Close

Results 1 to 3 of 3
  1. #1
    Moderator belgareth's Avatar
    Join Date
    Oct 2002
    Location
    Lower Slovobia
    Posts
    7,961
    Rep Power
    8698

    Default Computer Virus Warning released

    visit-red-300x50PNG
    Zafi.B: Virus of Babble



    Tue Jun 15, 4:31 PM ET







    Erika Morphy,

    www.enterprise-security-today.com




    A new virus sweeping the

    Internet has climbed its way to the top of the antivirus watchers' charts within a matter of days. Along with the

    usual gambits to get people to open unfamiliar e-mail, the virus, called "Zafi.B," customizes its language to the

    recipient's default language setting, Panda Software CTO Patrick Hinojosa told NewsFactor.








    "The social-engineering tactics were really thought out

    carefully, and that is why it is spreading so quickly," Hinojosa says. The virus attempts to shut down a PC's

    antivirus and firewall protections before the recipient can receive an updated signature file. Also, there appears

    to be a denial-of-service attack built in the virus to disable a certain Hungarian-based Web site. "This, of course,

    leads one to believe the virus writer is either Hungarian or has a grudge against some of these institutions."







    The language factor allows the virus to

    spread around the world faster. French and German speakers, for example, seem to let their guard down more easily

    with e-mail that comes to them in French or German, as opposed to English, Hinojosa says.








    Medium Risk







    McAfee's AVERT (Anti-virus and Vulnerability Emergency Response Team), the research division

    of Network Associates (NYSE: NET - news), reports that the worm constructs messages using its own SMTP engine,

    spoofing the From: address. It also attempts to propagate via P2P, by copying itself to folders on the local system

    that contain "share" or "upload" in the folder name.








    McAfee has raised the risk assessment to medium on Zafi.B.







    Copies Itself Twice







    The worm searches for e-mail addresses on the local hard disk, according to McAfee,

    harvesting addresses from files with the following extensions: .htm, .wab, .txt, .dbx, .tbb, .asp, .php, .sht, .adb,

    .mbx, .eml and .pmr. Harvested addresses are stored in five files in the system32 folder using random names and the

    file extension .dll.






    "After being executed,

    Zafi.b copies itself twice to the windir system32 folder using a random name and .exe and .dll extension. The worm

    copies itself to directories on the C: drive containing one of the following strings: "share" or "upload"; and uses

    one of the following file names: Total Commander 7.0 full_install.exe or winamp 7.0 full_install.exe," McAfee said.




  2. #2
    Doctor of Scentology DrSmellThis's Avatar
    Join Date
    Jun 2002
    Location
    Oregon
    Posts
    6,233
    Rep Power
    8848

    Default

    There's never a shortage of

    reasons to be paranoid! Tanks for the hedz up.
    DrSmellThis (creator of P H E R O S)

  3. #3
    Moderator belgareth's Avatar
    Join Date
    Oct 2002
    Location
    Lower Slovobia
    Posts
    7,961
    Rep Power
    8698

    Default

    Quote Originally Posted by DrSmellThis
    There's

    never a shortage of reasons to be paranoid! Tanks for the hedz up.
    You're welcome, DST.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Need Help with Computer Virus
    By bjf in forum Open Discussion
    Replies: 24
    Last Post: 04-27-2004, 02:26 PM
  2. Virus Warning!
    By belgareth in forum Open Discussion
    Replies: 2
    Last Post: 01-20-2004, 12:24 PM
  3. About warning labels
    By belgareth in forum Humor
    Replies: 0
    Last Post: 01-12-2004, 03:21 PM
  4. New Alcohol Warning Labels
    By Sexyredhead in forum Humor
    Replies: 20
    Last Post: 06-25-2003, 09:04 AM
  5. New Virus Alert: C-Nile Virus
    By upsidedown in forum Humor
    Replies: 1
    Last Post: 03-10-2003, 05:54 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •