New Virus Attack Technique Bypasses Filters

Started by DuVeL, February 22, 2005, 05:58:49 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

DuVeL

New Virus Attacks Via RAR Files

A new article at eWeek indicates that Virus writers are using .RAR files to bypass Filters and Anti-Virus systems to infect computers. Most anti-virus software cannot scan a .RAR file, and most firewalls do not block the extension yet". Anti-virus vendors have acknowledged the presence of viruses delivered as .rar files in the past few weeks and are scrambling to develop tools to identify and eradicate the malware.


Quote:
Virus writers have once again gotten the drop on anti-virus vendors and IT administrators with a new technique that's finding early and considerable success.
Late last month, administrators and service providers began seeing virus-infected messages with a new type of attachment hitting their mail servers: an .rar archive. .Rar files are similar to .zip files in that they are containers used to hold one or more compressed files. Administrators who have seen .rar-packed malware say that none of the messages have been stopped by their anti-virus defenses.

Many of the messages in .rar virus e-mail are slick invitations to view pornographic content, which is part of the reason for the viruses' success, experts say.  One recent .rar virus that appeared at the end of last week is disguised as a patch from Microsoft Corp.


WHOLE text here: LINK
Survivor of LAN V, VI, VIII, IX, X, XII, XIV, XVI, XVIII, XX, XXIV, XXX, XXXII, XXXIV and XXXVI so far...
[QUOTE]Lionheart; Grolsch to DuVeL is like spinache to Popeye [/QUOTE]
[QUOTE]Cheesepuff...A cyborg is sent from the future on a deadly mission. He has to kill Ninja_Freak, a young Man whose life will have a great significance in years to come.Ninja has only one protector - DuVeL - also sent from the future. The Terminator uses his exceptional intelligence and strength to find Ninja_Freak & attempt to terminate him.
[/QUOTE]

Anonymous

The Golden Rule still applies:

If you don't know who it's from don't open it
If you do know who it's from be suspicious

:D