061400.shtml
    Good description and special cleaners.
    Had emails with them already on the 11th, so i started searching for info by then already.
    Part of the results are the many emails we also get with a line telling there is an urgent voicemal waiting or just a link withough further words. Probably from infected users spitting out thir "joy", but fortunately without the infection itself.
    I hope for the webmasters of the sites named are innocent of al the accusitions seen in their guestbooks.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.