Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Weekly virus report

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Oct-04-03 12:00 AM
Original message
Weekly virus report
Posted in GD as a public service. If deemed to be inappropriate for this forum, Mods please move or lock.

The poster is not an employee of, or in any way associated with Panda Software.
---

- Weekly virus report -

Virus Alerts, by Panda Software (http://www.pandasoftware.com)

Madrid, October 3, 2003 - Today's report on malicious code centers on the Trojans -Hatoy.A, Petala.A and six variants of Istbar-, and three worms -Dozer.A, Simbag.A and Holar.I-.

Hatoy.A reaches computers when users access a malicious web page. To do this it exploits the 'Object type' Microsoft Internet Explorer vulnerability, which allows files in certain pages to be run locally. Once it is executed, and when users try to access certain search engines, Hatoy.A redirects them to an IP address that could host different pages.

Petala.A, is a backdoor Trojan that spreads across networks and IRC. This malicious code could give hackers remote access to the computer with which they could use IRC commands in order to copy files, terminate processes, etc., thus compromising confidential data and interfering with the use of the PC.

The B, C, D, E, F and G variants of the Istbar Trojan install spyware and dialers on the computer without users knowledge. They also display different screens with advertising for pornographic websites and add a toolbar to the Internet Explorer browser.

The first worm we'll be looking at in today's report is Dozer.A, which sends itself to all MSN Messenger contacts in the compromised PC. In order to trick users, it sends itself in an e-mail, which claims to contain a patch for MSN Messenger sent by Microsoft. However, when this file is run, a false error message is displayed to confuse the victim. Dozer.A creates various Windows registry keys and intercepts and terminates antivirus and firewall processes.

Simbag.A also spreads via MSN Messenger, sending a copy of itself to all contacts it finds. It also creates links to different erotic websites and generates the following files in the Windows directory: SMB.EXE, ADMAGIC.EXE, TEST.TXT, SM.DLL, RAW32X.DLL and UZ.EXE.

Finally, Holar.I spreads via e-mail and the KaZaA file sharing program. It changes the home page of Internet Explorer and when it has run more than thirty times it disables the mouse and the keyboard.

More information on these and other malicious code is available at the Panda Software Virus Encyclopedia at: http://www.pandasoftware.com/virus_info/encyclopedia/

Additional information

- Backdoor: This is an entry point, through either hardware or software, that can give access to a computer and could be used to take partial or complete control of the system.

- Dialer: This is a program that is often used to maliciously redirect Internet connections. When used in this way, it disconnects the legitimate telephone connection used to hook up to the Internet and re-connects via a premium rate number.

- Spyware: A program that is automatically installed with another, (without the user's permission and even without the user realizing), which collects personal data (data on Internet access, action carried out while browsing, pages visited, programs installed on the computer, etc.).

More definitions of virus and antivirus terminology at: http://www.pandasoftware.com/virus_info/glossary/default.aspx

NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the 'cut' and 'paste' options to join the pieces of the URL.
Printer Friendly | Permalink |  | Top
newyawker99 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Oct-04-03 07:19 AM
Response to Original message
1. kick
:kick:
Printer Friendly | Permalink |  | Top
 
bearfartinthewoods Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Oct-04-03 07:37 AM
Response to Original message
2. kick and thanks for posting this
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Oct-04-03 03:30 PM
Response to Original message
3. kick
for the late-sleepers. ;-)
Printer Friendly | Permalink |  | Top
 
Room101 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Oct-04-03 04:14 PM
Response to Original message
4. KICK,
I loath these people
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Dec 26th 2024, 09:30 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC