Advertisement
Promo

Security threats Toolkit

Viruses, worms, and Trojans return with a vengeance

John McCormick

Published: 09 Jun 2005 11:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

It's Sobering news as viruses, worms, and Trojans emerge from an apparent holiday -- rested and ready to wreak havoc once more.

Details
Just when you thought virus and worm attacks had finally slackened and no longer needed to top your list of concerns, new attacks are conspiring to bring malware concerns back to the forefront of security thinking. In addition, the latest version of Sober has surged across the Web, infecting more than three times as many emails in May as the month before.

Bagle
Meanwhile, a new version of the Bagle worm (designated Glieder by Computer Associates) has spread rapidly, using a new three-horned approach. The initial attack is the usual mass-mailing email that contains an infected attachment, which harvests addresses from the address book of infected systems. The next action is to download a Trojan called Fantibag that blocks automatic antivirus updates, including links to Microsoft's Windows Update Web page.

Finally, the worm downloads a second Trojan called Mitglieder, which disables firewalls and antivirus software. According to the News.com report, spammers are paying a bounty of five cents per computer for compromised PCs. With zombies now a commodity market with an economic incentive for attackers, we can expect increasingly more sophisticated Trojan attacks as well as a surge in the number of attacks.

Mytob
Mytob is a dangerous new piece of malware that uses MyDoom exploit code. According to a NewsFactor.com report, antivirus firm Trend Micro believes this new infection often carries spyware and speculates that it may be a commercial venture. In addition, Mytob shows signs that its creators are taking caution to spread it carefully in order to avoid media attention.

As many of you know, major media outlets (i.e., television and newspapers) have a tendency to only mention malware when there's a widespread infection hyped by some security vendor -- and that's usually after the infection has already run its course. However, it appears that Mytob may be the first malware intentionally kept low-key so it can fly below the radar of the major media, giving it a chance to spread further among home users and others who actually rely on getting security news from TV news reports.

At least five new versions of Mytob appeared in the first two days of this month. For more information, check out the Symantec report on Mytob.da.

CA AV Vulnerability
SecuriTeam.com reports that there's a vulnerability in Computer Associates' VetE.dll virus library. This affects various CA products, including the eTrust family and some Zone Labs products, so make sure you get the appropriate updates. According to Computer Associates, the risk level is medium for this remote access code-execution threat.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
143 out of 323 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters