Expeditions: Samurai veut révolutionner le RPG tactique avec une aventure entièrement jouable en coop
hier j ai entendu k il y avait un nouveau virus donc attention
http://www.hoaxbuster.com
faux, vrais tous savoir là bas!
je te jure il arrive sur paris
bon je vais mailer mes "indics"
moi je m enfout car j ai un anti virus
ctoreppe...tu crois que ton p´tit anti virus fera grand chose selon les virus?
bon entre nous j´espère que tu fais des MAJ journalière
euh...
c un travail a faire manuellement car norton théoriquement de préviens dès qu´y en as c vrai...mais faut-il encore que Norton ne débloque pas(1 fois sur 10)
enfin je sui bien equipe anti virus
t´as norton non?t´as un fire wall?
moi aussi je l ai
up
il est tro puissant le virus donc : mobilisation anti virus
signer ici si vous ete anti virus
Le virus c´est Bugbear.
WORM_BUGBEAR.A?
This worm terminates antivirus processes and propagates by sending itself via email using its own SMTP (Simple Mail Transfer Protocol) engine. It also propagates via shared network folders.
The email that it sends out contains no message body and uses any of the following as its subject:
$150 FREE Bonus!
25 merchants and rising
Announcement
bad news
CALL FOR INFORMATION!
click on this!
Confirmation of Recipes…
Correction of errors
Daily Email Reminder
empty account
fantastic
free shipping!
Get 8 FREE issues - no risk!
Get a FREE gift!
Greets!
hello!
history screen
hmm..
I need help about script!!!
Interesting...
Introduction
its easy
Just a reminder
Lost & Found
Market Update Report
Membership Confirmation
My eBay ads
New bonus in your cash account
New Contests
new reading
Payment notices
Please Help...
Report
SCAM alert!!!
Sponsors needed
Stats
Today Only
Tools For Your Online Business
update
various
Warning!
Your Gift
Your News Alert
It spoofs the FROM field of the email, while the TO field contains addresses obtained from the Windows Address Book (WAB). The email attachment may be one of the following:
A combination of the text strings: setup, card, docs, news, Image, images, pics, resume, photo, video, music, or song data; with any of the extensions: SCR, PIF, or EXE.
An existing system file concatenated with any of the of the filename extension: SCR, PIF, or EXE.
This worm opens port 36794 on the target system, allowing a remote user to connect thereby compromising network security. It also uses API (Application Program Interface) functions, commonly used by keylogger Trojans.
It exploits a known vulnerability on systems with unpatched Internet Explorer 5.01 and 5.5, which automatically runs the executable file attachment when the email message is previewed or opened in Microsoft Outlook and Outlook Express.
Solution:
AUTOMATIC REMOVAL INSTRUCTIONS
This option is currently only available as a patch for users of Trend Micro products. A stand alone version is being prepared for non-users of our products.
Download the Trend Micro System Cleaner Patch to effectively remove this malware from your system.
NOTE: You must download and use the latest pattern file for the TSC to be effective.
MANUAL REMOVAL INSTRUCTIONS
Identifying the Malware Program
To completely remove this malware from your system, you must first identify the filename of the malware program running in memory. Once identified, it can be terminated, then removed.
Scan your system with Trend Micro antivirus and NOTE all files detected as WORM_BUGBEAR.A. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro´s free online virus scanner.
Terminating the Malware Program
This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier.
Open Windows Task Manager.
On Windows 9x/ME systems, press
CTRL+ALT+DELETE
On Windows NT/2000/XP systems, press
CTRL+SHIFT+ESC, and click the Processes tab.
In the list of running programs*, locate the malware file or files detected earlier.
Select one of the detected files, then press either the End Task or the End Process button, depending on the version of Windows on your system.
Do the same for all detected malware files in the list of running processes.
To check if the malware process has been terminated, close Task Manager, and then open it again.
Close Task Manager.
Removing Autostart Entries from the Registry
Removing autostart entries from registry prevents the malware from executing during startup. You will need the name(s) of the file(s) detected earlier.
Open Registry Editor. To do this, click Start>Run, type REGEDIT, then press Enter.
In the left panel, double-click the following: HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>RunOnce
In the right panel, locate and delete the entry or entries whose data value (in the rightmost column) is the malware file(s) detected earlier.
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system in MS-DOS mode and delete the file(s)in the Startup folder detected as WORM_BUGBEAR.A. Afterwards, restart your system in normal Windows mode.
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files detected as WORM_BUGBEAR.A. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro´s free online virus scanner.
Applying Patches
This malware exploits known vulnerabilities in Internet Explorer. Download and install the security patch supplied by Microsoft. Refrain from using this product until the appropriate patch has been installed.
Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network or home PC.
il n´ets que 2e mondial avec 8434 ordinateurs infectés...
c rien comparre a PE_FUNLOVE.4099 14838 ordinateurs infectés.
Comme vous avez pu le constater votre noiuveau virus n´en ai pas un....et il se transmet de mail en mail...
n´ai pas un nouveau virus je voulais dire..enfin merde sais pu ce que je voulais dire ^_^
3jours???!!!
ben dit donc t lent!!! ^_^
koi
rien laisse