Security Information

Computer Viruses, Worms, and Hoaxes


In recent days, I was one of the unfortunate persons to receive the "Mydoom" worm emails. Not just one, but at least forty appeared in my popserver mailbox. As frustrating as it was deleting all of these nasty little boogers, I realized that some of these "worm" emails even came from persons I knew - or so I thought I knew.

The problem with the "Mydoom" email worm is that it specifically targets email addresses with the following extensions:

  • .htm
  • .sht
  • .php
  • .asp
  • .dbx
  • .tbb
  • .adb
  • .pl
  • .wab
  • .txt
Furthermore, it sends "get" requests to target domains and uses direct connections to port 80. It will also attempt to send email messages using its own SMTP engine. The worm is successful by using a mail server that a recipient uses or local server as well. Some strings to these target domain names are:
  • gate.
  • ns.
  • relay.
  • mail1.
  • mxs.
  • smtp.
  • mail.
  • mx.

The "Mydoom" worm will have subject headings such as:

  • "Returned Mail"
  • "Delivery Error"
  • "Status"
  • "Server Report"
  • "Mail Transaction Failed"
  • "Mail Delivery System"
  • "Hello/hello"
  • "Hi/hi"

What persons need to realize is that even if you "know" the sender, you must make absolutely sure that any attachments are specifically clarified from the sender before you attempt to open these suspect emails. Most worms and viruses are spread directly through attachments. Unless you are expecting an attachment from a person you know, be cautious. Do NOT open attachments unless you are absolutely positive that your known correspondent has actually sent it to you. Another thing to remember is that the "Mydoom" worm ranges from 6,144 bytes to 29,184 bytes in size and can affect Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, and Windows XP. Luckily, if you have DOS, Linux, Macintosh, OS/2 or UNIX, your systems will not be affected by the MyDoom worm.

For those of you who share files through Kazaa, there is a new worm with aliases such as Worm.P2P.Apsiv (Kaspersky) and W32/Apsiv.worm!p2p (McAfee) and seemingly affects Windows systems 2000, 95, 98, Me, NT, Server 2003 and Windows XP. The damage profile has not yet been assessed, but it would be a good idea to steer clear of this one as well.

"Keylogger.Stawin" is probably one of the nastiest viruses as it attempts to steal a user's online banking information. A Trojan is distributed through email messages with the subject line, "I still love you," and has a "message.zip" attachment. Affecting the same vunerable systems as mentioned above, Keylogger records keystrokes and has the ability to steal personal, financial information. A few systems that Keylogger monitors are window titles such as "PayPal," "Logon," and numerous other window titles associated with banking logins.

Common Hoaxes

A popular hoax circulating the Internet is an email titled, "FREE M &M's." Sorry guys - no M & M's here. More recently, you may have received the "Life is Beautiful" virus ... er, hoax. The "Life is Beautiful" virus is not real and should be ignored. This is only a scare tactic that causes unwarranted fears and concerns.

In closing, the Internet is a massive electronical world filled with infinite bits of information. When using your "key" to this magnificent but vast window of versatile knowledge, it pays to use logic when distinguishing hoaxes from real threats such as viruses and worms.

  • To learn more about current viruses and worms, visit: http://search.symantec.com/custom/us/query.html
  • For an updated listing of current email hoaxes, go to: http://securityresponse.symantec.com/avcenter/hoax.html

Copyright 2004 - All Rights Reserved
Computer Viruses, Worms and Hoaxes
by C. Bailey-Lloyd/LadyCamelot

About the Author: C. Bailey-Lloyd/LadyCamelot is the Public Relations Director & Writer for Holistic Junction -- Your source of information for Holistic Practitioners; Naturopathic Schools, Massage Therapy Schools, and Reflexology Schools; Alternative Healthcare; Insightful Literature and so much more!

NOTICE: Article may be republished free of charge as long as Author Resource Box (above) is included, and ALL Hyperlinks REMAIN in tact and active.


MORE RESOURCES:

ABC News

Blasts Hit Security HQs in Syrian City Aleppo
ABC News
Two explosions targeted security compounds in the Syrian city of Aleppo on Friday, state media reported, saying 25 people were killed and 175 wounded in a major city that has so far largely stood by President Bashar Assad in the nearly 11-month-old ...
Syria Crisis: Bombs Hit Security Headquarters In AleppoHuffington Post
Syria unrest: Explosions in Aleppo 'kill 25'BBC News
Bomb blasts bring death to Syria's AleppoReuters
Chicago Tribune
all 524 news articles »


Afghan private security handover looking messy
Boston.com
By Heidi Vogt AP / February 10, 2012 KABUL, Afghanistan—The push by Afghanistan's president to nationalize legions of private security guards before the end of March is encouraging corruption and jeopardizing multibillion-dollar aid projects, ...

and more »


AFP

Report says 2 Tibetans killed by security forces
San Jose Mercury News
By SCOTT McDONALD AP BEIJING—Chinese security forces shot dead two Tibetan brothers who had been on the run since taking part in anti-government protests two weeks ago in southwest China, a US-funded broadcaster reported Friday.
Security forces shoot dead two Tibetans: reportAFP

all 318 news articles »


Newsday

Blasts hit security HQs in Syrian city Aleppo
Newsday
Click here Blasts hit security HQs in Syrian city Aleppo Originally published: February 10, 2012 3:41 AM Updated: February 10, 2012 6:02 AM By The Associated Press BASSEM MROUE (Associated Press) (AP) -- Two explosions targeted security compounds in ...

and more »


Russian security agency says military officer sentenced to 13 years for ...
Washington Post
MOSCOW — A Russian security agency says a Russian military officer has been convicted of passing missile secrets to the CIA and sentenced to 13 years in prison. The Federal Security Service, the main successor to the KGB, said Lt.-Col.

and more »


New York Daily News

New airport security rules will let some passengers keep their shoes, belts on
New York Daily News
AP Travelers go through a security checkpoint at LaGuardia, one of the airports adopting the new passenger screening program. Are you interested in the new passenger screening program? WASHINGTON — A new passenger screening program to make check-in ...
TSA to expand PreCheck program to speed up airport security linesLos Angeles Times
O'Hare to get expedited security screeningChicago Tribune
BWI among airports to adopt prescreening programBaltimore Sun (blog)
Reuters -Boston Globe -Boston.com
all 803 news articles »


Nigerian runaway bomb suspect recaptured: source
Reuters
| ABUJA (Reuters) - Nigerian security forces recaptured on Friday the main suspect in a deadly Christmas Day bomb attack who escaped from police custody last month, a state security source said. Kabiru Sokoto's escape on January 18 was described by ...

and more »


First Security Group Completes Transformation of Executive Management Team
MarketWatch (press release)
CHATTANOOGA, Tenn., Feb 09, 2012 (BUSINESS WIRE) -- With the appointment of three new executive vice presidents, First Security Group, Inc. /quotes/zigman/6590222/quotes/nls/fsgi FSGI +0.89% has completed the restructuring of its executive management ...

and more »


Microsoft Ruining Valentine's Day with Nine Security Bulletins
PCWorld (blog)
Microsoft revealed today that there are nine new security bulletins slated for next Tuesday. Happy Valentine's Day? Of the nine security bulletins, four are rated as Critical and the remaining five are all Important. Based on the limited information ...
Microsoft to issue more critical patches next week for Win7 than XPComputerworld
Patch Tuesday heads-up: 21 vulnerabilities, including 'critical' IE bulletinZDNet (blog)

all 43 news articles »


NFC World

Security flaw in Google Wallet PIN identified
msnbc.com
By Matt Liebowitz A security researcher has found a serious flaw in Google Wallet's PIN protection that, in seconds, could enable an attacker to view everything in the owner's digital wallet, including credit card numbers and transaction history.
Google Wallet Security Concerns RaisedPCWorld
zvelo Researcher Discovers Google Wallet PIN Security VulnerabilityMarketWatch (press release)

all 78 news articles »

Google News

home | site map
© 2006