Tag: virus

  • Network Security guide for the home or small business network – Part 3 – Antivirus

    Ok, the first two entries thus far, hardware firewalls and software firewalls have been fairly operating system independant. A hardware firewall is best, but if that’s not possible a software firewall will do until you get a hardware firewall setup. This next item is (currently) a must have for Windows users. However, Mac and Linux users may see the day soon when it is an essential part of security for those systems as well. These days I am stunned to see PC’s that don’t have an antivirus program installed.

    (more…)

  • F-secure list of sober virus urls

    When the news was first out that an antivirus firm (f-secure) had cracked the psuedo-random algorithm that the sober worm uses to determine where to download “updates” from, they said that they had previously notified German authorities where the free hosting sites were located so that they could deal with the sites. I did find that they have announced a list of the addresses for the January 5th update (and the January 6th as well.)

    (more…)

  • More details on Sober worm

    There’s a bit more detail in this betanews article on the sober worm. They basically say that the next expected “release” is January 8th, that f-secure has cracked the “code” of the worm. You see it appears that the URL’s that new versions of the worm are downloaded from are not hardcoded, but “psuedorandom” and they’ve cracked the algorithm the worm uses.

    (more…)

  • New variation of Sober virus coming in January

    Now, we seem to be getting “coming attractions” previews in virus-land…. Anyway, I’ve read at several sources that we are to expect a new variation on the sober worm around January 5th, 2006. It’s said that the date was chosen to mark the formation of the Nazi Party. In the past, variants have spouted pro-nazi sentiments and redirected users to pro-nazi web sites.

    (more…)

  • Gmail Virus scanning and more

    I saw a link yesterday about Gmail adding virus scanning to their featureset. It’s very good to see, they have very good junk filtering at this point and had a blanket policy that .exe’s were banned (which would stop a good percentage of the bugs.) Anyway, it’s good to see this is added. (I wouldn’t mind if there were a config switch to opt out, to help send samples to virustotal or wherever, but there are other ways to do that so it’s not a big deal and probably better that it’s not optionally disabled.) Article (brief) here.

    (more…)

  • The virus arms race? is locking down systems the key?

    The securityfix has a post on the “dirty little secret” about antivirus. Eugene Kaspersky of Kaspersky antivirus has posted an introspective article on the antivirus industry and it’s current problems. The biggest problem with antivirus is that it’s always one step behind the virus writers. Antivirus software only can prevent you being infected by those viruses that the antivirus software knows about. In other words a quick, fast spreading infection can hit you anywhere between hours-days before your AV vendor has an update.

    (more…)

  • FBI / CIA virus

    Well… the media has taken the drab name of w32sober.X@mm or w32sober.x or w32sober.y, W32/Sober.AD-mm or any of those other drab names that we’ve been looking at the last week and dubbed the latest big virus, the FBI/CIA virus…. and it’s gotten a lot of press the last few days. I suspect as people head back to work from Thanksgiving, we may see a slight bump in traffic. (Bringing infected laptops into the network maybe? or just home/office users getting back to work…)

    (more…)

  • New Sober variants..

    Ok – there are some new variants on the Sober worm circulating. I received one on an address that’s unfiltered (no virus/spam filtering) and must say, I can see people being duped into looking at the attachment. Sans has a post on it.. Sarc is calling it W32sober.x@mm and rates it at a threat level of three. I’ve seen many outlets tag it as sober.y

    (more…)

  • Keyloggers a growing problem

    It’s interesting some years ago when viruses on Windows machines were SOOOO plentiful it seemed like that’s all I spent my time cleaning up, I thought… “you know, most viruses are prankster-ish programs. They rearrange icons, maybe cause Windows to crash, or send random files out to others, but they could be MUCH worse.” Since then, we’ve seen viruses used as delivery tools for mail relays (so that spammers can have more “safe havens”, we’ve seen viruses bring in spyware, both of the last two for “fun and profit”. I don’t know that we’ve really seen the WORST that a virus could be designed to do. However, I’m afraid we’re getting there.

    (more…)

  • Sony BMG is still having a bad week….

    Unfortunately a LOT of people that have bought Sony-BMG cds (or borrowed, whatever…) are going to have some headaches too. By stock in Tylenol or Aleve or something…. anyway… here’s todays roundup of Sony Rootkit news. Including a virus borrowing the gift of SONY…

    First up is some “backstory” that reminds us of Sony’s attitudes in the past on the issue of piracy and what should be done about it, along with the precient “I think most people don’t know what a rootkit is” satatement.

    (more…)