fsu seal Florida State University
Systems - Webmail - Web Support - UCS Home


 

UCS > Special Projects


Live Webcams
Come see the view from FSU!





       

University Computing Services

New Worms/Viruses/Trojans you will want to learn about:

These worms can cause many unlikely results including:

  • Worms can send email all over the world appearing to be sent from YOUR email account. (Actually, your address is spoofed on the email and learned from an address book of a worm-ridden pc.)
  • They cause more mail generated from mail servers responding to tell you that you have a virus (when it wasn't your email account that sent it, but your email address, forged), and they recieved mail from you containing a virus.
    Spawned email can look like this: 'failure to deliver' or '...detected a virus in the mail you sent', though you didn't send the mail and you may not be infected. This can cause slowness in the mail delivery system.
  • They generate email to join online clubs or submit subscriptions from your copied email address. You may recieve mail saying you have joined. While some of this is SPAM, you may not want to send a reply, just delete or store in a folder.


To stay virus-free and protect against hackers on your desktop, you will want to:

(1) Visit Microsoft's Update Site to check your system for missing critical updates..
It is a good practice to download the updates for your Windows computer regularly. Just 'Scan for Updates', and follow instructions.

(2) Get antivirus software, and keep it updated with automatically scheduled updates.
Get free antivirus software at
AVG download*
If you think you have a virus, try:

** Free Virus Removal Tool - Network Associates (McAfee)*
** Free Virus Removal Tool - Symantec*

**
Free Online Virus Scan - Trend Micro*

Note: Antivirus Tools Cannot Clean Infected Files in the _Restore
Folder," Article ID: Q263455
"How to disable or enable Windows Me System Restore"
"How to turn off or turn on Windows XP System Restore"

Computer Security Resource Center - Virus Resources & Other Areas of Interest, Anti-Virus Vendors

(3) Disable File Sharing
For instructions, go to Microsoft.com

(4) Get firewall protection. (Yes, you need a personal firewall!)
For Free (personal use) or for fee firewall protection for your computer, see ZoneLabs.*

(5) Watch out for Spyware.
If you think you have 'parasite' software on your PC, try (for free of for fee):
Dox Desk*
Ad-Aware
*
SpyBot*


(6) Have a plan for Recovery from a disaster.

Also, see Trace Route solutions for MS Windows OS and Technology Services Help Desk.

*UCS does not endorse any one antivirus, anti-spyware or firewall product.


- Virus Alert: W32/MyDoom-A
Alias: Mimail.R, Novarg.A, Shimg, W32.Novarg.A@mm, W32/Mydoom@MM
W32/MyDoom-A is a worm which travels by email. The worm harvests email addresses from your hard disk and uses randomly-chosen addresses for both the "to" and "from" fields. This means that the "from" address is spoofed and does not tell you where the mail really came from.
W32/MyDoom-A attaches itself to emails in either EXE (Windows program) or ZIP (Zip archive) format.
Sophos    |    McAfee    |   AVG/Grisoft


- Trojan.Qhost Address: www.google.com
Results:
"Are you trying to get to Google?
Your computer is running software that doesn’t allow you to use Google..."


- W32/Gibe-F "Last Internet Patch", Microsoft will NOT send YOU a patch!!   Beware!!

- W32/Lovsan
.worm.d (aka W32/Blaster-D) hits campus.
For more information see AVG, Symantec or Microsoft.
Also, see Technology Services Help Desk.


- W32/Sobig - is a worm that spreads via email and network shares.
Subject line: Chosen from -
  Re: That movie
  Re: Wicked screensaver
  Re: Your application
  Re: Approved
  Re: Re: My details
  Re: Details
  Your details
  Thank you!

- W32/Klez - Wonder why people are getting email from you... email that you didn't send? ... Read more.


- Virus: W32/Dumaru-A - Remember: Microsoft isn't going to send out individual patches to each Windows user.
Sender: "Microsoft" <security@microsoft.com>
Subject line: Use this patch immediately !