ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

British trojan launches weekend attack

Wendy McAuliffe ZDNet.co.uk

Published: 26 Nov 2001 12:38 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of a mass-mailing Internet worm has been spreading rapidly over the weekend and is reported to be reaching the epidemic levels of SirCam, according to British antivirus companies.

The "B" variant of the W32/Badtrans@MM virus has been attacking home and corporate PCs installed with Microsoft Outlook. It has initially been categorised as a medium risk, but is expected to reach high-risk levels by the end of Monday.

"All affected domains that we have detected have been home user ISPs (Internet Service Providers) -- it looks like the worm is gestating in the fertile ground of the home user base, but corporate users will be coming into work today and setting it off on business networks," said Mark Sunner, chief technology officer at antivirus company MessageLabs.

Since 10 am on Monday morning, MessageLabs has been detecting 100 instances of the worm passing through its servers each minute. On an average day, 10,000 viruses will be intercepted by Messagelabs at an Internet level, but Sunner expects more than 30,000 reports today, with 10,000 attributable to W32/Badtrans-B.

The "B" variant, which is though to have originated from Britain, combines a mass-mailing mechanism with a Remote-Access Trojan (RAT). RATs allow remote control over a machine, with the user having no idea that they have been infected. In this case, the RAT is dropped into the Windows directory, which attempts to email the victim's IP address to the virus' author and allows to author to access the PC and steal passwords and other sensitive information. The trojan also contains a keylogger program makes a record of the keystrokes, potentially capturing other vital information such as credit card and bank account numbers.

The worm arrives as an email attachment with a bogus extension that is 13,312 bytes in length. It spreads through Microsoft Outlook by replying to any unread emails in an infected user's inbox.

"Because it isn't using a security exploit but rather Microsoft Outlook to spread, people are just as vulnerable to infection as they were with Melissa and Loveletter, if they have no protection in place," said David Emm, product and marketing manager for antivirus company McAfee AVERT.

The original Badtrans worm was detected on 11 April by McAfee AVERT. Computers installed with Microsoft Outlook can protect themselves against the new variant by running a standard antivirus update.

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
45 out of 63 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Programme Office Support / PMO - London/Croydon - 250-320 Per Day

Excel skills - Good skills on Microsoft Project -Competent with Word and Microsoft Outlook - Experience of working in a large organisation, ideally ...

Exchange Engineer

Short Description: The Systems Administrator role will be responsible for resolving user issues relating to the use of the ...

Internet Team Leader

Responsibility for maintaining the integrity of the networks (i.e.providing adequate protection from viruses, spam, hacking, compliance with the Data ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains