Viruses at Interop

Opinion
May 9, 20055 mins

* Patches from Debian, Gentoo, Conectiva others * Beware new Rbot variants

During Interop last week in Las Vegas, Blue Coat systems provided the anti-virus system for the show network. Among the viruses stopped by the system:

W32/Sober.gen@MM – https://www.f-secure.com/v-descs/sober.shtmlhttps://www.f-secure.com/v-descs/eicar.shtmlhttps://www.f-secure.com/v-descs/exp_mht.shtmlhttps://vil.nai.com/vil/content/v_132627.htmhttps://vil.mcafeesecurity.com/vil/content/v_129476.htmhttps://www.f-secure.com/v-descs/startpag.shtmlhttps://vil.nai.com/vil/content/v_100261.htmhttps://secunia.com/virus_information/16793/downloader-lg/https://vil.mcafeesecurity.com/vil/content/v_132881.htm

EICAR test file –

Exploit-MhtRedir.gen –

BackDoor-CPT –

Downloader-RK –

StartPage-DU.dll –

Exploit-ByteVerify –

Downloader-LG –

Downloader-YH.dr –

Amazing that even a temporary network like the one set up at the show can be inundated with potential viral infections.

Today’s bug patches and security alerts:

Debian, Gentoo patch Ethereal

A number of flaws have been found in the Ethereal protocol analyzer. The most serious of the vulnerabilities could be exploited to run malicious code on the affected machine. For more, go to:

Debian:

https://www.debian.org/security/2005/dsa-718

Gentoo:

https://security.gentoo.org/glsa/glsa-200505-03.xml

**********

Gentoo releases patch for xine-lib

Two flaws in xine-lib, a multimedia library, could be exploited to run malicious applications on the affected machine. A patch is available. For more, go to:

https://security.gentoo.org/glsa/glsa-200504-27.xml

Gentoo patches Heimdal

A buffer overflow vulnerability in Heimdal’s telnet client could be exploited by an attacker to run any code on the affected machine. A fix is available. For more, go to:

https://security.gentoo.org/glsa/glsa-200504-28.xml

**********

Conectiva issues patch for evolution

A bug in evolution, a mail, calendar and contact manager client, could cause the application to crash when certain messages are displayed. A fix is available. For more, go to:

http://www.networkworld.com/go2/0509bug1a.html

Conectiva patches kernel

A new kernel update from Conectiva fixes six problems found in previous releases. Most of the flaws could be exploited in denial-of-service attacks against the affected machine. For more, go to:

http://www.networkworld.com/go2/0509bug1b.html

**********

Debian releases patch for lsh-utils

Debian says it has patched two vulnerabilities in the lsh-utils, an alternative SSH2 protocol server. The flaws could be exploited by an attacker to run any code on the affected machine. For more, go to:

https://www.debian.org/security/2005/dsa-717

Debian patches prozilla

According to an alert from Debian, “Several format string problems have been discovered in prozilla, a multi-threaded download accelerator, that can be exploited by a malicious server to execute arbitrary code with the rights of the user running prozilla.” For more, go to:

https://www.debian.org/security/2005/dsa-719

**********

Mandriva patches libxpm4

A flaw in the xpm image handling code used by a number of applications could be exploited to run malicious code on the affected machine. An attacker would have to pass a specially crafted image file to take advantage of this vulnerability. For more, go to:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:080

Mandriva releases patch for perl

A flaw in Perl’s rmtree() function could be exploited by an attacker to create files in areas they would not normally have access to. The attacker would already need some privileges on the affected system to take advantage of this flaw. For more, go to:

https://www.mandriva.com/security/advisories?name=MDKSA-2005:079

**********

Today’s roundup of virus alerts:

Troj/Bbprox-A — A Trojan that acts as proxy server for Internet traffic. No word on how it spreads, but it does register itself with a remote site. (Sophos)

W32/Rbot-ABP — A new Rbot variant that spreads through network shares by exploiting a couple of known Windows vulnerabilities. It installs “msfirewalI.exe” in the Windows System directory, allows backdoor access via IRC and can be used for a number of malicious applications. (Sophos)

W32/Rbot-ABQ — Another new Rbot variant. Similar to Rbot-ABP above, except this one installs “N0D32KRN.EXE”. (Sophos)

Troj/Zlob-I — A backdoor Trojan that injects its code into explorer.exe to help mask it from detection. It can download and store files from remote sites. (Sophos)

W32/Mytob-CA — Another Mytob variant that spreads through e-mail and IRC. It drops “shell.exe” on the infected machine and can block access to security Web sites by modifying the Windows hosts file. The infected messages look like bounce back errors. (Sophos)

W32/Mytob-CB — Yet another Mytob e-mail/IRC worm. This variant installs itself as “winsvc32.exe”. The infected e-mail attachment is a  PIF, SCR, EXE or ZIP file. (Sophos)

W32/Mytob-BZ — The thrid Mytob variant of the day uses “taskgmr.exe” as its infection point. It spreads through e-mails with a .scr attachment. (Sophos)

Troj/Fireby-B — This Trojan is designed to bypass the Windows firewall. No word on how exactly it spreads between machines. (Sophos)

Troj/Lohav-R — This Trojan drops “winhost.exe” in the Windows system folder and acts as a SOCKS proxy running on port 9030. It can limit access to security-related Web sites by modifying the Windows HOSTS file. (Sophos)

Troj/PurScan-W — A virus that attempts to change a browser’s settings and download files from a remote site, including “installer.exe” and “mt-uninstaller.exe”. (Sophos)

Troj/Agent-DQ — A downloader DLL that grabs files from the Internet. It uses a variety of file names. (Sophos)

Adware/Topspyware — A new spyware/adware Trojan that attempts to get infected users to pay for a tool that gets rid of it. Symptoms of infection include a system tray icon that toggles between a question mark and Windows Update icon. (Panda Software)

W32/Agobot-RX — An Agobot variant that drops “regsvc32.exe” and allows backdoor access via IRC. It can be used for a number of malicious applications. (Sophos)