ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

VBS worm targets Gnutella users

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 05 Jun 2000 08:49 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An unknown author has created a worm aimed at infecting Gnutella users.

Possibly malicious in intent, but benign in reality, the worm uses the Visual Basic Script language to store itself on an infected computer in 23 different files named, for example, Pamela Anderson movie listing.vbs, collegesex.vbs, Battlefield Earth.vbs, Napster Metallica Crack.vbs and NSync.vbs.

The worm can only spread to computers whose users execute the code by double-clicking on the file.

Anti-virus firm Trend Micro had not had any reports of public infections, but had posted an alert about the worm, which it calls VBS_GNUTELWORM, on May 31. The worm contains a simpler name, Gnutella Worm v1.1.

Gnutella is a free, distributed network for exchanging files, similar -- but technically different -- to Napster. While the network can be used to exchange any files, most files are pirated copies of music and software or porn.

"This is only going to affect people using the system," said Dan Schrader, chief security analyst for Trend. "This is not going to have a big impact on corporate America."

However, Gnutella users reported that numerous host computers had already been infected by their users clicking on the files.

By late Friday afternoon, ZDNet News could only confirm two infections by searching for the name of a specific file that the worm copies to the victim's hard drive.

By refusing to download -- and open -- VBS files, users of Gnutella can avoid infection.

The worm targets Gnutella by changing the gnutella.ini file to accept Visual Basic Script files and places the 23 Trojan files in the Gnutella download directory so that others on the network may find them.

The worm also creates a "victim" file with some statistics on what generation of the worm infected the user and on what date. One file found by ZDNet News listed itself as the 12th generation and infected the computer at 10 a.m. on May 31.

In addition, the worm copies a warning from its author to users of Gnutella: "If I was a naughty boy, I could use scripting to get name, email, whatever file I want."

Because users have to actively search for the files -- rather than have an infected file delivered to it as in the "ILOVEYOU" worm -- the rate of infection will be low and the worm should not spread widely.

But copycats based on the worm could prove to be more than the academic threat that this current worm poses.

For now, the greatest casualty seems to be the trust between users of Gnutella, said Schrader.

"It is another one of these worms that is eroding the trust relationship that these new distribution systems are based on," he said.

In the light of the recent denial of serivce attacks and the ILOVEYOU virus John Dvorak worries that we ain't seen nothin' yet. Go with him to AnchorDesk UK for the news comment.

What do you think? Tell the Mailroom. And read what others have said.

Go to ZDNet's ILOVEYOU Special Report

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
50 out of 114 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Want to make a name for yourself in C# Enterprise development?

Despite being a large national company you will be working within a team of 20 and have the great opportunity of standing out from the crowd and ...

Script Developer. London. 35,000 - 45,000. Java / C Programming

Script Developer Needed. ASAP. London. My client is a market leading developer of trading and risk management systems for some of the worlds premier ...

Software Development Manager(.Net/Web) - Household name -London(65K+)

Software Development Manager(.Net/Web) My Sports and Media client are a house-hold name, based in Central London. They are seeking a Software ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains