Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

Tracking System
Tracking System
Private Detectives
Quality Security Services in California
Fleet Management
Hosting

Popular content

Last viewed:

  • The SSD Project | EFF Surveillance Self-Defense Project
  • Is China Creating the World's Largest Botnet Army?
  • Cracking open the cybercrime economy
  • New Participatory Project: Updating Profiles on Think Tanks
  • Head of Greek privacy watchdog resigns over police use of cameras to monitor protests
  • Blog Trackback Spam Swamps Web Sites - March 2007
  • Popular Websites Vulnerable to Cross-Site Request Forgery Attacks

tags in Topics

Activists Alert Anonymity Companies Congress Copyright Court (US) Databases Data Mining Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Weekly Report on Viruses and Intruders

Submitted by MacRonin on April 24, 2007 - 7:43pm
  • Exploits
  • Microsoft Windows
  • Privacy
  • Scams
  • Security
  • SPAM

Weekly Report on Viruses and Intruders:This week's report focuses on the Artesimda Trojan and a worm, Rinbot.Q, that uses several vulnerabilities to spread. It also covers a new combined attack involving members of the Spamta family.

This attack, performed by the Spamta.WF worm and the SpamtaLoad.DW Trojan, consists of the following: when the Trojan infects a computer, it downloads the worm, which, in turn, collects all of the e-mail addresses it finds on the computer and sends them a message containing the SpamtaLoad.DW Trojan. The process then starts all over again.

SpamtaLoad.DW is installed on computers with a text file icon, although it is really an executable file. This aims at enticing users to open the document and run the Trojan inadvertently. To divert the user's attention, SpamtaLoad.DW displays an error message.

Rinbot.Q exploits two Windows vulnerabilities (one affecting DNS Servers and the second affecting the Local Security Authority Subsystem -- LSASS -- process). This worm has downloader features, enabling it to download other malware onto the affected computer. When run, Rinbot.Q checks to see if there are certain network monitoring programs installed on the system. If it finds any, it deletes them. It also ends processes belonging to several rootkit detection tools to make detection more difficult.

Rinbot.Q can also spread through shared network drives and alters the Windows registry to ensure it is run on every system startup.

Artesimda is a dangerous Trojan. When run, it creates an account in Windows with its own user name (Adminestrator) and password. Then it steals all kinds of data from the computers it infects: e-mail and other programs' passwords, hardware and software data, IP address, e-mail addresses, etc.

(Read Original Article - Via GT: Security and Privacy.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • Domain Names Can't Defend Themselves
  • Hacker Disables More Than 100 Cars Remotely
  • Judges Approves $9.5 Million Facebook ‘Beacon’ Accord
  • Hooking Up The Big Brother Machine... And Fighting It
  • Court: State Can Dump Non-Sex Offenders Into Registry
  • How Privacy Vanishes Online
  • Undercover Feds on Social Networking Sites Raise Questions
  • FBI Uses Fake Facebook Profiles To Spy On Suspects
  • Lawrence Lessig: Citizens Unite
  • Case Report – BCCA says aerial surveillance by telphoto zoom lens not a search
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.