ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Wallon virus wrecks Windows Media Player

Munir Kotadia ZDNet.co.uk

Published: 12 May 2004 16:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new mass-mailing virus called Wallon, which destroys Windows media player and is activated when a user tries to play MP3 or video files from an infected PC, was discovered in Europe on Tuesday.

Traditionally, mass-mailing viruses such as Netsky and Bagle are spread as attachments. When an unsuspecting user opens the infected attachment, it executes a piece of code that usually attempts to steal the user's address book and often opens a back door to give hackers easy access to the system's resources.

Maikel Albrecht, product manager at Finnish security company F-Secure, said that because of recent virus outbreaks, users are less willing to open email attachments, which is why Wallon's author is counting on users clicking on an email link instead.

"The link in the email points to the actual virus, so if you click the link you download the virus," said Albrecht.

However, once the PC is infected, Wallon remains dormant until the user tries to run a media file such as an MP3 or a video. If by default the system uses Windows Media Player, the virus is activated and attempts to send HTML emails, each with a link to the virus file, to any email addresses in the computer's address book.

"If you try and play media content, the worm will activate and start spreading but the user will not see the media player," said Albrecht.

Wallon requires intervention by the user before it can replicate, so Albrecht expects it will not spread very quickly. But unlike common viruses, Wallon is destructive because it replaces the wmplayer.exe file, which means that users infected by the worm will need to reinstall Media Player.

Stuart Okin, chief security officer at Microsoft UK, said anyone worried about Wallon should install Microsoft's MS04-13 patch, which was released in mid-April and solves the problem.

Okin said that if a user has been infected and can no longer use their Media Player he or she should first ensure the system is no longer infected by the virus and then reinstall Media player either from his or her original Windows CD or from the Microsoft Web site.

Additionally, Okin said users should remain cautious about opening email attachments and they should avoid clicking on links in email messages whenever they can.

"When you receive a link to a Web site that you normally visit, don't click on the link, use your Favourites or type in the address in manually," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
55 out of 97 people found this useful


Full Talkback thread

2 comments

  1. This must be an example of the first virus worth h... Craven Moorehead
  2. help! chubz90

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Cisco & VOIP Engineer - 40,000 - Leeds

With an excellent working knowledge (at least 2years) of Cisco Phone Services and VOIP and experience supporting and administering call manager/call ...

Technical Support Specialist - 25,000 + CC - York

An illustrious world player in the Manufacturing industry are looking to recruit for a Technical Support Specialist to join the team based in York. ...

Oracle Applications Support Analyst - Salford - up to 30k

Financials, HR/Payroll and Order Management 1st Line experience Desireable skills; Support of E-Business Suite 11.5.10 Knowledge of SQL Knowledge ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments