New Skype Worm Threatens All Skype Windows Users (comments)
A new Skype worm, known alternately as Ramex, Pykspa, or Skipi (technical names w32/Ramex.A, W32.Pykspa.D, and W32/Skipi.A, respectively), is threatening all Skype users who are running Windows. The worm replicates itself by sending a Skype instant message from the infected user's machine to everybody in the user's Skype address book.
New “Windows Genuine Advantage” Worm Cuebot-K Being Spread by AIM, Installs Self as Wgvan.exe and Dcpromo.log (This
article has 3 comments)
The files wgavn.exe and dcpromo.log are really the Cuebot-K worm, also known as W32/Cuebot-K, Backdoor.Win32.IRCBot.st, and Win32/IRCBot.OO. Cuebot-k is a new worm that masks itself as a "Windows Genuine Advantage Validation Notification", part of Windows Authentication Software (WAS). But it's really a nasty worm which gives control of your system over to the bad guys. It's spreading via AOL Instant Messenger (AIM).
New MSN Messenger Worm BlackAngel.b Offers Up Fantasma Video While It Munches Your PC Security (comments)
The BlackAngel.b worm infects through MSN Messenger, offering the Fantasma video which warns that "en el 1er dia te espantas", meaning that on the first day you get scared, as indeed you should. The worm sends itself through MSN Messenger messages saying things such as "jaja look a that" or "mira este video".
New Yahoo Worm Targets All Yahoo Email - Yamanner Worm Has No Manners at All (This
article has 3 comments)
A new Yahoo worm being called the "Yamanner worm" is targeting all of Yahoo email; in fact the only version of the Yahoo email program which is at present safe from the Yamanner Yahoo email worm is a not yet fully released beta version of Yahoo mail.
Did You Get Hit by the Black Worm? BlackWorm Day is Today! (This
article has 5 comments)
Today, February 3rd, is Black Worm Day, so called because today is the day that the nasty BlackWorm is posed to strike computers around the world, wiping data files willy nilly. Also known as the Kama Sutra worm, Mywife worm, and a host of other names, it is estimated that as many as 600,000 PCs are infected with the Black Worm.
Reminder! Friday is BlackWorm Day (This article has 1 comment)
Black Worm Day is fast upon us. This Friday, February 3rd, is being called "BlackWorm Day" because that is when the Mywife worm or Kama Sutra worm, also known as Blackmal.E, Nyxem.E, Email-Worm.Win32.VB.bi, W32.Blackmal.E@mm worm, or W32/Nyxem-D, and now being dubbed just "The Black Worm", is set to delete files on at least a half-million PCs.
“It’s Immoral, but the Money Makes it Right,” says Apprehended Botnet Operator Jeanson Ancheta (This
article has 2 comments)
"Bot Herder" Jeanson James Ancheta, the BotNet operator taken down by the Feds, told colleagues of operating the botnet of more than 400,000 infected PCs, "It's immoral, but the money makes it right."
Half-Million PCs Infected with Blackworm Code to Delete Files on February 3rd! (This article has 1 comment)
According to best estimates, as many as a half-million PCs world-wide are infected with a malicious "blackworm" code which is set to delete data from their hard drives on February 3rd. The worm, previously identified as the Kama Sutra worm, also known as Blackmal.E, Nyxem.E, Email-Worm.Win32.VB.bi, W32.Blackmal.E@mm worm, or W32/Nyxem-D, is set to wipe all Word, Excel, PowerPoint and PDF data from your hard drive! It's being delivered in email with subjects like "School girl fantasies gone bad," and "Re: sex video."
Kama Sutra Worm Catches Windows Users in Compromising Position (comments)
The new Nyxem-D worm making the rounds has been dubbed the "Kama Sutra worm", because it arrives in an email offering graphic sex images and videos. Also called Email-Worm.Win32.VB.bi, W32.Blackmal.E@mm worm, or W32/Nyxem-D, the email has such enticing subjects as "Kama Sutra pics!", "Hot Movies", "give me a kiss", Miss Lebanon 2006", "Part 1 of 6 Video clip", "The Best Videoclip Ever", "Arab sex DSC-00465.jpg", "Fw: SeX.mpg", "Fwd: Crazy illegal Sex!", and "School girl fantasies gone bad."
Sober Worm Convinces Pedophile to Turn Self In! (This
article has 2 comments)
The Sober worm, and its fake email from the FBI, has accidentally caused a German pedophile to turn himself in!
Santa Worm Making the Rounds - You Better Watch Out! (This
article has 5 comments)
You better watch out, you better not click - Santa Worm is coming to AIM. And the IM.GiftCom.All Santa Claus worm is targeting Yahoo and MSN messengers as well.
New AIM Worm Chats with You to Fool You (comments)
A new AIM worm, called IM.Myspace04.AIM, attempts to get you to download the clarissa17.pif file by appearing to interact with you. But give IM.Myspace04.AIM and clarissa17.pif the cold shoulder!
Fake Email from the FBI or CIA is Really a Worm, Not Steven Allison (This
article has 4 comments)
The newest version of the Sober worm disguises itself as a fake email from the FBI or fake email from the CIA. Most come from Steven Allison.
AIM SDBot Worm Installs Lockx.exe RootKit, Takes You to eza1netsearch.com (This article has 1 comment)
A new AOL Instant Messenger worm, SDBot.add, installs the rootkit Lockx.exe on your computer. In addition to the root kit, the AIM worm changes your searchpage to http://www.eza1netsearch.com/sp2.php at eza1netsearch.com.
Bagles and Locks: New Bagle Virus Rolls Across Internet (a/k/a Bagle.da and Bagle.cd) (comments)
The BagleDI-U trojan is showing up in a lot of places this week. Being called Bagle.cd or Bagle.da, and hidden in an attached file called either "price_new.zip", "price2.zip" or "09_price.zip", it's turning up all over the place.
Mepe.A Instant Messenger Worm: Postcards from the Latino Edge (comments)
Mepe.A is an instant messaging worm which says "te mandaron un recado conmigo" (I've been asked to give you a message), but which really gives you an infection instead.
Worst Problem on the Internet is Stupid Users, Survey Says (This
article has 9 comments)
Stupid users are the worst problem on the Internet, according to this survey of more than 600 Internet users.
Yusufali-A Trojan Worm Censors Adult Surfing with Koran Verses (This
article has 2 comments)
Yusufali-A is a new trojan worm which censors web sites by minimizing your browser window and displaying a verse from the Koran which includes the phrase "Yusufali: Know, therefore, that there is no god but Allah, and ask forgiveness for they fault, and for the men and women who believe"
Zen Neeon MP3 Player Infected with Windows Wullik Worm Virus (This
article has 2 comments)
Wullik.B (W32.Wullik.B@mm) has infected the Zen Neeon MP3 player. Creative says that nearly 4,000 of the Zen Neeon MP3 players were shipped with the worm, and has issued a recall.
Zotob Botzor.exe and Mytob Worm Authors Arrested, Identified as Farid Essebar and Atilla Ekici (comments)
The Zobot Botzor.exe (a/k/a worm-rbot.cbq, rbot.cbq, and rbot.ebq) and Mytob worm authors are believed to have been arrested in Turkey and Morroco. Authorities in both countries, in cooperation with the FBI and Microsoft, arrested Farid Essebar and Atilla Ekici, using online nicknames Diab10 and Coder, who are believed to have authored the worms.
Online Game Community Targeted by Worm PrsKey.a (comments)
Online game community and security experts are warning about PrsKey.a, a keylogging worm which steals your username and password, and allows those behind it to steal all your game booty.
Zotob Botzor.exe Worm Removal Tool Offered by Microsoft (comments)
Microsoft has announced that they have just updated their Malicious Software Removal Tool (KB890830) to detect and remove the Zotob worm which brought down computer systems across the country this week. The Zotob worm has also been referred to in news reports ...
Microsoft Statement Regarding Zotob Worm that Crashed CNN, ABC, NYT and Congress: “Low Threat for Customers” (This article has 1 comment)
Microsoft has today released a statement regarding the Zotob worm (also reported as Botzor, Botzor.exe, and, incorrectly, as Zobot and rbot.ebq or rbot.cbq), which crashed computer systems across the nation yesterday.
The Zotob worm, which takes advantage of a flaw in the Windows Plug ...
Breaking News! New Worm-rbot.cbq Brings Windows 2000 Computers Crashing to a Screeching Halt Across the U.S. (Zotob - not “Zobot” - Also Implicated) (This article has 1 comment)
Worm-rbot.cbq, rbot.ebq, Win.32.rbot.ebq, Zotob, Botzor.exe, or Zobot - whatever you call it, and whichever it is, it's causing a whole lot of trouble across the United States.
