Flea bugs Windows users

Discussion in 'Computer Security' started by Phil, Oct 24, 2003.

  1. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    A new virus called Flea is on the loose. The Visual Basic Script worm disguises itself as the ‘signature file’ in HTML-formatted mail.

    Flea can execute automatically when users open HTML formatted emails in Microsoft Outlook or Outlook Express. Unlike most Windows nasties, the bug does not depend on a user opening an infectious file to do its mischief, Finnish AV vendor F-Secure warns.

    When an infected HTML email is rendered a webpage is loaded. This page contains JavaScript which in turn loads another webpage containing the VB Script which drops a file (C***.HTM) in the Windows folder

    rest of story

    F-secure Advisory
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  2. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Interesting. I tried looking for this at http://www.sarc.com since I use Norton Anti-Virus, but I couldn't find any "flea" reference on their site. Obviously, this is of concern to me.
     
    Certifications: A+ and Network+
  3. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Certifications: A+ and Network+
  4. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    I just got to work and found a virus alert e-mail from avertlabs/mcafee on this worm. It's rated low profile because of media attention (I must have missed the attention so far). Discovered on the 21st. I went to a security site http://www.securelyspeaking.com and they hadn't heard of it either.
     
    Certifications: A+ and Network+
  5. Nelix
    Honorary Member

    Nelix Gigabyte Poster

    1,416
    3
    82
    It's still early days yet.......But it does make you wonder how good these so called security web site ACTUALLY are, if anyone should know first, they should.
     
    Certifications: A+, 70-210, 70-290, 70-291, 74-409, 70-410, 70-411, 70-337, 70-347
    WIP: 70-346
  6. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Well, the worm references a server in Spain and it's first noticed by a finnish anti-virus outfit and the register in the uk. Maybe it took a day or so to come to the attention of the folks on my side of "the pond". Just a thought.
     
    Certifications: A+ and Network+
  7. Phil
    Honorary Member

    Phil Gigabyte Poster

    1,680
    7
    87
    It all just highlights the fact that your av solution is only as good as its most recent update and when asked which one is best the answer is always going to be different from one minute to the next because it's always going to be the provider who is quickest with a definition for the latest threat
     
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade
  8. Jakamoko
    Honorary Member

    Jakamoko On the move again ...

    9,924
    74
    229
    Cheers for the nod, Phil - more to look out for :gun

    Just as an aside, I was doing a full clean install of Server on my main box earlier this week. I got everything loaded up (inc. ZoneAlarm and Grisoft AVG6) before I even went near the net. In the time it took me to connect to the AVG Update site and bring down the latest definitions, guess who sneaked in ? Our old "friend" Naachi :evil: :cussing

    Fortunately, ZoneAlarm caught it trying to get back out, but I just cannot believe some folks go without any form of security these days - then they come running to us when the worst does happen :!:
     
    Certifications: MCP, A+, Network+
    WIP: Clarity
  9. tripwire45
    Honorary Member

    tripwire45 Zettabyte Poster

    13,493
    180
    287
    Whenever we set up a machine here, we log onto the anti virus server we have, load the client software and run a full scan. The machines I've worked on so far have been clean but I've heard that machines that new can still have viruses found on them.
     
    Certifications: A+ and Network+

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.