Click here

Malware: Archive: November 2003 

Trojan Emails Encoded Local Passwords to Hacker

McAfee issued a low-level alert Wednesday for PWS-LDPinch, a password stealing Trojan designed to email the encoded local passwords to the Trojan author.

Marketers Relieved At Can Spam Bill's Progress

They might prefer no law at all, but a single federal law clears the way for business as usual for most legitimate marketers.

Lawmakers: Spam Bill Is a Turkey

Call them five against the tide of support for the national anti-spam law: federal lawmakers who support tougher state laws.

Trojan Mass-Spammed in 'Dear Mary' Email

Several security vendors Tuesday issued alert for a Backdoor Trojan commonly known as Sysbug, which retrieves system information and allows unauthorized access to the compromised computer.

U.S. Named as Biggest Spammer, Spammee

An annual United Nations report identified the country as the biggest victim of spam and digital attacks, while also leading the globe in sending unwanted e-mail.

Anti-Spam Bill Clears Senate

Technical issues force another House vote; Bush still expected to sign bill by end of year.

Worm has Trojan-Like Characteristics

Panda Software Monday issued an alert for Randex.BF, a worm with Trojan characteristics that spreads across networks.

Bush Likely to Sign Anti-Spam Bill by Jan. 1

No Senate opposition expected for opt-out legislation that pre-empts tougher state laws.

Mimail Becomes Fourth Most Damaging Virus

Even though the Mimail virus didn't achieve the threat level or the media coverage that its malicious code cohorts, Sobig and Blaster, did a few months ago, it has become the fourth most damaging virus of all times.

Spam Driving Away 25% of Emailers

Spam is taking its toll, driving 25 percent of Americans away from using email. A new report shows that people are actually using email less because they don't want to deal with the digital scourge.

Worm Exploits DCOM RPC Vulnerability

Symantec Friday issued an alert for W32.Bolgi.Worm, a worm that exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 445.

Putting Spyware on the Hook

Preparing for an FTC suit, an Internet privacy organization launches an online action to collect histories of spyware gone wrong.

Cyber Crime Sweep Nets Over 100 Arrests

Federal, local and overseas authorities team up to crack down on online crimes involving fraud, software piracy and fencing stolen goods.

Worm Propagates via HTML E-mail

Sophos Thursday issued an alert for JS/Flea-B, a worm that propagates via HTML email.

AntiOnline Security Spotlight: Ironclad Passwords

More often than not, a weak user password is the only thing standing in the way between an intruder and your company's valuable data. Lay the foundation for a strong password policy with this week's spotlight AO discussion.

Keylogging Trojan Copies Itself to Windows File

Sophos Wednesday issued an alert for Troj/Tofger-A, a keylogging Trojan that copies itself to the file system.exe in the Windows folder in order to run automatically when Windows starts up.

Cisco Declares War on Network Worms

The networking giant teams up with a trio of anti-virus specialists to thwart the spread of malicious viruses.

New Mimail Variant Spreading at High Rate

Several security vendors Tuesday issued high alerts for W32/Mimail-J, a mass-mailing worm very similar to an earlier variant, W32/Mimail-I.

Clock Ticking on Spam, 'Net Access Bills

With House and Senate adjournment dates looming, passage of 2003 tech legislative centerpieces is threatened.

GAO Report Targets IRS Security Weaknesses

Persistent problems place confidential data at risk of hack attacks and inappropriate disclosure.

The Firewall and the Wandering Workers

Corporations with strong firewall defenses didn't take long to figure out that their greatest threat was from employees who log on from outside the building. Executive Tech columnist Brian Livingston outlines some new solutions to this security hazard.

Worm Attempts to Copy Itself to Windows Folder

W32/Opaserv-V is a worm that spreads by copying itself to network shares, according to Sophos, which issued an alert Monday.

Fending Off a Vicious Attack

eSecurityPlanet's Phil Hollows describes a hypothetical virus attack on a company's email system. Sound possible? Sound familiar? Take a look at what you can do to make sure it doesn't happen to you.

Gates' New Window On Seamless Computing

The chairman and chief software architect of Microsoft shows off the company's new anti-spam filtering technology for Comdex attendees -- and talks security.

Email Worm Sends Fake Message About PayPal Account

Several antivirus vendors Friday issued threats for W32/Mimail-I, a worm that spreads via email using addresses harvested from the hard drive of a computer.

Experts to Marketers: Spam Lawsuits are Coming

Bigfoot Interactive's 'Spam Summit' in New York finds marketers bracing for the impact of a far-reaching California law.

PayPal Phishers Turn to E-mail Viruses

Internet scammers have come up with a new -- and startling -- technique to 'phish' for sensitive information.

Stopping Spam before the Gateway: Honeypots

There's more than one way to stop a spammer. Our author discovers that like pesky flies, spammers just can't resist the allure of honey.

Ad Groups Urge Congress To Pass Anti-Spam Law

Three trade organizations push for quick action on federal legislation.

AntiOnline Security Spotlight: How Hackers Pick Their Victims

Are you an easy target? Delve into the factors that motivate an attacker to breach your network's security.

Trojan Runs in Background, Allows Unauthorized Access

Troj/Muly-A is a backdoor Trojan that runs in the background as a service process and allows unauthorized remote access to the computer over a network, according to Sophos, which issued an alert Thursday.

Trojan May Arrive as Citibank Email

Panda Software has issued a medium level threat alert for Webber.C, a Trojan that, when installed on a computer, downloads a file purporting to be from Citibank, from the Internet.

Trojan Contains Two Components

Sophos Tuesday issed a low-level alert for Troj/Webber-C, a backdoor Trojan with two components.

Trojan Opens Random Port to Get Input From Intruder

Sophos Monday reported receiving several copies of Troj/BDSinit-A, a backdoor Trojan.

New Worm Using Pornographic Names

Following on the heels of W32/SpyBot-W Thursday, Sophos issued an alert Friday for W32/SpyBot-V, also a peer-to-peer worm as well as a backdoor Trojan that copies itself into the Windows system folder.

Worm Copies Itself to File in System Folder

W32/Spybot-W is a peer-to-peer worm that spreads via network drives, email, Messenger and the IRC network, according to Sophos, which issued an alert Thursday.

Will Microsoft's 'Hang 'em High' Plan Work?

The security community is reacting with both incredulity and excitement to the news that Microsoft is putting a quarter-of-a-million-dollar bounty on the heads of the virus writers behind the highly destructive Blaster and Sobig worms.

AGs Want to Can the Can Spam Bill

Now, they tell us. Saying the Can Spam Act of 2003 passed the Senate too quickly for them to respond, a group of attorneys general begs the House not to pass the bill.

FTC Blocks Pop-Up Spam 'Scam'

Agency obtains restraining order against San Diego firm exploiting vulnerability in Microsoft's Window Messenger.

The Deadly Duo: Spam and Viruses, October 2003

While one firm measured a decline in the monthly amount of spam, another report finds the economic damage to be among the worst ever recorded.

Spam Cleaning with the Big Boys

Server-based anti-spam protection isn't just a good idea, it's the only feasible idea for ISPs and businesses.

Worm Spreads by Emailing Itself via SMTP

W32/Yaha-X is a worm that spreads by emailing itself via SMTP to addresses extracted from various sources on the victim's computer (e.g. the Windows Address Book) and by copying itself to network shares and other fixed drives connected to the computer.

Microsoft Posts Bounties for Cyber Saboteurs

In collaboration with FBI and Secret Service, Redmond offers $500,000 rewards for instigators of MSBlast and Sobig.

Mimail Variants Continue to Spread

Variants of the Mimail worm continued to spread Tuesday, security vendors reported.

Change of Guard in New List of Worst Viruses

Two viruses that pose as security patches issued from Microsoft have outdone malicious competitors like Klez, Bugbear and Blaster for the top two seats in October's top virus charts.

Mimail Worm, Variants, Launch DoS Attacks

Several security vendors over the weekend and Monday elevated the threat level for the Mimail worm and a number of variants that when run, infect the host computer then email themselves (using their own SMTP engine) to harvested email addresses from the victim's machine.

Worm Hitting Anti-Spam Sites with DoS Attacks

Five new variants of a mass-mailing worm are infecting computers around the globe and launching denial-of-service attacks -- some against well-known anti-spam Web sites.