Virus Top Twenty for September 2004

04 Oct 2004
Virus News

PositionChange in positionNamePercentage by occurrence
1+3I-Worm.Netsky.q21.67%
2-1I-Worm.Netsky.aa13.79%
3+1I-Worm.Zafi.b12.70%
4-2I-Worm.Netsky.b9.63%
5-I-Worm.Mydoom.m5.34%
6+2I-Worm.Bagle.z4.86%
7+2I-Worm.Netsky.d4.55%
8newTrojanDownloader.JS.Gen4.41%
9-3I-Worm.Netsky.t2.51%
10+1I-Worm.Netsky.y1.62%
11-1I-Worm.Lovgate.w1.41%
12newI-Worm.Bagle.as1.35%
13+2I-Worm.Mydoom.l1.11%
14-2I-Worm.Netsky.r1.08%
15newI-Worm.Mydoom.t0.93%
16+3I-Worm.Bagle.gen0.86%
17re-entryI.Worm.Netsky.c0.83%
18-5TrojanDropper.VBS.Zerolin0.73%
19newI-Worm.Bagle.ah0.62%
20newI-Worm.Mydoom.u0.51%
Other malicious programs (not in the Top 20)9.49%

This September we witnessed several outbreaks caused by new variants of our old enemies Bagle and Mydoom. Thankfully, we did not see any malware exploiting the JPEG vulnerability in MS Windows, despite dire predictions by some analysts that an outbreak was inevitable. In short, September resembled August, with only minor changes.

Just as in August, we see 5 new malicious programs in the ratings this month. And it's more variations on the same theme: we had 3 new Mydoom variants and no Bagles in August, while in September they evened out with 2 new variants of each. TrojanDownloader.JS.Gen was the only truly new piece of malware in the ratings this month.

In the meantime, Netsky variants continue to dominate the top slots; changing places with each other, but not yielding to any other viruses. NetSky.q pushed aside NetSky.aa and took first place. Once again, the only malicious program to compete with the NetSky variants is Zafi. This Hungarian virus is maintaining a slow but steady downward pace, moving down to third place.

The Mydoom.m variant that appeared in August hung on to fifth place with the same occurrence rating.

The main newcomers this month are two Mydoom variants that appeared in the space of a single day. Bagle authors were not caught napping and brought their summer holidays to a close by releasing several new variants, which all used email and file-sharing networks to spread.

TrojanDownloader.JS.Gen is a catch all name for a huge number of Trojans written in Java Script. We group them together because they all have only one function - to download other malware from the Internet. This summer virus coders were placing such Trojans on websites, wheras in September we saw a new trend: using spammer techniques to mass mail malicious programs. On the one hand, Bagle, LovGate and NetSky variants carry on creating a steady background of virus activity, moving insignificantly up and down in the ratings.

On the other hand, the old steadfasts Swen and Sobig.f have finally disappeared from the Top Twenty. In other words, September 2004 finally saw malware created in previous years vanish totally from the ratings: we now have only viruses created in 2004. Moreover, 16 out of 20 viruses in this month's Top Twenty are worms from only three families. The only serious competion Bagle, NetSky and Mydoom variants face comes from Zafi and Lovgate.

Summary:

New virusesTrojanDownloader.JS.Gen, Bagle.as, Bagle.ah, Mydoom.t, Mydoom.u
Moved upNetSky.q, Zafi.b, Bagle.z, NetSky.d, NetSky.y, Mydoom.l, Bagle.gen
Moved downNetsky.aa, NetSky.b, NetSky.t, LovGate.w, NetSky.r, TrojanDropper.VBS.Zerolin
No changeMydoom.m