Friday, June 06, 2014

New Computer Virus List

GEORGE DUBYA BUSH VIRUS: Causes your computer to keep looking for viruses of mass destruction.

ANITA HILL VIRUS: Lies dormant for ten years.
OPRAH WINFREY VIRUS: Your 200MB hard drive suddenly shrinks to 80MB, and then slowly expands back to 200MB.
AT&T VIRUS: Every three minutes it tells you what great service you are getting.
MCI VIRUS: Every three minutes it reminds you that you're paying too much for the AT&T virus.
PAUL TSONGAS VIRUS: Pops up on December 25 and says, "I'm not Santa Claus."
JERRY BROWN VIRUS: Blanks your screen and begins flashing an 800 number.
AL GORE VIRUS: Causes your computer to keep counting, recounting, recounting ... ad nauseam.
MADONNA VIRUS: If your computer gets this virus, lock up your dog!
PAUL REVERE VIRUS: This revolutionary virus does not horse around. It warns you of impending hard disk attack---once if by LAN, twice if by C:>.
BILL CLINTON VIRUS: This virus mutates from region to region and we're not exactly sure what it does.
POLITICALLY CORRECT VIRUS: Never calls itself a "virus", but instead refers to itself as an "electronic microorganism."
WARREN COMMISSION VIRUS: Won't allow you to open your files for 75 years.
RIGHT TO LIFE VIRUS: Won't allow you to delete a file, regardless of how old it is. If you attempt to erase a file, it requires you to first see a counselor about possible alternatives.
RONALD REAGAN VIRUS: Saves your data, but forgets where it is stored.
RICHARD NIXON VIRUS: Also known as the "Tricky Dick Virus", you can wipe it out but it always makes a comeback.
BILL CLINTON VIRUS #2: Gives you a permanent hard drive, with no memory.
ROSS PEROT VIRUS: Activates every component in your system, just before the whole darn thing quits.
UK PARLIAMENT VIRUS: Splits the screen into two with a message in each half blaming other side for the state of the system.
DAVID DUKE VIRUS: Makes your screen go completely white.
MARIO CUOMO VIRUS: It would be a great virus, but it refuses to run.
MICHAEL JACKSON VIRUS: Hard to identify because it is constantly altering its appearance. This virus won't harm your PC, but it will trash your car.
TED TURNER VIRUS: Colorizes your monochrome monitor.
ARNOLD SCHWARZENEGGER VIRUS: Terminates and stays resident. It'll be back.
DAN QUAYLE VIRUS #2: Their is sumthing rong wit your komputer, ewe jsut cant figyour out watt!
GOVERNMENT ECONOMIST VIRUS: Nothing works, but all your diagnostic software says everything is fine.
NEW WORLD ORDER VIRUS: Probably harmless, but it makes a lot of people really mad just thinking about it.
TED KENNEDY VIRUS: Crashes your computer but denies it ever happened.
FEDERAL BUREAUCRAT VIRUS: Divides your hard disk into hundreds of little units, each of which does practically nothing, but all of which claim to be the most important part of your computer.
GALLUP VIRUS: Sixty percent of the PCs infected will lose 38 percent of their data 14 percent of the time. (plus or minus a 3.5 percent margin of error.)
BILL CLINTON VIRUS #2: Promises to give equal time to all processes: 50% to poor, slow processes; 50% to middle-class processes, and 50% to rich ones. This virus protests your computer's involvement in other computer's affairs, even though it has been having one of its own for 12 years.
TERRY RANDALL VIRUS: Prints "Oh no you don't" whenever you choose "Abort" from the "Abort" "Retry" "Fail" message.
TEXAS VIRUS: Makes sure that it's bigger than any other file.
ADAM AND EVE VIRUS: Takes a couple of bytes out of your Apple.
CONGRESSIONAL VIRUS: The computer locks up, screen splits erratically with a message appearing on each half blaming the other side for the problem.
AIRLINE VIRUS: You're in Dallas, but your data is in Singapore.
FREUDIAN VIRUS: Your computer becomes obsessed with marrying its own motherboard.
PBS VIRUS: Your programs stop every few minutes to ask for money.
ELVIS VIRUS: Your computer gets fat, slow and lazy, then self destructs; only to resurface at shopping malls and service stations across rural America.
OLLIE NORTH VIRUS: Causes your printer to become a paper shredder.
NIKE VIRUS: Just does it.
PAT BUCHANAN VIRUS: Shifts all your output to the extreme right of your screen.
SEARS VIRUS: Your data won't appear unless you buy new cables, power supply and a set of shocks.
JIMMY HOFFA VIRUS: Your programs can never be found again.
CONGRESSIONAL VIRUS #2: Runs every program on the hard drive simultaneously, but doesn't allow the user to accomplish anything.
KEVORKIAN VIRUS: Helps your computer shut down as an act of mercy.
IMELDA MARCOS VIRUS: Sings you a song (slightly off key) on boot up, then subtracts money from your Quicken account and spends it all on expensive shoes it purchases through Prodigy.
STAR TREK VIRUS: Invades your system in places where no virus has gone before.
HEALTH CARE VIRUS: Tests your system for a day, finds nothing wrong, and sends you a bill for $4,500.
GEORGE BUSH VIRUS: It starts by boldly stating, "Read my docs....No new files!" on the screen. It proceeds to fill up all the free space on your hard drive with new files, then blames it on the Congressional Virus.
CLEVELAND INDIANS VIRUS: Makes your 486/50 machine perform like a 286/AT.
LAPD VIRUS: It claims it feels threatened by the other files on your PC and erases them in "self defense".
CHICAGO CUBS VIRUS: Your PC makes frequent mistakes and comes in last in the reviews, but you still love it.
ORAL ROBERTS VIRUS: Claims that if you don't send it a million dollars, it's programmer will take it back.

