Internet Security News
Ranked #3,673 in Tech & Geek, #91,711 overall | Donates to Action Against Hunger, Save the Children
Internet Security News!
Internet Security News Table of Contents!
This is Internet Security News Table of Contents to ease your browsing. If you are at this line, please spread the word about Internet Security News by sharing and adding it to some of your social networks. Thanks!
- Malicious PDF files exposed!
- Worms are spreading!
- Worms modify HTML pages!
- New Trojan uses a real storm in Europe!
- Malware known as Tibs.jy spreads on greetings cards!
- Intrusion Attempts from China!
- New batch of Warezov spammed!
- Warezov.AT updates itself differently!
- Root Kit Hidden Backdoor has spammed!
- First Bot to Exploit MS has developed!
- New Breplibot Hits the Nerves!
- Nyxem.E is Widespread!
- Take Care of New Vulnerability in Many Versions of Windows!
- Protect your digital lifestyle with this Internet Security
- Sober.Y is the Year's Largest Email Worm Outbreak!
- Sober.Y Variants come with attached ZIP files sometimes!
- Names of Attachments in Sober Variants!
- Bagle.BI variant spammed!
- New Zotob network worm is tricky!
- Take Care of Such IP Address!
- Bagle variants developed to disable antivirus programs!
- Lebreat Inhabits Breatle Antivirus!
- Strong Internet Shields Detect any Intrusive IP!
- MyDoom Installs a Spam Proxy!
- Bagle.AY Spreads via P2P networks!
- If You Saw a "NeverEverNoSanity", Fly!
- Trojan-Downloader Gets in through Google Toolbar!
- How Do You Disinfect Your Computer?
- Let McAfee help you Disinfect Your Computer and Protect Your Entire System!
- Now there is a Stupid Malware Called Kuang2.in!
- Take Care of Trojan-D in Attachment!
- Worm W32/Autorun Spreads in Emails Attachments
- How Worm W32/Autorun Works? Moreover, What It Does?
- United Postal Services Distribute Worms and Trojan in Attachments!
- Use High Internet Securities to Protect Your PC!
- Japan Enters Trojan Spy Industry!
- Spammers Send PayPals Hacking Emails in French!
- Trojan-Spy Spreads Using Google Groups!
- Obama Sex Scandal is a Trojan in Attachments!
- Are They MSN Featured Offers Really?
- eBay Hackers Have Bad Stupid Trends!
- New Guestbook
- Internet Security at Amazon
- Twitter Follows Internet Security News
- Khalid Osman's Squidoo Network
- Internet Security News has Ways to Block Hackers!
- Off Topic Videos in RSS Feed for Enjoyment!
- None
Malicious PDF files exposed!
Worms are spreading!
Worms modify HTML pages!
New Trojan uses a real storm in Europe!
Malware known as Tibs.jy spreads on greetings cards!
Intrusion Attempts from China!
New batch of Warezov spammed!
Warezov.AT updates itself differently!
Strange Internet Security News!
Root Kit Hidden Backdoor has spammed!
First Bot to Exploit MS has developed!
New Breplibot Hits the Nerves!
Nyxem.E is Widespread!
Take Care of New Vulnerability in Many Versions of Windows!
F-Secure issued a Level 2 alert on the serious WMF vulnerability. However, so far no viruses or worms using it have been found. FSAV detects malicious WMF files as PFV-exploit or Exploit.Win32.IMG-WMF.
Here's my favorite link:
Sober.Y is the Year's Largest Email Worm Outbreak!
Sober.Y Variants come with attached ZIP files sometimes!
Names of Attachments in Sober Variants!
Bagle.BI variant spammed!
New Zotob network worm is tricky!
Zotob worm uses a five-day old MS05-39 Plug-an-Play vulnerability. The worm targets unpatched machines by scanning port 445 and downloading the virus file via ftp.
Take Care of Such IP Address!
Description: Inbound Malware probe
Services: Malware - MyDoom in
Remote address: 66.173.254.173
Remote port: 3884
DNS name: www.clondalkin-group.com
The IP Address is located in US, Pennsylvania region, Philadelphia. ISP Clondalkin Group
See more IP Address that used to send Malware attacks to my system at this link, so you can copy sources and paste them into your protection system to block them.
Bagle variants developed to disable antivirus programs!
New downloader resembling the Bagle email worm is reported globally. This Trojan has been spammed widely as "doc_01.exe". When it runs, it disables antivirus programs and attempts to download more Malware.
Lebreat Inhabits Breatle Antivirus!
Strong Internet Shields Detect any Intrusive IP!
Description: Intrusion attempt detected: Nmap TCP scan
Direction: Inbound
Protocol: tcp
Services: TCP High ports in
Remote address: 202.194.159.98
Remote port: http(80)
However, the Security shield has blocked that intrusion at time and recorded details about the intrusive IP.
MyDoom Installs a Spam Proxy!
Bagle.AY Spreads via P2P networks!
If You Saw a "NeverEverNoSanity", Fly!
Trojan-Downloader Gets in through Google Toolbar!
My Virus and Spy Protection has detected Trojan-Downloader.Win32.Agent.aaza virus in my computer.
Name: Trojan-Downloader.Win32.Agent
Type: Trojan
File: located and deleted.
Path: googletoolbarinstaller.exe
The hacker tries to use a standalone program to hidE downloads and run other files from remote web and ftp sites. When a Trojan-Downloader runs, it installs itself, roots it to the system in a Rootkit, and waits until an Internet connection becomes available. After that, it attempts to connect to a web or ftp site, download a specific file or files and run them.
In some anti-viruses the disinfect operations could fail to disinfect the computer because the Trojan-Downloader has the ability to rename itself.
How Do You Disinfect Your Computer?
Another kind of Trojan-Downloader is the Trojan-Downloader.Java.OpenStream.ac (virus).
Using strong antivirus protection is enough to disinfect your computer. However, when disinfection is not possible, you can manage that manually. To disinfect standalone Malware (backdoors, worms, Trojans, etc.) manually, it is usually enough to delete all infected files from a computer and to restart it.
You can do that by tracking the root and the destination of the virus (where it resides). You can for example rename the file and delete it. However, manual disinfection is a risky process, so ignore this advice if you are not advanced user and request help from your antivirus provider.
I have found the following process at one of the Internet Security providers useful:
If Windows 95, 98 and ME operating system is used, it is recommended to restart a computer from a bootable system diskette and to delete an infected file from command prompt. For example, if a malicious file named ABC.EXE is located in Windows folder, it is usually enough to type the following command at command prompt: DEL C:\WINDOWS\ABC.EXE and to press Enter. After that, an infected file will be gone.
If Windows NT, 2000 or XP is used, a malicious file has to be renamed with a different extension (for example .VIR) and then a system has to be restarted. After restarting, the renamed malicious file will no longer be active and it can be easily to delete manually.
Here's my favorite link:
Let McAfee help you Disinfect Your Computer and Protect Your Entire System!
Now there is a Stupid Malware Called Kuang2.in!
As I know Greeks are very peaceful people, I am surprised by having the late Malware - Kuang2.in coming from there two times to attack two computers at the same time. I moved from this computer to the second to track and see the same blocked traffic with the following information, thanks to my Internet guard:
Description: Inbound Malware prope
Direction: Inbound
Protocol: tcp
Services: Malware - Kuang2.in
Remote address: 84.205.241.5, Location: Country: Greece, Region: Attiki, City: Athens, ISP: Greek Public Administration Network, Domain: OTE.GR
Remote port: 31029
DNS name: host-84-205-241-5.cpe.syzefxis.ote.gr
Take Care of Trojan-D in Attachment!
The body message goes like this:
"Good morning,
We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree with all the provisions we are ready to make the payment on Friday for the first consignment.
We are enclosing the file with the prepared contract.
If necessary, we can send it by fax.
Looking forward to your decision."
Worm W32/Autorun Spreads in Emails Attachments
I have received such Virus in an email spam with the following information:
The first lines of the body of the message go this way: Please find attached a statement of fees as requested; this will be posted today. I received such spam with a Trojan included in the attachment from astonrose dot co dot uk ([195.72.48.170]) UK United Kingdom, ISP: Worldinternet.
The sender was JetBlue Airways at erxsr at bmrcpas.com and the Subject line says, Your Online Flight Ticket N 67003 and the multi-part message was in MIME format.
How Worm W32/Autorun Works? Moreover, What It Does?
The worms create an autorun.inf into the root directory of drives they want to infect.
The autorun.inf includes the name and path of the actual worm executable. When an infected media device (CD, DVD OR USB drive) is inserted into the computer, the autorun.inf and consequently the actual malicious program is automatically executed.
In addition to drives on the local computer, an Autorun worm can also spread to remote computers by infecting shared network drives.
Members of the Autorun family also often contain other functionality in addition to just spreading. In fact, this infection method can be used to propagate any malicious playload, such as a backdoor, password stealer, or some other kind of Trojan.
United Postal Services Distribute Worms and Trojan in Attachments!
The message goes this way: "Unfortunately, we were not able to deliver postal package you sent on Sept the 28 in time because the recipient's address is not correct.
Please print out the invoice copy attached and collect the package at our office
Your UPS"
The words on the "From" fields are as the same as these words: United Postal Services.
The words on the Subject line are also the same. However, it is only that the numbers of the tracking are changed. The word read as this: UPS Tracking Number 30935741114; and UPS Tracking Number 02498012147.
The first email spam dropped in through the following details:
IP Address: 81.149.217.89, ISP Location UNITED KINGDOM, ENGLAND, LONDON SP: SINGLE STATIC IP ADDRESSES, domain: BTOPENWORLD.COM
The second email spam dropped in through the following details:
IP address: 62.45.25.10, ISP Location: NETHERLANDS, ZUID-HOLLAND, NAALDWIJK, IP: KABELFOON, Domain: CAIWAY.NL
Here's my favorite link:
Japan Enters Trojan Spy Industry!
I read the details on the screen and followed the two emails until they landed naked from that virus into my folder. I then followed them through the email system to discover the following details.
The two emails were received: from ([221.189.225.27]) located in Japan. Region: Gifu City: Gifu ISP: OPEN COMPUTER NETWORK
with the "From" line: "Microsoft" <customerservice@microsoft.com> and the "Subject" line: Security Update for OS Microsoft Windows, on Tue, 14 Oct 2008 13:11:59 +0900.
The same stupid message was addressing me this way: Dear Microsoft Customer, and the lines followed:
Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.
Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.
Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.
As your computer is set to receive notifications when new updates are available, you have received this notice.
In order to start the update, please follow the step-by-step instruction:
1. Run the file, that you have received along with this message.
2. Carefully follow all the instructions you see on the screen.
If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.
We apologize for any inconvenience this back order may be causing you.
Thank you,
Steve Lipner
Director of Security Assurance
Microsoft Corp.
There are so many stories like this you can read at the following links at the Ezine Act IP| IP Address| Malware|
Spammers Send PayPals Hacking Emails in French!
Cher PayPal User.
Nous recemment avons determine que les differents ordinateurs ont note sur votre compte de PayPal, et les echecs multiples de mot de passe etaient presents avant les ouvertures.
Nous avons besoin maintenant de vous pour reconfirmer votre information de compte . Si ceci n'est pas accompli avant le 13 Octobre 2008, nous serons forcés de suspendre votre compte indefiniment, comme il a pu avoir ete employe pour des buts frauduleux.
Nous vous remercions de votre cooperation de cette maniere.
Cliquez ci-dessous pour confirmer et vérifier votre compte de PayPal :
https://www.paypal.com/us/cgi-bin/webscr?cmd=_login-submit
Note : si vous choisissez d'ignorer notre demande, vous ne nous laissez aucun choix mais ? provisoire suspendez votre compte.
Les Meilleurs souvenirs.
PayPal
Securité de PayPal et departement Anti-Frauduleux.
Trojan-Spy Spreads Using Google Groups!
However, since the processes goes through Google, so Google should be the first to block this door. Yes, it worth mentioning this note again and again. The following is a complete information of one silly hacker using this method to send his or her Trojan-Spy in.
Trojan-Spy.HTML.Fraud is fraudulent e-mail messages and website HTML. They include a mismatch in HREF tags used by hyperlinks. This happens when hackers attempts to disguise or obfuscate the hyperlink. An example to HREF mismatch is < a href="http://www.nananana.com" >http://www.paradox.com< / a>
The HREF tag in this example directs to nananana.com while the displayed hyperlink will show paradox.com. Phishers attempt to lure victims to spoofing sites in order to steal personal account details.
Obama Sex Scandal is a Trojan in Attachments!
Name: Adware
Category: Spyware
Alias: Adware.win32.agent
This software produces advertisements on the infected computer. It collects data and exposes it to users.
Are They MSN Featured Offers Really?
All messages go this way:
About this mailing:
You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the "Unsubscribe" link below. This will not unsubscribe you from e-mail communications from third-party advertisers that may appear in MSN Feature Offers. This shall not constitute an offer by MSN. MSN shall not be responsible or liable for the advertisers' content nor any of the goods or service advertised. Prices and item availability subject to change without notice.
Following this message are three text links to Chinese websites at hudardd.cn, iicurpx.cn, and one site none cn at legacymethod.com. The text links are Unsubscribe | More Newsletters | Privacy.
I do not know what the spammer will feel if somebody told him or her nothing like this will work.
eBay Hackers Have Bad Stupid Trends!
Details of the Spam!
Return-Path: member@ebay.com
Received: from ALLOY.MNAlloys.local ([70.148.53.183])
Received: from User ([83.110.102.209]) by ALLOY.MNAlloys.local with Microsoft SMTPSVC(5.0.2195.6713); Wed, 15 Oct 2008 16:02:23 -0500
From: "eBay member : poppy20016"< member@ebay.com >
Subject: You've received a question about your eBay item
Date: Thu, 16 Oct 2008 00:49:20 +0400
MIME-Version: 1.0
Content-Type: text/html; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Return-Path: member@ebay.com
Message-ID: < ALLOYSs21Ud9mTP2vZX00000290@ALLOY.MNAlloys.local >
X-OriginalArrivalTime: 15 Oct 2008 21:02:23.0656 (UTC) FILETIME=[522B7280:01C92F09]
Fra: "eBay member : poppy20016" member@ebay.com
Bcc: "eBay member : poppy20016" member@ebay.com
The Message Body
Dear member,
eBay member poppy20016 left you a message regarding item #120316315275
View the dispute thread to respond. This is a text link that redirects to: http://210.71.14.74/xampp/img/lt1.gif/singin.
ebay.com/ws/ebayISPp.dll/SignIn/index.html?SignIn&co_partnerId=2&pUserId=&siteid=0&page
Type=&pa1=&i1=&bshowgif=&UsingSSL=&ru=http%3A%2F%2Fwww.ebay.com&pp=&pa2=&errmsg=&runame=&
ruparams=&ruproduct=&sid=&favoritenav=&confirm=
&ebxPageType=&existingEmail=&isCheckout=&migrateVisitor=
Regards,
eBay
New Guestbook
Khalid-Osman wrote...
Thanks DonVito and JziE
Did you know I can't update and publish this lens because I received this letter and I reported it because the system can't be always right and have not received any update about ´this matter until now:
Uh oh. We're worried that the lens you just published might be (gasp) spambait! Due to significant levels of abuse, there are certain topics that Squidoo just doesn't permit lenses on. This page sure seems to cross into one of those areas. So, you've got three choices:
Go Back and Edit (I want to fix it)
Delete the lens! (I'll make a lens on something else instead) OR I'll stake my Squid-reputation that this lens is not: used to promote or sell prescription or illicit drugs online or by mail; used to promote online gambling or the sale of information about gambling; used to offer debt reduction or bankruptcy counseling online or by phone; used to promote or describe any sexual aids, techniques or content for sale online; and it doesn't violate Squidoo
DonVito wrote...
Great lens, internet security is very important, check out online fax software.
Khalid-Osman wrote...
Thanks Mia for your cafe. I liked that one too and I am sure you do:-)
Internet Security at Amazon
Amazon Voting (Plexo)
Here is everything about Internet Security, Internet Privacy, Worms, Malware, Viruses, Phishing, and Spam from Amazon.
Norton Internet Security 2008 up to 3 Users
What do you do to keep yourself healthy? Norton In more...0 points
Firewalls and Internet Security: Repelling the Wily Hacker (2nd Edition) (Addison-Wesley Professional Computing Series) by William R. Cheswick, Steven M. Bellovin, Aviel D. Rubin
Essential information for anyone wanting to protec more...0 points
Norton Internet Security 2008
Stay protected from the latest online threats! Nor more...0 points
Internet Security Suite Plus 2008 W/$10,000 Warranty
Comprehensive protection against Internet threats more...0 points
Twitter Follows Internet Security News

- talkative
- aka talkative
- 96 followers
- 58 following
-
- Ezine Act - Where Politics, Business and Love Combination Makes Money at Home! http://a2a.me/U9k via @AddToAny
-
- Ezine Act 56 - Be Careful of Make Money at Home Programs! (http://ping.fm/BXZlD)
-
- Ezine Act 56 - Be Careful of Make Money at Home Programs! http://a2a.me/TXt via @AddToAny
-
- Ezine Act 55! http://a2a.me/T0U via @AddToAny
-
- Check this video out -- Danish painter Mette Mors Larsen http://bit.ly/4sDWFX
Khalid Osman's Squidoo Network
Well, I am taking some friends on squidoo on my ark through this automation. You will be glad if you jumped to this ark through the Squadron of Poets. Just do it before the flood;-)
Fetching RSS feed... please stand byInternet Security News has Ways to Block Hackers!
Off Topic Videos in RSS Feed for Enjoyment!
Fetching RSS feed... please stand by
by 5 people |










