andsome Posted October 26, 2003 Report Share Posted October 26, 2003 "Imagination is more important than knowledge." Albert Einstein (1879-1955); physicist and mathematician. - Weekly virus report - Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)Madrid, October 26, 2003 - This week's report on malicious code will focuson three worms -Lohack.C, Flop.A and Sexer.A-, a Trojan called Sdbot.N andthe virus Vix.A.Lohack.C spreads via e-mail and across network drives. The message carryingthis worm tries to trick users by referring to the Spanish InformationSociety and E-business Services law. It also spoofs the sender's address, sothat it seems to have been sent from the Spanish Ministry of Science andTechnology or Panda Antivirus.Lohack.C automatically activates when the message carrying the worm isviewed through the Preview Pane in Outlook. It does this by exploiting avulnerability -known as Exploit/Iframe- that affects versions 5.01 and 5.5of Internet Explorer and allows e-mail attachments to run automatically.Finally, one of the effects of Lohack.C is that it moves the mouse pointeraround the screen. Today's second worm is Flop.A, which spreads by copying itself to all thefloppy disks used on the affected computer, provided that they are notwrite-protected. When this malicious code is run, it displays a message inSpanish describing how to enlarge the male member. The file carrying Flop.Ahas the same icon as Word documents.Sexer.A is a worm that spreads via e-mail in a message written in Cyrilliccharacters and includes an attachment called WIN2DRV.EXE. When Sexer.A hasinfected a computer, it sends a copy of itself to all the contacts it findsin the Windows address book and changes the Windows wallpaper for a textwith Cyrillic characters. The fourth malicious code in today's report is a Trojan called Sdbot.N. ThisTrojan has been mass mailed in a message with the subject: "MicrosoftSecurity Update" and an attachment called MS03-047.EXE. The message textalso tries to trick the user into believing that the message has been sentby Microsoft. However, when the attached file is run, Sdbot.N goes memoryresident and connects to an IRC channel. This channel sends the Trojanremote control commands in order to carry out the following actions, amongothers: scan ports, download and run files, launch Denial of Service (DoS)attacks, etc. Finally, Vix.A is a virus with worm characteristics that infects PE filesand spreads via the P2P (peer-to-peer) file sharing programs KaZaA, iMeshand Shareaza. A file that has been infected by this virus cannot bedisinfected and will therefore be rendered unusable. For further information about these and other malicious code, visit PandaSoftware's Virus Encyclopedia at:http://www.pandasoftware.com/virus_info/encyclopediaAdditional information- PE (Portable Executable): PE refers to the format of certain programs. - Preview Pane: A feature in e-mail programs that allows the content of themessage to be viewed without having to open the e-mail. More definitions of virus and antivirus terminology at:http://www.pandasoftware.com/virus_info/gl...ry/default.aspxNOTE: The addresses above may not show up on your screen as single lines.This would prevent you from using the links to access the web pages. If thishappens, just use the 'cut' and 'paste' options to join the pieces of theURL.------------------------------------------------------------To unsubscribe from Oxygen3 24h-365d, please visit:http://www.pandasoftware.com/unsubscribe.aspTo contact with Panda Software, please visit:http://www.pandasoftware.com/about/contact/------------------------------------------------------------ Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.