Friday, February 03, 2006

Feared computer worm not so scary in Asia, Europe

A malicious computer worm intent on creating worldwide headaches on Friday caused relatively little damage in Asia and Europe, although a city in Italy shut down their computers as a precaution.

Experts have warned that the worm, known by the names "Kama Sutra," "C-M-E-24," "BlackWorm," "Mywife.E," or "Nyxem," was set to strike infected computers at midnight, corrupting the most common types of computer files.

But many companies and individuals took precautions, cleaning up and protecting their machines this week, and officials in Asia and Europe say they've found little evidence that the worm has caused any major damage.

"It's been pretty quiet," Mikko Hypponen, chief research officer for Finnish security company F-Secure Corp, told the Associated Press. "We know the word is out there."

"It's well past the deadline but we haven't confirmed any cases of the Kama Sutra in Japan, which suggests we're not looking at a major outbreak,'' said Itsuro Nishimoto, an executive at Tokyo-based computer security company LAC Corp.

In Milan, Italy, technicians switched off more than 10,000 computers after discovering the infection Thursday and decided they didn't have enough time to clean the machines.

"It has spread to all our computers," said Giancarlo Martella, Milan's councilman for technological innovation and public services. "Knowing how destructive it is, we turned off all personal computers to avoid losing our data."

The computer security company LURHQ reported earlier this week that there may be hundreds of thousands of machines already infected with the worm, mostly in India, Peru, Turkey and Italy.

The worm was programmed to go to work as of midnight Friday, Feb. 3 and the third of every month thereafter, overwriting or corrupting the most common types of files -- Microsoft Windows Office documents, Word documents, Excel spread sheets, and PDFs (portable document format).

The creators of the virus have tried to trick people into opening e-mail attachments by falsely claiming they contain pornographic images or videos.

When users click on the attachments, their computers become infected with a worm which burrows itself deep within Microsoft Windows XP, Windows 2000, Windows 98 and Windows ME operating systems.


for more : ctv.ca

Thursday, September 15, 2005

WORM_ZOTOB.N

Malware type: Worm
In the wild: Yes
Destructive: No
Language: English
Platform: Windows 98, ME, NT, 2000, XP, Server 2003
Encrypted: No
Characteristics: Propagates via software vulnerabilities
Overall risk rating: Low

Reported infections: Low
Damage potential: High
Distribution potential: High

Description:

This memory-resident worm propagates by exploiting the Windows Plug and Play vulnerability. For more information, please refer to the Microsoft Security Bulletin MS05-039 page.

It is dropped by other malware as UPDATE.EXE in the Windows system folder. Upon execution, it downloads and executes certain files from a certain Web site.

It is capable of launching a SYNC flood type of denial of service attack that consumes system resources.


For additional information about this threat, see:
Solution
Technical Details
Statistics

Shadow Software Attack

INTRODUCTION
During the last years we could see how shadow server[3] attacks were a serious problem for many companies. It’s true that, for a security "expert", a shadow server attack can be considered obsolete and a "stupid" attack but in a security contest there is no banal problem,
mainly if it is still feasible.

The shadow software[1] attack, discussed in this paper, is very similar to the shadow server’s one, if we abstract to its essence.

Usually, the user does not require the authentication of the server and the exchange of information begins trusting the look-and-feel of the server[3]. This is very dangerous since we don’t know if the server we are connected to is the real one.

The shadow software attack is based on the concept that an attacker could simulate the look-and-feel of a software, launched by the victim, to steal his or other people's information.


For More: neworder

Saturday, September 10, 2005

TROJ_BAGLE.CR

Malware type: Trojan
Aliases: No Alias Found
In the wild: Yes
Destructive: Yes
Language: English
Platform: Windows 98, ME, NT, 2000, XP, Server 2003
Encrypted: No
Overall risk rating: Low

Reported infections: Low
Damage potential: High
Distribution potential: Low

Description:

Upon execution, this memory-resident Trojan opens the Notepad application, possibly to hide its malicious routines from unsuspecting users. In the background, however, it drops copies of itself as WINSHOST.EXE in the Windows system folder and as CJECTOR.EXE in the Windows folder. It also drops its dynamic link library (DLL) component using the file name WIWSHOST.EXE. The dropped DLL carries this Trojan's malicious routines.

This Trojan modifies a system's HOSTS file to contain only the following entry:

127.0.0.1 localhost

By default, most systems only have this line in their HOSTS file, so this routine does not really pose any adverse effects on the system. However, this may overwrite the HOSTS file of users who customize it for filtering purposes.

This Trojan disables antivirus applications by deleting specific keys from the system registry. It also modifies the registry to disable the Windows automatic updates, the Windows XP SP2 Firewall, and the system's administrative alerts. Furthermore, it stops services, terminates processes, and renames several files that are mostly related to security, antivirus, and firewall applications.

These routines may make it difficult for affected users to detect and remove this Trojan from the system. This may also pose as an additional threat to the affected system by making it vulnerable to further attacks from other malware programs.

Notably, this Trojan specifically disables Trend Micro antivirus by modifying a certain registry entry.

This Trojan downloads a file from a list of URLs. The downloaded file is saved as _RE_FILE.EXE. As of this writing, the said URLs are inaccessible.


For additional information about this threat, see:
Solution
Technical Details
Statistics


source: trendmicro.com

WORM_LEWOR.D

Malware type: Worm
Aliases: No Alias Found
In the wild: Yes
Destructive: No
Language: English
Platform: Windows 95, 98, ME, NT, 2000, XP, Server 2003
Encrypted: No
Characteristics: Propagates via instant messengers
Overall risk rating: Low

Reported infections: Low
Damage potential: High
Distribution potential: Medium

Description:

This worm propagates via MSN Instant Messenger. It sends messages containing a link that points to a copy of itself to available contacts in the MSN Instant Messenger of the affected user. The following are some of the URLs where this worm is downloaded:

  • http://play.joyiex.c{BLOCKED}0.exe
  • http://play.joyiex.c{BLOCKED}ie.exe
  • http://play.joyiex.c{BLOCKED}e.htm

Upon execution, it drops a copy of itself in the Windows folder. It also drops two copies of itself in the Windows system folder.

For its autostart technique, it modifies the registry depending on the platform of an affected system. It also modifies specific registry entries to enable it to start whenever a .TXT file is opened.

It creates a registry entry to disable the affected system's Task Manager. The affected user then has to use a third-party process explorer in order to terminate this worm.

It also sets the home page and search page of the Internet Explorer of an affected system to http://www.joyiex.com by creating several registry entries.

It also creates a registry entry to prevent the affected user from restoring the default home page settings while in Internet Explorer.

This worm creates mutexes to ensure that only one instance of itself is running on a system.


For additional information about this threat, see:
Solution
Technical Details
Statistics

source: trendmicro.com