Read up on the latest ideas and technologies from companies that sell hardware, software and services. Solve Exchange Mailbox Storage Issues Once and for All
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Wireless LANs: Is my enterprise at risk?
Revolutionising Back-up and Recovery
Why Security SaaS Makes Sense Today
Web Security SaaS: The Next Generation of Web Security
Best Practice in Building an Integrated Information Management Strategy
Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
On Dec. 22, an Internet investigator got a tip that child pornography was being housed on an adult Web site. When he visited the site to verify the information, he didn't find any illegal images. But what he did find was a Trojan horse that disabled the ActiveX security controls on his browser and took control of it.
"I heard my hard drive churning and clicked on my task manager and saw three executable programs were installing themselves," says Chris Brandon of Brandon Internet Services. "I knew I was in trouble when I couldn't get my task manager to cancel the programs."
By the time he checked his registry, the Trojan had installed dozens of programs that replaced the default Web page with its own, and loaded its own IP addresses in his favorite places, short cuts and safe zones. When he tried to erase the programs and reboot the machine, the virus reinstalled.
This program is a perfect example of spyware gone amok.
It installed itself by taking advantage of a vulnerability in Internet Explorer 4.x and 5.x that lets an unsigned applet to create and use ActiveX controls. Then it hijacked Brandon's browser, a term called "Web-jacking." But it could have been worse. Some variants evoke dialers to call up 1-900 numbers if the victim is using telephone dialup for Internet access.
"We're seeing more of this type of virus activity in recent months," says Ken Dunham, director of malicious code for iDefense, a security intelligence firm in Reston, Va. "Trojans promote going to certain pornography sites and other sites they affiliate with because they get money for the clicks from advertisers. They terminate regedit.exe (registry editor), and they can be very difficult to remove."
Anti-spyware vendor PestPatrol Inc. reports staggering growth over the past few months of the virus that Symantec Corp. dubbed Trojan.Norio. And at least 24 variants of the virus now exist in the wild, according to the anti-spyware site Spywareinfo.com.
Each variant is designed to do something different. One variant changes your customized search settings to allhyperlinks.com, for example. Another variant redirects all searches through a bogus site called Coolwebsearch.com. Another redirects Verisign Inc.'s Site Finder to a fraudulent Site Finder site. Another evokes the auto-dialer. And so on.
Expect these types of Trojan viruses to be used for even more malicious purposes, such as the culling of credit cards and passwords, Dunham says.
"In the case of the Norio Trojan, it changes the registry and the host file," he says. "You type in a name like Microsoft.com, it will redirect you to a site they want you to go to. You could make it redirect you to a fake Citibank.com Web site and get you to fill in sensitive information."
Brandon removed the malicious code by using Spywareinfo's remediation kit called CWSweep. (PestPatrol also provides a removal kit.) He's since been tracking down the IP addresses and domain names that the virus loaded into his registry. Many of the domain names are a variation of Coolwebsearch.com.
"I want to find the people responsible for this, the affiliates in collusion with this, and turn them into Microsoft for that bounty it promises on virus writers," he says.
With the IP addresses and Web site names so easy to find, you'd think tracking the virus writers would be easy for someone with Internet tracking skills. But most of the IP addresses Brandon's investigated led to bogus hosting providers and anonymized administrative contacts. Meanwhile, the PestPatrol report on the virus lists an address for Coolwebsearch.com, the originator of the virus, to be in Natick, Mass.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
New Verizon Business Managed Service Makes Collaboration Easier 2008-10-13 10:06:00+10
F-Secure achieves excellent results in Internet security suite comparison 2008-10-10 14:37:00+10
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 2008-10-10 08:51:00+10
Pitney Bowes MapInfo Launches New Version of AnySite 2008-10-10 05:58:00+10
IOGEAR Gears Up in Australia 2008-10-09 20:18:00+10
Email Archiving Implementation: Five Costly Mistakes to Avoid
Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.










