Security Information

Computer Viruses, Worms, and Hoaxes


In recent days, I was one of the unfortunate persons to receive the "Mydoom" worm emails. Not just one, but at least forty appeared in my popserver mailbox. As frustrating as it was deleting all of these nasty little boogers, I realized that some of these "worm" emails even came from persons I knew - or so I thought I knew.

The problem with the "Mydoom" email worm is that it specifically targets email addresses with the following extensions:

  • .htm
  • .sht
  • .php
  • .asp
  • .dbx
  • .tbb
  • .adb
  • .pl
  • .wab
  • .txt
Furthermore, it sends "get" requests to target domains and uses direct connections to port 80. It will also attempt to send email messages using its own SMTP engine. The worm is successful by using a mail server that a recipient uses or local server as well. Some strings to these target domain names are:
  • gate.
  • ns.
  • relay.
  • mail1.
  • mxs.
  • smtp.
  • mail.
  • mx.

The "Mydoom" worm will have subject headings such as:

  • "Returned Mail"
  • "Delivery Error"
  • "Status"
  • "Server Report"
  • "Mail Transaction Failed"
  • "Mail Delivery System"
  • "Hello/hello"
  • "Hi/hi"

What persons need to realize is that even if you "know" the sender, you must make absolutely sure that any attachments are specifically clarified from the sender before you attempt to open these suspect emails. Most worms and viruses are spread directly through attachments. Unless you are expecting an attachment from a person you know, be cautious. Do NOT open attachments unless you are absolutely positive that your known correspondent has actually sent it to you. Another thing to remember is that the "Mydoom" worm ranges from 6,144 bytes to 29,184 bytes in size and can affect Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, and Windows XP. Luckily, if you have DOS, Linux, Macintosh, OS/2 or UNIX, your systems will not be affected by the MyDoom worm.

For those of you who share files through Kazaa, there is a new worm with aliases such as Worm.P2P.Apsiv (Kaspersky) and W32/Apsiv.worm!p2p (McAfee) and seemingly affects Windows systems 2000, 95, 98, Me, NT, Server 2003 and Windows XP. The damage profile has not yet been assessed, but it would be a good idea to steer clear of this one as well.

"Keylogger.Stawin" is probably one of the nastiest viruses as it attempts to steal a user's online banking information. A Trojan is distributed through email messages with the subject line, "I still love you," and has a "message.zip" attachment. Affecting the same vunerable systems as mentioned above, Keylogger records keystrokes and has the ability to steal personal, financial information. A few systems that Keylogger monitors are window titles such as "PayPal," "Logon," and numerous other window titles associated with banking logins.

Common Hoaxes

A popular hoax circulating the Internet is an email titled, "FREE M &M's." Sorry guys - no M & M's here. More recently, you may have received the "Life is Beautiful" virus ... er, hoax. The "Life is Beautiful" virus is not real and should be ignored. This is only a scare tactic that causes unwarranted fears and concerns.

In closing, the Internet is a massive electronical world filled with infinite bits of information. When using your "key" to this magnificent but vast window of versatile knowledge, it pays to use logic when distinguishing hoaxes from real threats such as viruses and worms.

  • To learn more about current viruses and worms, visit: http://search.symantec.com/custom/us/query.html
  • For an updated listing of current email hoaxes, go to: http://securityresponse.symantec.com/avcenter/hoax.html

Copyright 2004 - All Rights Reserved
Computer Viruses, Worms and Hoaxes
by C. Bailey-Lloyd/LadyCamelot

About the Author: C. Bailey-Lloyd/LadyCamelot is the Public Relations Director & Writer for Holistic Junction -- Your source of information for Holistic Practitioners; Naturopathic Schools, Massage Therapy Schools, and Reflexology Schools; Alternative Healthcare; Insightful Literature and so much more!

NOTICE: Article may be republished free of charge as long as Author Resource Box (above) is included, and ALL Hyperlinks REMAIN in tact and active.


MORE RESOURCES:

How the NSA Took Linux To the Next Level
Slashdot - 7 hours ago
In RBAC, permissions are provided based on roles that are granted by the security system. The concept of a role differs from that of a traditional group in ...
Anatomy of Security-Enhanced Linux (SELinux) OS News
all 1,730 news articles


Private security firms say no way to meet demand of 2010 Winter Games
The Canadian Press, VANCOUVER - 9 hours ago
VANCOUVER — There's no way the private security industry can meet the demands from either Olympic organizers or the RCMP for help during the 2010 Winter ...
RCMP checking into downtown Vancouver hotel for 2010 Olympic Games The Canadian Press
all 32 news articles


Times Colonist

No need to check background of cabinet spouses, partners, says Day
The Canadian Press, OTTAWA - 8 hours ago
OTTAWA — Public Safety Minister Stockwell Day says there's no need to run security checks on the spouses or partners of federal cabinet ministers, ...
Foreign Affairs Minister Maxime Bernier under fire CTV.ca
Minister to face grilling by Commons over judgment Globe and Mail
Bloc calls for Bernier security probe Toronto Star
Canada.com - The Gazette (Montreal)
all 322 news articles


Secure Computing delivers security gateway virtual appliances for ...
Al-Bawaba, Jordan - 2 hours ago
Secure Computing Corporation (Nasdaq: SCUR), a leading enterprise gateway security provider, has announced it is working with VMware to provide customers ...


Rebate excludes many taxpayers with foreign spouses
The Associated Press - 9 hours ago
But Shelat is married to a foreigner who still hasn't completed the often years-long process that allows her to apply for a Social Security number. ...


China's biggest city beefs up subway security check
Xinhua, China - 1 hour ago
The increased workforce was expected to help speed up security checks during work day rush hours to ensure smooth traffic flow as well as improve Metro ...


Peninsula On-line

IB blames 'slack' BSF for infiltration
Times of India, India - 7 hours ago
It is fairly common for security forces engaged in counter-terrorism operations to lower their guard during periods of lull. What is also common is that ...
Samba encounter ends, six civilians, 2 jawans killed Hindu
Jammu terrorist attack defies BSF claims Merinews
Sambha encounter over, militants holed up inside a house killed Thaindian.com
CNN-IBN - Times of India
all 133 news articles


China's energy security moves it closer to the Middle East
Daily Star - Lebanon, Lebanon - 5 hours ago
Therefore China has a significant interest in the Middle East, and any changes in the situation there will affect China's energy security. ...


The Southern Ledger

Security source: Terrorists firing mortars to avoid retaliation
Ynetnews, Israel - 5 hours ago
'We cannot continue living under fire without proper fortification,' one resident says The problem, according to a security source, stems from the ...
Negev council head: Government busy with investigations instead of ... Ynetnews
all 179 news articles


Canada.com

Gov't of Sudan to lodge complaint to UN Security Council against Chad
Xinhua, China - 6 hours ago
KHARTOUM, May 11 (Xinhua) -- Sudan announced on Sunday it would lodge an official complaint to the United Nations Security Council against Chad's government ...
Sudan steps up security, says Darfur rebels advance Reuters
Sudan Imposes Curfew to Hunt for Darfur Rebels in Capital; Cuts ... Voice of America
Sudan cuts ties with Chad The Associated Press
Yahoo! Italia Notizie - New York Times
all 758 news articles

Security - Google News

home | site map

Visit our other sites:
GamesBlog | GamingDepot | GimmeaRide | GimmeNetwork | Golf Biz | HotorNotGame | I Want Computers | I Want Games | I Want Hosting | I Want Music | I Want Security | JokeBox | ScriptShock | Wantedfonts | Webalize
© 2006