EmailEmail
PrintPrint
Worry Watch -- A virus in anti-virus software
Saturday, December 24, 2005

 
 

WEEKLY REPORTS

Solutions, Prevention & Remedies

Top 10 Threats

   
 

An independent security researcher discovered a vulnerability this past week in several products from anti-virus company, Symantec.

The problem lies within the way that Symantec's software unpacks the various data compressed in its .RAR files. .RAR files, like .ZIP files, can store one or multiple pieces of information compressed into a single file which can be unwrapped by you or another user after download.

If a user programs one of Symantec's affected products to automatically scan incoming e-mail, a .RAR file housing a virus or worm could be unpacked, infecting the system and allowing the PC to be controlled remotely by hackers without any intervention from the user.

According to Symantec, no attempts by hackers to exploit this flaw have yet been discovered, and they are studying any activity involving .RAR files appearing to be malicious.

According to a posting at Security Focus, a community of online security professionals, the code where the weakness is located has been licensed to a number of other vendors, whose products could also be affected.


Worry Watch Plus Online only:

More Information About Symantec?s vulnerability ? Symantec Update (including list of affected Symantec Enterprise products

VULNERABLE PRODUCTS
Affected Consumer Products:

Product

Version

Symantec Norton Antivirus

2006

2005

2004

Symantec Norton Internet Security Professional

2006

2005

2004

Symantec Norton System Works

2006

2005

2004

Norton Personal Firewall

2006

2005

2004

Symantec Norton Antivirus for Macintosh

9.x

Symantec Norton Internet Security for Macintosh

3.x

Symantec Norton System Works for Macintosh

3.x

Symantec Norton Antivirus for Macintosh

7.x

Symantec Norton Antivirus for Macintosh

8.x

Symantec Norton Internet Security for Macintosh

2.x

Symantec Norton System Works for Macintosh

7.0

Symantec Norton Antivirus for Macintosh

9.x

Symantec Norton Internet Security for Macintosh

3.x

Symantec Norton System Works for Macintosh

3.x

Symantec AntiVirus for Handhelds

All


Latest Security Updates:

Anti-Spyware Product

Latest update

Download Site

Ad-Aware SE

SE1R82 19.12.2005 (Definitions updated December 19, 2005)

Download

Spy Sweeper

Version 4.5.8.683 (Released December 16, 2005)

Download

Spybot Search and Destroy

Version 1.4 (Definitions updated December 16, 2005)

Download

Go back

* Reading: Solutions, Prevention & Remedies
Additional summary information related to a specific type of solution or prevention that you should be considering. Depending upon the week, this section may have:
• Recent Windows security releases from Microsoft
• Recent updates to widely used anti-spyware programs
• Recent updates to widely used anti-virus programs
• Recent updates to other security programs & devices (ex: Firewalls, routers)
• Recent updates to various applications in wide use


Top 10 Threats:

Name

Type

Affects

Alert Level

Sdbot.ftp

Worm

Windows 95, 98, 2000, ME, NT, XP

Medium

Sober.AH

Worm

Windows 98, 2000, ME, NT, XP

High

Netsky.P

Worm

Windows 95, 98, 2000, ME, NT, XP*

High

Mitglieder.GO

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Medium

Galapoper.HP

Backdoor

Windows 95, 98, 2000, ME, NT, XP

Medium

Mitglieder.GK

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Galapoper.IC

Backdoor

Windows 95, 98, 2000, ME, NT, XP*

Medium

Mitglieder.GB

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Gaobot.gen 

Worm

Windows 2000, NT, XP*

Medium

Parite.B

Virus

Windows 95, 98, 2000, ME, NT, XP*

Low

Go back

Read: Top Threats
These are viruses that are currently on the watch lists of major anti-virus software companies.

Name
What the threat is called. We use the name given each virus by Panda Software. Sometimes other anti-virus companies give the same threat a different name. Usually they use similar names.

Type
There are different characteristics associated with different types of threats.
• Virus - has the ability to replicate or infect computers or other programs
• Trojan Horse (or Trojan) - appear to be harmless programs when you get them. They unleash their payload when you double-click, open, or execute them.
• Phishing - a Web site or e-maill message posing as another company - usually one you know to fool you into giving the sender personal information.
• Worm - self replicates onto additional disks, computers or networks
• Spyware - installs on your system to collect information about your activity, preferences or interests
• Hoax - false messages sent by e-maill to mislead the recipient
• Backdoors - opens a security hole that allows outsiders to take control of your computer
• Dialer - uses your telephone to dial an outside number - sometimes a number that costs you money when dialed

Affects
Not all viruses affect all types of systems. Some, for example may affect only Windows 98 and 95, but not Windows XP or NT. Others affect all Windows systems, but not Macintosh. In this column, we show you the consumer systems that the threat is known to affect. We don't always include the servers that operate in your company's backroom.

Alert level
The level of awareness that anti-virus vendors suggest you need to have for each threat listed.
For each threat listed, we'll post a corresponding link here, so you can get more information to help you recognize, diagnose, prevent, and repair the problem.

First published on December 24, 2005 at 12:00 am
Worry Watch is compiled by David Radin & Jes Scherder using data and reports from Microsoft, CERT, Panda, and other sources. To contact the compilers of Worry Watch, go to http://www.megabyteminute.com/contactdavid.html.