Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Panda Software: Weekly virus report

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-24-03 08:27 AM
Original message
Panda Software: Weekly virus report
Posted in GD as a public service.

The poster is not an employee of, or in any way associated with Panda Software.
---

Weekly virus report

Virus Alerts, by Panda Software (http://www.pandasoftware.com)

Madrid, October 24, 2003 - This week's report on malicious code will focus on three worms -Lohack.C, Flop.A and Sexer.A-, a Trojan called Sdbot.N and the virus Vix.A.

Lohack.C spreads via e-mail and across network drives. The message carrying this worm tries to trick users by referring to the Spanish Information Society and E-business Services law. It also spoofs the sender's address, so that it seems to have been sent from the Spanish Ministry of Science and Technology or Panda Antivirus.

Lohack.C automatically activates when the message carrying the worm is viewed through the Preview Pane in Outlook. It does this by exploiting a vulnerability -known as Exploit/Iframe- that affects versions 5.01 and 5.5 of Internet Explorer and allows e-mail attachments to run automatically. Finally, one of the effects of Lohack.C is that it moves the mouse pointer around the screen.

Today's second worm is Flop.A, which spreads by copying itself to all the floppy disks used on the affected computer, provided that they are not write-protected. When this malicious code is run, it displays a message in Spanish describing how to enlarge the male member. The file carrying Flop.A has the same icon as Word documents.

Sexer.A is a worm that spreads via e-mail in a message written in Cyrillic characters and includes an attachment called WIN2DRV.EXE. When Sexer.A has infected a computer, it sends a copy of itself to all the contacts it finds in the Windows address book and changes the Windows wallpaper for a text with Cyrillic characters.

The fourth malicious code in today's report is a Trojan called Sdbot.N. This Trojan has been mass mailed in a message with the subject: "Microsoft Security Update" and an attachment called MS03-047.EXE. The message text also tries to trick the user into believing that the message has been sent by Microsoft. However, when the attached file is run, Sdbot.N goes memory resident and connects to an IRC channel. This channel sends the Trojan remote control commands in order to carry out the following actions, among
others: scan ports, download and run files, launch Denial of Service (DoS) attacks, etc.

Finally, Vix.A is a virus with worm characteristics that infects PE files and spreads via the P2P (peer-to-peer) file sharing programs KaZaA, iMesh and Shareaza. A file that has been infected by this virus cannot be disinfected and will therefore be rendered unusable.

For further information about these and other malicious code, visit Panda Software's Virus Encyclopedia at: http://www.pandasoftware.com/virus_info/encyclopedia

Additional information

- PE (Portable Executable): PE refers to the format of certain programs.

- Preview Pane: A feature in e-mail programs that allows the content of the message to be viewed without having to open the e-mail.

More definitions of virus and antivirus terminology at: http://www.pandasoftware.com/virus_info/glossary/default.aspx

NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the 'cut' and 'paste' options to join the pieces of the URL.
Printer Friendly | Permalink |  | Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC