Welcome to the RonaldReagan.com Forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   RonaldReagan.com Forums > Reagan's Peers > Newt's Neutron

Newt's Neutron A Science & Technology Forum Dedicated To The Former Speaker Of The House And Honorary Chairman Of The NanoBusiness Alliance.

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 01-07-2003, 04:30 PM
The Finman's Avatar
The Finman The Finman is offline
Administrator
 
Join Date: Oct 2001
Posts: 11,649
Rep Power: 50
The Finman has disabled reputation
AddThis Social Bookmark Button AddThis Feed Button

Lightbulb

Quote:
<APPLET CODE="chat_ticker.class" CODEBASE="http://newsticker.shortnews.com/com/newsticker/" WIDTH="700" HEIGHT="20">
<PARAM NAME="MSGTEXT" VALUE="http://newsticker.shortnews.de/com/export/default.txt">
<PARAM NAME="BGCOLOR" VALUE="000000">
<PARAM NAME="FGCOLOR" VALUE="ffcc33">
<PARAM NAME="LINKCOLOR" VALUE="00ff00">
<PARAM NAME="HIDECOLOR" VALUE="000066">
<PARAM NAME="MOUSEOVERHOLD" VALUE="1">
<PARAM NAME="SPEED" VALUE="20">
<PARAM NAME="U_ID" VALUE="4318">
</APPLET>

<h2><font color=#003399>Lirva worm attaches to Avril Lavigne
</font></h2>
The popularity of singer Avril Lavigne has spread to the world of computer viruses.

Lirva (w32.Lirva@mm), also known as Naith, is a mass-mailing worm that is UPX-compressed to a file size of 32,766 and arrives via e-mail either announcing a new Microsoft patch or offering fan access to Avril Lavigne.

Once active, Lirva will attempt to e-mail copies of itself to all contacts on an infected system, shut down all antivirus and firewall programs, and launch a Web browser to open the Avril Lavigne Web site on an infected user's desktop.

Lirva uses the Iframe vulnerability, so on unpatched systems, the worm will automatically execute whether or not the attached file is opened.

Antivirus vendor MessageLabs reports that parts of the Lirva worm code very look familiar, so Lirva may turn out to be a variant of a known virus family.

Because this worm sends e-mail but is not considered destructive, it rates a 4 on the ZDNet Virus Meter.

Re: Brigade Ocho Free membership Re: According to Daos Summit Fw: Avril Lavigne - the best Re: Reply on account for IIS-Security Re: ACTR/ACCELS Transcriptions Re: The real estate plunger Fwd: Re: Admission procedure Re: Reply on account for IFRAME-Security breach Fwd: Re: Reply on account for Incorrect MIME-header The e-mail containing Lirva may also include the following information in the body text: Patch is also provided to subscribed list of Microsoft® Tech Support: to apply the patch immediately.

Microsoft strongly urges all customers using IIS 4.0 and 5.0 who have not already done so and do not need to take additional action.

Microsoft has identified a security vulnerability in Microsoft® IIS 4.0 and 5.0 To prevent from the further buffer overflow attacks apply the MSO-patch Attachment you sent to %s is intended to overwrite start address at 0000:HH4F Restricted area response team (RART) Admission form attached below Vote for Im with you!

Once active, Lirva will attempt to shut down all security programs such as antivirus and firewall software.

Prevention
Users of Microsoft Outlook 2002 and users of Outlook 2000 who have installed the Security Update and have installed the patch for the MS01-020 vulnerability in Internet Explorer should be safe from Lirva. Users who have not upgraded to Outlook 2002 or who have not installed the patch for the MS01-020 vulnerability should do so. In general, do not open attached files in e-mail without first saving them to hard disk and scanning them with updated antivirus software. Contact your antivirus vendor to obtain the most current antivirus signature files that include MyLife.

Removal
A few antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, McAfee, Sophos, and Trend Micro.


Full Article <font color="red"><u>Here</u></font>
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
New Worm Poses DoS Attack Threat The Finman Newt's Neutron 0 11-01-2003 06:48 PM
Swen Worm Spreads Quickly The Finman Newt's Neutron 2 10-02-2003 03:00 PM
FBI Hunts Down Worm Writers The Finman Newt's Neutron 1 08-28-2003 01:26 PM
Microsoft SQL Sapphire Worm Analysis Radical Conservative Newt's Neutron 0 01-26-2003 12:17 AM
Henpeck Worm Nags MSN Messenger The Finman Newt's Neutron 0 10-11-2002 08:02 PM


All times are GMT -3. The time now is 12:14 AM.
Powered by vBulletin
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
RonaldReagan.com is the property of Techsure LLC ©1996-2008


 
Page generated in 0.08238 seconds with 10 queries