Randy Sigman said:Pete said:Well I'd agree with that except there are viri about which do not need to be executed. They
function on arrival.
Hi Pete, Are you able to cite an example of such a virus? Randy
Viruses are categorized by how they infect. These categorizations often overlap the categories
above and may even be included in the description (e.g., polymorphic file virus). These
categories include:
Polymorphic Viruses Stealth Viruses Fast and Slow Infectors Sparse Infectors Armored Viruses
Multipartite Viruses Cavity (Spacefiller) Viruses Tunneling Viruses Camouflage Viruses NTFS
ADS Viruses
Virus Droppers - programs that place viruses onto your system but themselves may not be viruses (a
special form of Trojan).
Nimda is one of the more complex virus/worm constructs released. It infects files, spreads itself
via E-mail, spreads via *Web sites*, and spreads via local area network exploits. It infects all
versions of Windows from Win95 through Win2000 as well as Microsoft's IIS.
Nimda is credited with several "firsts" in its infection techniques. It is the first beast to infect
.EXE files by embedding them into itself as a resource. It also infects Web pages so unsecured
browsers will infect upon viewing the Web page. Finally, Nimda is the first worm to use any user's
computer to scan a network for vulnerable machines behind a firewall to attack (in the past only
infected servers did that).
Nimda uses several known weaknesses in Microsoft IIS servers. It would not have spread as far as it
did had administrators applied the known patches.
Level of Threat
High
- Blended threats (i.e. spreads via email, P2P, IM, network shares)
- Mass mailers
- Spreads via network shares
Medium
- Mailers
- has spread via third-party or media
- spreads in IRC, IM, or P2P <<<<<<<<<<<<<<<<note
- requires user intervention to spread
- URL/Web site download <<<<<<<<<<<<<<<<<Note
Low
- no network spreading
- requires manual distribution to spread
ActiveX malicious code <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<Note ActiveX controls allow Web developers to
create interactive, dynamic Web pages with broader functionality such as HouseCall, Trend Micro's
free on-line scanner. An ActiveX control is a component object embedded in a Web page which runs
automatically when the page is viewed. In many cases, the Web browser can be configured so that
these ActiveX controls do not execute by changing the browser's security settings to "high."
However, hackers, virus writers, and others who wish to cause mischief or worse may use ActiveX
malicious code as a vehicle to attack the system. To remove malicious ActiveX controls, you just
need to delete them.
This new MYDOOM variant [B] is a mass-mailing worm that selects from a list of email subjects,
message bodies, and attachment file names for its email messages. It spoofs the sender name of its
messages so that they appear to have been sent by different users instead of the actual users on
infected machines.
It also propagates using the Kazaa peer-to-peer file-sharing network and copies itself into machines
with random IP addresses.
***It scans IP addresses for accessible systems and sends a copy of itself into these systems via
port 3127. ***
So in short do not assume that these things are spread just as an attachment to an e-mail. That is
not the case at all.
There are many more examples and information. An easy Google will show you all you want to know.
HTH
Pete
Diagnosed 20/03/03 Type II D&E + Metformin + Gliclazide
+ Asprin 210lbs at Dx to BMI 166lbs achieved. To mail: aspen at freeuk.com