Windows Worm of the Day Zotob Attacks Plug and Play (a/k/a Botzor.exe, but not “Zobot”) (comments)
[Breaking News! Tuesday, August 16th: Zotob May Be Responsible for Computer Crashes Across the U.S. Read Here]
Today's Windows worm, brought to you by the letters Plug and Play, is the worm Zotob. Zotob attacks a flaw in the Windows ...
Free Tool from Microsoft Removes Malicious Software, Recommended for All Windows Machines (KB890830) (This article has 1 comment)
Microsoft has this week released an updated version of its Malicious Software Removal Tool for Windows (KB890830).
This free tool is not a replacement for anti-virus, anti-spyware, or anti-spamware. Rather it is a separate, additional tool (and did I mention that it's free?), ...
Doombot.A Delivers CommWarrior.B to Bluetooth Smartphones (This article has 1 comment)
While consumers, and indeed the online security industry, have typically not paid much mind to warnings of nasties being sent to or through a Bluetooh device, experts are warning that this needs to change. Case in point: the newly discovered Doombot.A, ...
Grand Theft Auto Worm Hagbard.A Offers Hot Water, Not Hot Coffee (This article has 1 comment)
Security experts are reporting that a new worm called Hagbard.A is posing as a pirated version of the popular and now scandal-plagued game, Grand Theft Auto: San Andreas.
Riding the wave of publicity which Rockstar Game's Grand Theft Auto: San Andreas has received ...
Are the Chinese Stealing U.S. Corporate Secrets Through Internet Worms? (This article has 1 comment)
Are the Chinese stealing U.S. corporate trade and other secrets through the use of computer worms and trojans?
According to at least one security expert, the answer is "yes".
Joe Stewart, with U.S. security company Lurhq, claims that a new worm called "Myfip" is being ...
New Kirvo Trojan Worm Sidekick Targetting AOL AIM and MSN Instant Messenger (This article has 1 comment)
The Kirvo Trojan visits you via Instant Messenger, blazing a trail so that Spybot can then install itself on your system. And once you have a Spybot infestation, all bets are off.
New AIM Instant Messenger Worm Impersonates iTunes (comments)
The newest worm in the big apple known as the Internet is worm_opaniki.y, also known as Oscabot-L. What makes Opaniki.y unique is that it impersonates iTunes, by sending itself around disguised as "iTunes.exe".
Propogating itself across AOL's Instant Messenger platform, AIM, Opaniki.y / ...
Lebreat “Breatle AntiVirus” Actually Double-Edged Worm for Windows (This
article has 3 comments)
A new worm has hit the streets, and it's a double-edged worm. The Lebreat worm, which is mailing itself around calling itself "Breatle AntiVirus" is both a network worm and a mass-email worm. It's two, two, two worms in one.
According to ...
Don’t Say That Aunty Didn’t Warn You - This Month’s Fake Microsoft Security Update MS05-039 (This article has 1 comment)
Well, you can't say that it wasn't expected. Sure enough, after Tuesday's release by Microsoft of its July Security Updates, along came the fake "Microsoft Security Update" that you were warned about, the very next day.
Identifying itself, falsely of course, ...
Crime Pays! Microsoft to Reward Sasser Informants (comments)
It turns out that crime does pay, after all. Informants, that is.
Microsoft has announced that they will pay out a promised $250,000 USD reward to two informants who helped lead authorities to Sasser creator Sven Jaschan. The teenaged Jaschan was tried ...
Worldwide Trojan Attacks in Progress (This article has 1 comment)
Online security company MessageLabs is warning people that there has been a sudden sharp rise in Trojans assailing user inboxes, worldwide.
In just one morning this week, MessageLabs says that they blocked 54,000 copies of new Downloader Trojans. The Download Trojans include Trojan ...
Sasser Suspect Scores Suspended Sentence (comments)
Sven Jaschan, the German teenager who created the Sasser worm, has now been convicted of creating Sasser, and has received a suspended sentence for his deeds, along with an order to perform community service.
The twenty-one month suspended sentence is due in large part ...
Sasser Suspect Sven Speaks (and Confesses) (This article has 1 comment)
Sven Jaschan looks like, and by most accounts is, a typical teenager. That is, except for that small matter of bringing hundreds of thousands of computer systems around the world to a screeching halt - or at least a snail's paced crawl ...
New W32 Kedebe-F Worm Announces Osama’s Capture, My Doom Arrest, and Pope Conspiracy (comments)
The newest version of the W32 Kedebe-F worm is playing on the natural curiousity and rubber-necking of the email-reading public, or as it's known in the trade, "social engineering".
Masquerading as a variety of news headline stories, Kedebe-F has been seen breaking the news ...
Newest AIM Opanki Worm says “LOL Look at Him” (comments)
The newest AOL Instant Messenger (AIM) worm, discovered today, causes targetted AIM users to receive a message, ostensibly from a buddy, which says "LOL, LOOK AT HIM", and containing a link to a file called "picture.pif". This worm is considered to be ...
Osama Bin Laden Internet Worm a Dud (comments)
A new email worm being carried in email purporting to contain pictures of a captured Osama Bin Laden has failed to elicit the likely intended response - releasing the worm and allowing it to spread.
According to spokespersons at both F-Secure and McAfee, the ...
New Improved Bagle Worm Win32.Glieder! Now with Win32.Fantibag and Win32.Mitglieder (This article has 1 comment)
Not content to just do its normal wormly dirty work, a new variation on the infamous Bagle worm, Win32.Glieder, brings with it two companion Trojans, Win32.Fantibag and Win32.Mitglieder (literally, in German, "with Glieder").
Said Chris Thomas, a security architect with Computer Associates, "We've seen ...
AIM Gpic.aol Worm Says “damn this looks just like me lol” (This article has 1 comment)
This is an update on the Gpic.aol worm which is borne by AOL Instant Messenger (AIM). This is the worm which spreads itself by sending the target (that's you) an instant message via AIM which says "damn this looks just like me ...
New Gpic AIM Worm Invites Users to Look at Pictures on Google (This
article has 3 comments)
A newly discovered worm dubbed "Gpic.aol" and being transported via AOL Instant Messenger (AIM) arrives as an instant message along the lines of "damn this looks just like me lol" and proffering a link which claims to be a link to pictures.google.com
However, as ...
A New and Dangerous Variant of Mitglieder Is Being Spread Massively (News Release) (comments)
Mitglieder.DC Is a Malicious Code Designed to Kill Processes Belonging to IT Security Programs, Leaving Computers Unprotected Against Other Possible Attacks
- Detections in ActiveScan Are Increasing Progressively, Because It Is Being Mass-Mailed
GLENDALE, Calif., June 1 /PRNewswire/ -- ...
New Viruses for AOL and Yahoo Instant Messengers for the Long Weekend (This article has 1 comment)
Just in time to make Memorial Day weekend really memorable, both AOL and Yahoo Instant Messengers are being targeted, the former by an Internet worm, the latter by a phishing scam.
"hehe i found this funny movie", says your AOL AIM Instant Messenger ...
Two Internet Worms Target MSN Instant Messenger Users (This
article has 4 comments)
MSN Messenger has been added to the list of instant messenger programs which require heightened vigilence. Two security companies have discovered that there are two worms, one old and revised, and one new, which are targetting MSN Messenger users. As if ...
New Worm Targets Windows and MSN Messengers (comments)
A newly discovered Internet work, dubbed "Bropia.A", is targetting Windows and MSN Messenger messaging clients.
The worm does a host of nasty things, including sending a copy of itself to all of the messaging contacts found on the victim's computer, installing a Trojan horse ...
Information Security Magazine Determines Top 39 Security Products (This article has 1 comment)
Information Security Magazine, following extensive review, has published its list of the top security products for 2004. Evaluating products in a baker's dozen of categories, and with a first, second, and third place in each (gold, silver, and bronze, respectively), this is ...
It’s in the Cards - Internet Worm Poses as Electronic Christmas Card (This
article has 3 comments)
Instead of the Grinch who Stole Christmas, it's the Worm who Sneaks Into Your Computer Disguised as an Electronic Christmas Card. And oh joy, targetted specifically towards Windows systems, just to ensure you a white-out Christmas.
Yes, this year it's the ...
New MyDoom Worm Has No File, Just a URL, Exploits I.E. Hole (This article has 1 comment)
The newest version of MyDoom does not even have a file attached to it, making it look even less suspect, and less worm- or virus-like.
Instead, it exploits one of the more recently discovered holes in Internet Explorer, through which clicking on a URL ...
New Sasser Virus Worm Attacks Windows Computers (This
article has 10 comments)
The newest of the sinsister worm types of viruses, Sasser, has attacked Windows-based computers around the world.
Even more insidious than its earlier siblings, Sasser scans the Internet for computers with the Microsoft security flaw which allows it to do its dirty work, and ...
|