ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

New Year rings in more worms

Matthew Broersma ZDNet.co.uk

Published: 02 Jan 2004 13:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus experts are warning of a destructive, Christmas-themed email worm and a virus that spreads via MSN Messenger, the popular instant-messaging application.

The Jitux.A worm is not destructive but has already begun to spread via MSN Messenger, according to Panda Software. When executed, the file becomes resident in memory and sends messages to other MSN Messenger users every five minutes, prompting them to download the worm's code, contained in a file called jituxramon.exe.

The worm started to spread more rapidly on Friday, affecting mainly Portugal, Spain and Mexico, said Panda Software. It affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003 and Windows XP. Users can remove the worm simply by scanning their PCs with antivirus software that has up-to-date virus definitions, from Panda, Symantec, McAfee or others.

A more dangerous worm is PE_QUIS.A, according to antivirus company Trend Micro; it is also called W32.HLLP.Belzy@mm by Symantec and has been detected in the past few days by several other firms. Quis spreads itself via Outlook as an email containing a destructive payload. The worm affects Windows 95, 98, and ME.

The worm infects all .exe files in the My Documents and C:\progra~1\mirc folders. Among its less disruptive effects, it overwrites ringtone files (using the extension .rtx) with the tune "Jingle Bells" and subjects the user to a quiz.

The worm arrives in an email with the subject line, "Merry Christmas!" The body reads: "You've probably received enough e-cards. Here's a nice Christmas screensaver instead :)," and the message carries an attachment called xmas.scr.

Removal involves identifying infected files with an antivirus program, deleting them and then undertaking the tricky process of removing autostart entries from the registry. Detailed instructions can be found on Trend Micro's Web site. Updated virus definitions can be obtained from Trend Micro, Symantec and others.

When an infected system is restarted, Windows automatically runs an application called "startup.exe", which begins by informing the user that the PC is infected. The pop-up message reads, in part: "Your computer is infected with Win32.HLLP.Quizy. However, if you complete the quiz, you may be able to disinfect it."

The quiz contains such seasonal questions as "which animal would Santa have if he actually existed?" (reindeer) and "Which season do I hate the most?" (winter). The virus writer's nationality is signposted in some questions, such as, "In which country do I live?" (Belgium) and "Which keyboard layout is used in Belgium?" (azerty).

Other questions are technical, such as, "which chipset does a U.S. Robotics 22Mbps Wireless PC Card have?" (acx100), or whimsical, such as, "what does antivirus person Graham Cluley have between his toes?" (cheese).

Upon completion of the quiz, the program executes the infection code again, and directs the user to a Web site which promises information on how to remove the worm.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
56 out of 117 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Security/Quality Analyst-00055189

Be the point of contact for security questions within the Accenture IT operation. Investigate any security questions delegated by the unit management ...

C# ASP.NET Developer Required URGENTLY!!!!!!

Are you an experienced developer using C# ASP.NET? Have you completed numerous contracts in web site development using these technologies? If so, ...

Business Analyst Required

If the answers to these questions are yes then this is the role for you. Further to the above questions, experience in the public sector ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment