eSecurity Planet   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   eSecurity subjects:
E-Security Planet Webcasts:
Keeping Your Data Secure from the Outside In

Beyond Basic Data Security

more Webcasts...


Search EarthWeb Network

internet.commerce
Be a Commerce Partner
KVM Switches
Laptop Batteries
Calling Cards
Shop
Find Software
Condos For Sale
Auto Insurance Quote
Remote Online Backup
Build a Server Rack
Best Price
Computer Hardware
Web Hosting Directory
Laptops
Compare Prices

esecurityplanet : Online Threats & Alerts: Virus Alert: Worm Lowers Microsoft Office Security Settings

Meet the HP ProLiant DL385 G5

  Rethinking the Datacenter
Sponsored by HP
Today's datacenters need to increase utilization, get control over power and cooling costs, and align with business objectives. Download this eBook to learn about the challenges facing the data center in a world where digital information is growing at a torrid pace and costs are being held in check. Learn more. »
 
  Putting the Green into IT
Sponsored by HP
Electricity use in data centers is skyrocketing, sending energy bills through the roof, creating environmental concerns and generating negative publicity. "Going Green" means looking to technologies like virtualization, energy-efficient chips and racks, and implementing policies that extend beyond the data center. Learn more. »
 
  Managing the Modern Network
Sponsored by HP
In a global economy where information crosses the globe in an instant, and where Web-based applications power business, it's more important than ever to ensure your network is safe from threats and optimized to deliver the data your business needs. »
 
  Evaluating Software as a Service for Your Business
Sponsored by Webroot
Is Software as a Service just hype, or is something really going on here? See if your company can benefit as SaaS tries to change the face of the enterprise. »
 
  Is Your Disaster Recovery Plan Good Enough?
Sponsored by HP
Preparing for a disaster is more often than not part of the storage planning process, and it is one of the most difficult tasks, since it includes local hardware and software, networking equipment, and a test plan. Learn how to get disaster recovery right. »
 

Related Articles
Virus Alert: Worm Sends Profane Emails
Worm Searches for Admin Passwords
Virus Alert: Worm Launches IE, Connects to Various News Sites
No Holiday Week for Viruses, Worms
Virus Alert: Different Variants of Mumu Worm Spreading
Virus Alert: Sobig.E Threat Level Upgraded
eSecurity Glossary
biometrics
encryption
keylogger
malware
phishing
RFID
security
spyware
virus
worm
Search for more eSecurity terms ...
FREE Tech Newsletters

Virus Alert: Worm Lowers Microsoft Office Security Settings
July 8, 2003
By eSecurityPlanet Staff

Antivirus vendor Sophos on Tuesday warned about a worm that sets a registry entry to reduce security levels for Microsoft Office.

WM97/Adenu-A lowers the Microsoft Office Security settings by making the following registry entry:

HKCU\Software\Microsoft\Office\9.0\Word\Security\Level=01

WM97/Adenu-A also disables the following menu options within Microsoft Word:

Tools|Macro
Tools|Customize
Tools|Templates and Add-Ins

WM97/Adenu-A creates the file GbcHS4664.VBS in the Windows system folder and sets a registry entry. View it and other information at this Sophos page.

Virus Infects Excel 95 Spreadsheets

XM/Laroux-Fam is a family of viruses that infect Excel 95 spreadsheet files. Members of the XM/Laroux-Fam family are simple viruses, similar to the first Word macro viruses, and contain two macros, usually named auto_open and check_files.

The auto_open macro is run when the infected document is opened, and merely instructs Excel to call the check_files macro every time a new worksheet is activated.

When this happens, the virus creates a file in the XLSTART directory called PERSONAL.XLS and copies the viral macros into it. This file is automatically opened every time Excel is run, much like Word's NORMAL.DOT. From then on, it infects every workbook used. When PERSONAL.XLS is infected, the virus will be loaded every time Excel is started.

For information on removing macro viruses, visit this Sophos page.

Macro Virus Displays 'Porn Error' Message

Sophos has also issued an alert for WM97/ZWMVC-B, a simple macro virus that uses the name "zwmvc_macro" for the infected VBA module.

The virus displays the message "Yet Again Porn Error" every time an infected document is opened or a clean document is infected.

For removal instructions visit this Sophos site.

Worm Tries to Use Malformed MIME Header to Execute Attachment

This Borland Delphi worm, W32/Pluto.A@MM, propagates via:

  • mass-mailing itself to all recipients listed in the Outlook Address Book and the Windows Address Book (WAB).
  • peer-to-peer file-sharing networks like eDonkey2000, KaZaa, LimeWire, Morpheus, Shareaza and Xolox.
  • It is packed with UPX. It arrives attached to emails and tries to use a known malformed MIME header exploit to execute the attachment (view here).

    View the various subject lines the message may arrive in at this McAfee page.

    Worm Targets Weak Passwords to Copy Itself to Network Shares

    W32.HLLW.Graps is a network-aware worm that has backdoor capabilities. By default is opens port 45836 for listening.

    The worm copies itself to available network shares by connecting with weak passwords. It is a Visual Basic application compiled to native code and packed with UPX v1.24.

    Technical details are at this Symantec page.

    Compiled by Esther Shein.

     

    Tools:
    Add www.esecurityplanet.com to your favorites
    Add www.esecurityplanet.com to your browser search box
    IE 7 | Firefox 2.0 | Firefox 1.5.x
    Receive news via our XML/RSS feed

    Online Threats & Alerts Archives

    eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
    Five Trends for Application Development & Program Management. Download Complimentary Report Now.
    Increase your reach with unlimited Webinars for one low rate. Try GoToWebinar FREE.
    Whitepaper: Enterprise Information Integration--Deployment Best Practices for Low-Cost Implementation
    Keep up with the latest business and technology news and information! Visit Internet.com.



    JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
    Avaya Article: How to Feed Data into the Avaya Event Processor
    Microsoft Article: Install What You Need with Win Server ‘08
    HP eBook: Putting the Green into IT
    Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
    Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
    Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
    Avaya Article: Setting Up a SIP A/S Development Environment
    IBM Article: How Cool Is Your Data Center?
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    Intel Video: Are Multi-core Processors Here to Stay?
    On-Demand Webcast: Five Virtualization Trends to Watch
    HP Video: Page Cost Calculator
    Intel Video: APIs for Parallel Programming
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Sun Download: Solaris 8 Migration Assistant
    Sybase Download: SQL Anywhere Developer Edition
    Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
    Red Gate Download: SQL Compare Pro 6
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
    eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
    IBM Article: Collaborating in the High-Performance Workplace
    HP Demo: StorageWorks EVA4400
    Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES