Search This Site:






This page contains pertinent information and links to sites which contain important virus and malware information.

January 24, 2008
A recently discovered trojan that affects Mac computers has been found on campus. On Jan 24, 2008, CIS posted a tool to remove the trojan.

It is known as OSX/Puper (aka OSX.RSPlug.A) Trojan . To access the tool to remove the trojan, enter the following URL into the address field of your browser.
http://132.177.212.103
and look for the Stop Puper tool under Additional Resources.

The symptoms include losing connectivity after a brief connection, arriving at inappropriate webpages when following a link, and having the DNS settings redirected to non-UNH addresses.

Hoax Alerts | back to top


Hoaxes are e-mail warnings that contain information about security issues that are not actual threats. These messages should be deleted immediately without being viewed. All virus related announcements pertaining to the University community will be directed from the department of CIS.

The following link will take you to Network Associates for more information:

http://vil.nai.com/vil/hoaxes.aspx


Scam / Fraud Alerts | back to top

The following is a list of current Scams and Frauds that are going around. Please be sure to read these carefully. Below each you will find a link to more information about the given Scam or Fraud alert.

The latest information from the FBI regarding Scams and Frauds can be found at
http://www.fbi.gov/majcases/fraud/fraudschemes.htm


  1. PHONE SCAM - 809 AREA CODE
  2. CHARTER ONE BANK
  3. MICROSOFT ANTI-PIRACY/CREDIT CARD SCAM
  4. FRAUD ALERT FROM BANK NORTH
  5. EBAY ACCOUNT SUSPENSION NOTICE

Virus Warnings | back to top | Click here to print this article.  Please note this will open a new window

The following is a list of known virus warnings. To get more information about any of the viruses listed, simply click on the associated link. The list is sorted from most recent to oldest.

To view the lastest threats as reported by McAfee, click http://us.mcafee.com/virusInfo/default.asp



Filtered Notifications | back to top | Click here to print this article.  Please note this will open a new window

Below is a list of those viruses being filtered by CIS:

Virus Name Date Added
   js/zerolinmonday, september 13, 2004
   w32/mywifemonday, september 13, 2004
   w32/vallamonday, september 13, 2004
   w32/patemonday, september 13, 2004
   w32/elkernmonday, september 13, 2004
   w32/krizmonday, september 13, 2004
   js/illwillmonday, september 13, 2004
   w32/sober (all variants)march 8, 2004
   w32/mydoom (all variants)january 26, 2004
   w32/bagle (all variants)january 19, 2004
   w32/netsky (all variants)february 19, 2004
   w32/klez (all variants)december 16, 2003
   w32/swen@mmdecember 16, 2003
   w32/mimail (all variants)december 16, 2003
   w32/dumaru (all variants)december 16, 2003
   w32/sobig (all variants)december 16, 2003

Protecting the UNH Campus From A Large Volume Of Infected E-mail Messages

The two primary public e-mail systems on the UNH campus are the CISUNIX and the Microsoft Exchange systems. Together, these systems serve 16,000 e-mail accounts, providing services for faculty, students and staff throughout the campus. These systems are subjected to continuous malicious activity from infected software from the Internet. Both e-mail systems are currently protected against malicious software, and intercept infected e-mail messages. When an infected message is blocked, a notification is typically sent to the intended recipient indicating that the infected message was intercepted. The problem faced by campus clients is that most of these notifications are about messages that were not valid electronic mail messages in the first place.

During the first few months of the fall 2003 semester, campus clients on these two central systems were subjected to an average of 30,000 to 90,000 attempted infections per month, with peaks of 100,000 per day, and up to 5,000 per hour. While these malicious software attacks involved a wide variety of virus types, approximately six types (or variants) account for about 90% of these attempted infections. These six types are known to be automatically generated and are infected mail messages that have no content value for the intended recipient; their only purpose is to cause further proliferation of the malicious software or to produce other more ominous impacts. This large volume of notifications fills up client e-mail boxes, and degrades the performance of the electronic mail servers.

Because of the rapidly rising volume of malicious e-mail software attacks, and the highly disruptive notification volumes experienced by the campus clients, the e-mail administrators of the protected systems (CISUNIX and Microsoft Exchange) will, effective 12/16/03, be suppressing the recipient notification for the most common malicious types of infected e-mail messages that are known to be automatically generated and have no content value for the intended recipient. MS Exchange clients must be using an alias (exp: Firstname.Lastname@unh.edu) as their Reply To: e-mail address in order to take advantage of this protection.

E-mail resulting from the following list of viruses is currently being blocked. As new viruses are discovered and become a problem on the e-mail servers, messages resulting from those viruses will also be blocked. This page will be continuously updated to provide the University e-mail clients with up-to-date information as to what message types are being blocked. Additional information about these and other common viruses is available by going to http://www.virus.unh.edu and clicking on “Virus Warnings” in the links on the left. Complimentary virus protection software is also available to UNH community members, as well as additional virus-related information, from that webpage.




Quick Links
Download virus protection click here to download your free copy of either McAfee VirusScan or ClamXav
Visit Windows Updates click here to visit windows update.  Please note this will open a new window.


Software Details

Below you will find the most current information about virus protection at UNH.

scan engine: 5200
   definitions: 5345

 » get DAT/extraDAT updates «

for instructions on how to determine your systems current level of protection, click here




Copyright © 2001 CIS
UNH - Durham, NH 03824
Design Last Updated:
ipsCAS Secured Page best viewed using IE 5 or higher at 1024x768
Usage