Archive for the 'Viruses' Category


Zotob details

Monday, August 15th, 2005

Here are some details on the zotob worm (s) culled from several sources…. It copies itself to the Windows system folder as BOTZOR.EXE, it modifies the hosts file to frustrate attempts to access antivirus sites. The .b variant copies itself as csm.exe in the Windows System folder. Both variants create a Mutex so that only […]

Another entry in the sunbelt discovery of a keylogger

Monday, August 15th, 2005

Sunbeltblog has another entry in the continuing story. Really, there is not much new here, but iDefense has analyzed the code of the trojan that was discovered and have stated that it is not related to CoolWebSearch. (Which is what sunbeltblog has been saying for some time.) They initially said it was discovered during a […]

Zotob.b may be affecting some XP SP2/2003 installs

Monday, August 15th, 2005

As I noted yesterday, virii typically get updated and improved. Yesterdays reports about the zotob virus noted that Windows Xp service pack 2 and Windows 2003 were not affected by the new worm. Today however, the sans institute is reporting that zotob may be affecting some XP sp2 and 2003 installs. It appears that it […]

Zotob Worm

Sunday, August 14th, 2005

According to The Sans handlers diary, a worm exploiting one of the security vulnerabilities disclosed last week by Microsoft, is in the wild and spreading. The worm tagged as zotob.a exploits the ms05-039 vulnerability. (Sans reminds us that ms02-039 was the vuln. targetted by the slammer worm. Interesting coincidence.) They are still at infocon yellow. […]

Exploits in the wild and other news

Friday, August 12th, 2005

After perusing the Sans.org handlers diary, there are a few things brewing that should be known. Exploits are in the wild for some of the vulnerabilities addressed by this weeks Microsoft patchfest. There is a Veritas Backup Exec vulnerability and it appears that the Beta of Vista has a network service that might be nice […]

Sunbeltblog has more info on the identity theft keylogger and will offer removal tool

Thursday, August 11th, 2005

There another two fascinating posts in the saga of the massive identity theft that was reported in the Sunbelt blog. For starters they detail the beast here. It sounds truly devious, MAY still be related to coolwebsearch after all. It turns off Windows firewall and runs through Internet Explorer (thereby bypassing any other software firewall.) […]

HP virus throttler available for Linux

Monday, August 8th, 2005

HP will be making their virus throttler software avialable for Linux. Their virus throttler software detects compromised machines on a network, mails the administrator and throttles network connections to the machine, attempting to minimize the impact of the viral outbreak. (It seems as though it would be especially useful against network worms.    Send article […]

Monad will not be in Windows Vista

Friday, August 5th, 2005

I wrote earlier about “proof of concept” viruses that targeted Monad, the next generation command shell from Microsoft. There had been talk that Monad would ship with Windows Vista and so some people were saying these “proof of concept” virii were the first to target Vista. Well, according to the Microsoft Security Response Center Blog […]

Suspicious Emails inderectly leading to virus infection

Friday, August 5th, 2005

According to The August 4th entry of the isc.sans.org handlers diary, there are some peculiar emails going around. They claim to be for an article claiming an explosion kills 140 in Iraq. It contains a link to a news article that has been altered from it’s original (140 instead of 14 for instance.) It also […]

Windows 2000 Worm vulnerability

Friday, August 5th, 2005

Apparently, there is an unpatched vulnerability in Windows 2000 that could open the door for a network worm. The details have not been released to give Microsoft time to deal with a patch. (Microsoft is drawing down support commitments to 2000, releasing a batch of updates just before their timeline to start phasing out support.) […]

Google
 
Web www.averyjparker.com