ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Russian firm warns of Roron virus

Published: 07 Nov 2002 10:49 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Russian antivirus company on Wednesday warned that a new virus could help hackers gain control of home computers, but other security companies downplayed the threat.

Kaspersky Labs has named the virus, or worm, Roron, and it is known as Oror.B by several other companies. The new computer virus can spread through email messages, shared hard drives and the Kazaa file-sharing network, Kaspersky Labs spokesman Denis Zemkin said.

"We see that this worm is particularly dangerous for home users," Zemkin said. "Corporate customers are already aware of the danger of attachments", and are unlikely to open the file containing the program.

Kaspersky Labs sent out an advisory on Roron that rated the virus a "high danger" because of the various ways the program can spread. The company also cited the worm's goal of enabling online vandals to use a victim's PC as a platform from which to launch attacks. Each copy of the virus contains several hacker tools that let an infected computer be controlled by way of messages from Internet relay chat (IRC). With the IRC messages, online vandals could launch a denial-of-service attack, which unleashes a deluge of data at a computer or router, flooding the device's bandwidth and cutting it off from the Internet.

Security company Symantec, however, said it will most likely rate Roron as only a two on its threat scale of five, said Sharon Ruckman, senior director of Symantec's security response group.

"We haven't had any reports in the US of this virus yet," Ruckman said, adding that the company's clients in Europe had seen very few copies. "We'll watch it."

Kaspersky Labs' clients are mainly European, with a strong concentration in the nations that once made up the Soviet Union.

Email service provider MessageLabs said Roron didn't appear on its Top 10 list of malicious attachments, a list the UK-based company culls from the messages it filters on behalf of clients. The lowest scoring virus on that list, Yaya.c, only represented 77 attachments in the last 24 hours.

The Roron virus is the latest of five variants of an email worm that appeared in August and is known by most companies as Oror. Kaspersky Labs believes Roron was created in Bulgaria, because several words found in the worm's code are written in that language.

Once Roron infects a system, it spreads by creating email messages with different subject lines and different names for the attached file that carries the worm.

Once opened, Roron copies itself to several folders, including those used to share music files in the Kazaa network, as well as to any shared hard drives on a network. In that way, the virus resembles another worm that began spreading through the Kazaa network in May.

Finally, Roron installs a backdoor program onto the PC that lets remote attackers run attack tools.

Kaspersky Labs believes that if the virus becomes popular it will quickly burn itself out, said Zemkin.

"I don't think it will be long infection, like the Klez (virus)," Zemkin said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
27 out of 57 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

C# / .Net Excel VBA Development Derivatives - 450

The requirement is going to based working with the Quant team to develop a spread sheet pricing application. C# / .Net Excel VBA Development ...

Technical Author - Contract - London - URGENT

Knowledge of Symantec NetBackup, Network Appliance Filers, Windows environments with SQL Server and Exchange 2007 would be desirable. Huxley ...

Senior Java developer -J2E/EJB/SPRING-London-40K

Their method of delivering targeted messages to website readers is in need to top developers with a high level of expertise. Senior Java developer ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal