New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 990
Comments: 20
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image trj: Advisories!: Graybird-A image
Trojans
Trojan preying on Lovsan hits inboxes

By Edward Hurley, SearchSecurity.com News Writer
15 Aug 2003, SearchSecurity.com

A new Trojan has emerged that preys off people's fears about the Lovsan worm.

Graybird-A is a backdoor Trojan, which travels by e-mail, and purports to be an update to protect against the worm. If installed, it could allow outsiders access to infected systems, antivirus software vendor Sophos said in an advisory.

Normally, Graybird wouldn't likely garner much attention (or be particularly successful), but Lovsan fears could make users fall prey since they're being bombarded with warnings about patching their systems.

Microsoft has had to take its patch download page down because the worm is set to launch a distributed denial of service attack on it on Aug. 16. The necessary patches are easy enough to find. There are multiple links to them on Microsoft's home page.

Experts always advise computer users to never install what purport to be patches attached to e-mails.

Never trust unsolicited executable code that arrives via e-mail, said Chris Belthoff, senior security analyst at Sophos, Inc., in a statement. Businesses should consider blocking all executable code at the e-mail gateway so it cannot reach their users.

The message carrying Graybird arrives looking like this:

Subject line: updated

Message text: Dear customer:

At 11:34 A.M. Pacific Time on August 13, Microsoft began investigating a worm reported by Microsoft Product Support Services (PSS). A new worm commonly known as W32.Blaster.Worm has been identified that exploits the vulnerability that was addressed by Microsoft Security Bulletin MS03-026.

Download the attached update program. To begin the download process, do one of the following:

To download the attached program to your computer for installation at a later time, click Save or Save this program to disk.then run it. If you have any problem, connect to us immediately.

Attached file: 03-26updated.exe

This is not the first time that a malware maker tapped fears about worms to get people to install malicious code. In March, W32/Gibe-A arrived as an attached executable to what appears to be an official Microsoft alert e-mail.

TechTarget
Posted on Monday, 18 August 2003 @ 13:00:00 EDT by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· More about Trojans
· News by phoenix22


Most read story about Trojans:
Lover Spy

image
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register