ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Braid virus winds its way through email

Published: 05 Nov 2002 09:16 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new mass-mailing computer virus known as W32.Braid has slowly spread among PCs over the weekend, said UK email service provider MessageLabs.

Although the company has seen only 43 copies of the virus -- indicating an extremely slow start -- W32.Braid shares some attributes of the widely spread Klez family of viruses and could have similar success. Among the similarities, both viruses forge a fake sender address in the emails they use to propagate themselves, which makes finding infected PCs more difficult.

The Klez.h variant of the Klez virus has sent out millions of email messages with a copy of itself attached. Since it was first placed on the Internet in April, the virus has topped the charts of malicious email attachments found by antivirus firms and email service providers, which filter junk email for companies and also zap messages that have viruses attached.

W32.Braid, also known as PE.Brid, can spread to PCs running any version of Microsoft Windows. People who use Microsoft Internet Explorer 5.01 and 5.5 may find that their computers automatically become infected, because Braid uses an old flaw in Internet Explorer to automatically execute the attachment that carries it when the email message is viewed. Patching the program with Service Pack 2 will solve the problem, Network Associates said in its advisory on the virus.

Like Klez, Braid contains its own email engine, so once it infects a computer, it doesn't need to use an email client, such as Outlook, to spread. The virus will also attempt to infect any program, as well as screen saver files. So far, though, antivirus researchers believe that Braid simply spreads itself, and doesn't actually destroy data.

While many of the tactics Braid uses to spread resemble those used by the Klez family, the program itself seems closer to a more famous virus, LoveLetter. Antivirus software from Network Associates and rivals Symantec and Trend Micro all detect Braid as a variant of FunLove, a close relative of LoveLetter.

Because the virus is already detected by all major antivirus software, the application makers have labelled Braid a fairly minor danger.

Network Associates has rated Braid a low-priority threat, while Trend has rated the virus a medium risk, and Symantec has given the worm a two out of five, with five being the most severe.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
34 out of 68 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS Active Directory 2000/2003 and MS Exchange messaging ...

Market Risk Analyst Energy Major (55K)

This role will give you excellent exposure to a number of markets including coal and freight, UK power, spark and dark spread, the UK-France ...

Purchasing Manager - 40-45K+bonus & car allowance

Private Family Healthcare If you are interested in this exciting opportunity please either apply with an updated version of your CV or ask to speak ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal