Virus Name: ------------------- W32/Sober.k@MM Alias: ------------------- W32/Sober-J WORM_SOBER.J Email-Worm.Win32.Sober.j W32.Sober.J@mm E-mail Subject: ------------------- Ey du DOOF Nase, warum beantw... I've got YOUR email on my account!! E-mail Body: ------------------- (German) Warum beantwortest Du meine E-Mails nicht? Kommen meine Mails nicht mehr bei dir an oder so??? Habe mir jetzt extra...

============================================= Weekly Top 5 Virus Incidents ============================================= The table below lists the top 5 virus and malware files submitted to Computer Associates during the week from January 24 to 30, 2005. 1. Win32.Netsky.P http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=38650 2. Win32.Lovgate.AB http://www3.ca.com/securityadvisor/virusinfo...

LS35 myITforum Code Repository Speaker(s): Ron Crumbaker , Dan Thomson Session Level(s): 400 We are the myITforum version of Microsoft's Scripting Guys! I'm Ron Crumbaker; and this is my partner Dan Thomson! We're going to show you The Code Repository, Various Code Packs for the Code Repository and Various Resources as examples of what we do, and how these will help you in your day to day job. Oh,...

www.autopatcher.com General Information This release is based on the all-new AutoPatcher 5.0. Although it was made with Windows XP SP2 (English) in mind, it will load on any (English) Windows version, showing only the items which match the running environment. For those wondering what the new release includes, here's the list: Windows XP SP2 - Critical Updates KB834707: Cumulative Security Update for...

Misprinted 800 number in some versions of Intuit's TurboTax software sends customers to phone sex operation. http://news.com.com/Taxpayers get unexpected return--sex chat/2100-1012_3-5557315.html?part=rss&tag=5557315&subj=news.1012.5

Senator Hillary Clinton, former first lady, collapses while giving a speech in Buffalo, New York state, US media report. For more details: http://www.bbc.co.uk/news

SUMMARY When you run a Microsoft Jet database engine-based program, such as Microsoft Office Access, on your Microsoft Windows 2000-based or Microsoft Windows XP-based computer, the program may appear slower and less responsive than you expect. This article contains information about how you can optimize network performance for Windows 2000-based and Windows XP-based computers. Doing this can make...

W32/Sober.k@MM contains its own SMTP engine source/target email addresses are harvested from the victim machine outgoing messages maybe in English or German Mail Propagation spoofs the "From" header of constructed messages The worm is packed with UPX. Mail Propagation The worm extracts target email addresses from the victim machine, and writes them to the file DATAMX.DAM in the %SysDir% . For example...

http://secunia.com/advisories/14061/ Secunia Advisory: SA14061 Release Date: 2005-01-31 Critical: Not critical Impact: DoS Where: Local system Solution Status: Unpatched OS: Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows NT 4.0 Server Microsoft Windows NT 4.0 Server, Terminal Server...

We (Dan Thomson and I) are wanting to gather up some more code so we can release another Code Pack for the Code Repository. http://www.myitforum.com/blog/rcrumbaker/archive/2004/12/01/178.aspx - Code Repository Links We are wanting to collect as many scripts as possible so we can get them included in our next Code Packs. If you are willing to share any of your bat, cmd, hta, html, ipf, js, jse, kix...

I've noticed that Spammers for Blogs (at least the two blogs I maintain) upload their SPAM on Sunday Night and/or Saturday Nights. With the way RSS Feeds work, it allows sites such as the Online Poker Sites to get their sites to the top of the Search Engines Lists by SPAMMING links on various Blogs as comments. One good thing about Blogs, as an Admin...I can go in and delete any comment I want. So...

http://www.myitforum.com/blog/rcrumbaker/articles/2768.aspx

Sober up A new Sober variant is going around, sending variable emails with English and German content. This one is also known as "Reblin" or "Email-Worm.Win32.VB.af". Source: http://www.f-secure.com/weblog/#00000455

http://www.microsoft.com/downloads/details.aspx?FamilyID=92a9bb94-1806-487b-a697-92492bf8cc8e&DisplayLang=en Microsoft SMS 2003 Inventory Tool for Dell Update SMS 2003 Inventory Tool for Dell Updates is an add-on to SMS 2003 SP1 that enables customers to use the SMS 2003 Software Update Management feature update their Dell servers. Customers will be able to deploy BIOS, firmware, and driver updates...

Systems Management Server 2003 891999 The Systems Management Server 2003 Toolkit 2 documentation contains incorrect information about the Site Boundary command-line tool The original article on Microsoft.com can be found here. Microsoft Legal Links Terms of use Security & Privacy Accessibility

Systems Management Server 2.0 891778 Additional network traffic may occur when you run the Security Update Inventory Tool or the Microsoft Office Inventory Tool for Updates in a Systems Management Server 2.0 environment

http://www.myitforum.com/blog/rcrumbaker/articles/2690.aspx

http://www.myitforum.com/blog/rcrumbaker/articles/2689.aspx

SQL Server 2000 890637 FIX: A 17883 error is written to the SQL Server 2000 error log and the LogWriter component does not yield correctly 867677 You receive an ODBC error when you use BCP in SQL Server 2000 Systems Management Server 2003 886687 "Failed source list update for product" error message is logged in the Srcupdatemgr.log file on a Systems Management Server 2003 client computer

Great read over at zdnet about MyDoom - http://news.zdnet.com/2100-1009_22-5553419.html?tag=nl.e589 100 Million emails...impressive!!

Got this from neowin.net Windows Update v6 Beta Coming Soon Microsoft Beta co-ordinator, Roger Holland, has just informed current testers of Windows Update v5 that version 6 of the update service is due to hit beta soon. The Windows Update v5 beta ended late last year and Windows Update v5 is the current release that millions of users across the world are using. In an email to testers Holland thanks...

The mass-mailing virus is starting to spread worldwide, antivirus firms have warned. http://news.com.com/Bagle virus makes a return/2100-7349_3-5553360.html?part=rss&tag=5553360&subj=news.7349.5

Online-retailer EBGames becomes first major U.S. retailer to start taking advance orders for Sony's new handheld game machine. http://news.com.com/Pay now, play later with PSP/2100-1043_3-5553223.html?part=rss&tag=5553223&subj=news.1043.5

http://video.google.com/ Just checked it out...not too bad for the few minutes I searched it.

Microsoft Windows Indexing Service query validation vulnerability Microsoft Windows contains a vulnerability that may allow remote attackers to execute arbitrary code. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32230

Microsoft Windows Cursor and Icon format handling vulnerability Microsoft Windows contains a vulnerability that may allow remote attackers to execute arbitrary code. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32219

Microsoft Windows Kernel cursor, animated cursor, and icon format file processing vulnerabilities Microsoft Windows Kernel contains multiple vulnerabilities that can allow remote attackers to cause a denial of service condition. http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32140

W32/Bagle.bj@MM This is a mass-mailing worm with the following characteristics: contains its own SMTP engine to construct outgoing messages harvests email addresses from the victim machine the From: address of messages is spoofed contains a remote access component (notification is sent to hacker) copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications;...

f-secure is reporing Bagle.AY upgraded to level 2 Due to the increased number of reports we just upgraded Bagle.AY to Radar Level 2 Source: http://www.f-secure.com/weblog/#00000452

f-secure.com is reporting Yet another new Bagle variant - Bagle.AY has been found from several different countries early morning on January 27th, 2005 EET. This variant is similar to the last evening Bagle.AX . On 27/01/05 At 08:11 AM Source: http://www.f-secure.com/weblog/#00000451 More Posts Next page »