Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Internet worm disguised as e-Christmas card
AFP ^ | Dec 15, 2004

Posted on 12/14/2004 5:50:22 PM PST by Tumbleweed_Connection

Internet security experts have warned of a new virulent email worm particularly successful in infecting computers as it is disguised as a multilingual electronic Christmas card.

"We think this worm will be big because of its timing and the fact that it comes in 15 different European languages," said Mikko Hyppoenen, head of anti-virus research at Finnish firm F-Secure.

The virus, dubbed Zafi D, is a traditional Internet worm infecting computers by email and distributes itself by using email lists on contaminated personal computers.

Its Christmas greeting is in the language of the recipient, decided by the country code - like ".fi" or ".fr" - at the end of the email address, making it all the more dangerous.

Mr Hyppoenen says it also opens a back door on infected PCs, making it possible for outsiders to use them to distribute unsolicited bulk email advertisements, or spam and launch malicious attacks to close down websites.

He says the earlier variants of the Zafi Internet worm family were highly dangerous viruses, with the B variant still among the top 10 most virulent bugs several months after it was launched.

While this is the first Zafi worm disguised as a Christmas card, the phenomenon is not new.

"We have seen these hoaxes for several Christmases already and personally I prefer traditional pen and paper cards and we recommend this to all our clients too," Mr Hyppoenen said.


TOPICS: News/Current Events
KEYWORDS: infection; internet; virus; worm

1 posted on 12/14/2004 5:50:23 PM PST by Tumbleweed_Connection
[ Post Reply | Private Reply | View Replies]

To: Tumbleweed_Connection

If you have a good anti-virus scanner to scan your e-mail you're safe. If you see a Christmas Card greeting in your in-box, delete it.


2 posted on 12/14/2004 5:53:19 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop; Tumbleweed_Connection

If your ISP is anything like mine, you don't see this kind of stuff in your in-box.


3 posted on 12/14/2004 5:58:28 PM PST by BigSkyFreeper (Congratulations President-Re-Elect George W. Bush!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Tumbleweed_Connection
I Blog BooksPer Symantec, Win32.Erkez.D, also known as Win32.Zafi.D [Computer Associates], Zafi.D [F-Secure], W32/Zafi.d@MM [McAfee], W32/Zafi.D.worm [Panda], W32/Zafi-D [Sophos], WORM_ZAFI.D [Trend Micro] is a new, highly wild and distributed worm that causes medium damage.

Sounds like a good idea not to open it, even if you do have a good anti-virus pack installed.
4 posted on 12/14/2004 6:32:01 PM PST by dr_pat (Life is sexually transmitted.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Tumbleweed_Connection

I'm sure it will infect our home computer. My wife's silly girlfriends forward this kind of stuff to her without fail.


5 posted on 12/14/2004 6:34:04 PM PST by Fitzcarraldo
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fitzcarraldo
I'm sure it will infect our home computer.

Only if you choose to open the attachment. Plus, your antivirus software should light up like a roman candle as it scans your incoming email when it finds this one.

6 posted on 12/14/2004 7:25:49 PM PST by upchuck (This tag line shutdown for it's "30,000 messages posted" check up.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Tumbleweed_Connection; All
Help for viruses and malware:
 
 Ad-Aware ... Spybot ... Peper Uninstaller ... HijackThis... CWShredder ... Spyware Blaster ... IE Spyad ... Free online Virus scan ... AVG AntiVirus ... LSPfix ... How to Show Hidden Files ... How to boot into Safe Mode ... How did I get infected in the first place?


Things you need--(all FREE)
Anti-Virus
AVG Anti-Virus version 7 (free) release available...
 Avast
Firewall
Kerio(Direct Download) Zone Alarm
 If are using zone alarm it may slow your PC. Try Outpost Firewall http://www.agnitum.com/products/outpost or Sygate Firewall http://www.sygate.com/ both have FREE and Pro versions and are heads above ZA.
Misc.
IE Spyads SpywareBlaster Spyware Guard
Windows Update- you must keep updated, it is the start of a secure system-
get all CRITICAL Updates

Things you want(Still Free)
 
 Get Firefox I use Firefox PR1 and IMHO, beats the sox off MS Explorer. Life is good with tabs. Click the link and give it a try.

Ad-Aware
Spybot S&D
SpywareBlaster
MS MVP Hosts file
Mike Lin's Homepage and get the Startup Control Panel and Startup Monitor tools.
 
The best forum for malware removal:
-SWI Forums-


Three fast suggestions?

1- keep your OS updated-- first line of defense.
2- use another browser besides IE... even that old Netscape 4.7 you forgot about on a free disc is better, but you will like Firefox- try it today.
3- set up a home network and hide behind a hardware firewall.

7 posted on 12/15/2004 12:41:43 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the Trackball into the Dawn of Information...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe

Thanks for posting all of that. I do like firefox.


8 posted on 12/15/2004 12:45:29 AM PST by MarMema
[ Post Reply | Private Reply | To 7 | View Replies]

To: MarMema

Thanks for looking-- my wife found 535 malicious files on her office PC the first time she ran Ad-aware a few months ago... claimed it was "teenagers getting into the office after hours..."


9 posted on 12/15/2004 12:52:05 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the Trackball into the Dawn of Information...)
[ Post Reply | Private Reply | To 8 | View Replies]

To: backhoe
LOL. My 16 yo daughter just cannot understand why she gets all the junk she does on hers. If you watch her she is all over the internet with scores of pop-ups and ads on sites.

Finally she is so slow that the thing hardly moves, and my husband reformats the hard drive.

10 posted on 12/15/2004 12:55:41 AM PST by MarMema
[ Post Reply | Private Reply | To 9 | View Replies]

To: MarMema
Finally she is so slow that the thing hardly moves, and my husband reformats the hard drive.

Yep, the old "fdisk & format C: /s" cure will get anything, except that nasty stuff that flashes the BIOS chips in various subsystems. I've tossed out two CD burners so infected, before I got a hardware firewall.

11 posted on 12/15/2004 1:03:29 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the Trackball into the Dawn of Information...)
[ Post Reply | Private Reply | To 10 | View Replies]

To: backhoe

Hmmm, how would you find out you had whatever that is?


12 posted on 12/15/2004 1:06:19 AM PST by MarMema
[ Post Reply | Private Reply | To 11 | View Replies]

To: MarMema
The drives in question started making eerie noises, popping the tray in & out, and the LEDs went through color changes that I have never seen before-- amber, green, red... and, naturally, the drives didn't work at all.

Web research found references to "coffee cup," a virus that pops the tray out, but I never found what was actually causing it.

Since the BIOS chips in most new hardware are flashable, I surmised that was causing it.

At the time, the only company offering to re-flash any BIOS was in England, so I decided it was cheaper, and less hassle, to replace the drives.

This was about the same time I got a newer PC and a firewall, so I never learned the cause.

And despite all the "stuff" between me & the internet, I found "imscan.dll" lurking in the machine last night. Vermin!

13 posted on 12/15/2004 1:19:19 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the Trackball into the Dawn of Information...)
[ Post Reply | Private Reply | To 12 | View Replies]

To: backhoe

Thanks for the info. It's a never ending attack, I know.
They are vermin.


14 posted on 12/15/2004 1:21:09 AM PST by MarMema
[ Post Reply | Private Reply | To 13 | View Replies]

To: MarMema
It's a never ending attack, I know. They are vermin.

The more rational side of me wants to see these characters triple-fined for lost time and damages...

...the more atavistic side wants them stripped in public, in the town square, flogged, and then chained to the whipping post for a week.

And forced to trim the grass in the public square with a pair of manicure scissors...

...and, no, I am not kidding about that public whipping at all. Maybe if we re-introduced the element of humiliation and shame, the scum who write and propagate this garbage would see how much they are despised. I spent two weeks clearing their junk out of my home systems, and I am still in a vengeful mood.

15 posted on 12/15/2004 1:41:37 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the Trackball into the Dawn of Information...)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Tumbleweed_Connection
I think my computer is infected or hijacked. What should I do?

Wilders Security Forums

CastleCops

Secunia - Vulnerability and Virus Information

16 posted on 12/15/2004 1:44:04 AM PST by this_ol_patriot
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe

It is really frustrating. The thing that I used to get were those homepage diversions. I had to wonder if they thought that in your frustration and anger you would really buy something from them. I would think most people would make sure to never buy from those who hijack your homepage.


17 posted on 12/15/2004 1:57:13 AM PST by MarMema
[ Post Reply | Private Reply | To 15 | View Replies]

To: MarMema

Windows downloaded four critical updates this morning. I am installing them now.


18 posted on 12/15/2004 2:03:58 AM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 17 | View Replies]

To: goldstategop

Thanks. I had better tell my daughter. :-)


19 posted on 12/15/2004 2:24:18 AM PST by MarMema
[ Post Reply | Private Reply | To 18 | View Replies]

To: goldstategop
Windows downloaded four critical updates this morning-

Thanks- going there now.

20 posted on 12/15/2004 2:45:29 AM PST by backhoe (The 1990's? The Decade of Frauds...)
[ Post Reply | Private Reply | To 18 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson