ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Proof-of-concept malware targets Windows PowerShell

Graeme Wearden ZDNet.co.uk

Published: 01 Aug 2006 17:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Virus writers in Austria have reportedly developed malicious code that targets Windows PowerShell, the command line interface (CLI) shell and scripting language product being developed by Microsoft.

Security firm McAfee warned this week that it had detected the worm, called MSH/Cibyz.

MSH/Cibyz is designed to spread using the Kazaa file-sharing network, and the worm runs in PowerShell, which is due to ship in the second half of this year. PowerShell will underpin future Microsoft products such as Exchange Server 2007.

The worm doesn't exploit a specific security hole in PowerShell. Instead, it abuses the product's ability to execute scripts, by attempting to trick users into downloading and running malicious code. To do this, it uses a series of product names that may be attractive to Kazaa users. If run, the worm will overwrite some file types, change registry details and place itself in the machine's Kazaa shared folder in order to spread.

This type of threat isn't specific to PowerShell, and has existed for many years. It's likely that most commercial malware protection would be able to detect and remove a worm that behaved in this way. McAfee said its own security software will offer protection, but users should also be cautious when receiving files from P2P networks.

It's thought that the group behind MSH/Cibyz was also responsible for a virus last summer targeting PowerShell. F-Secure was criticised for identifying this as "the first virus to target Vista". At the time, PowerShell, earlier known as Monad, was expected to be included in Vista, but Microsoft subsequently laid out a separate release schedule for the product.

ZDNet UK's Jonathan Bennett contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
48 out of 113 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Messaging Support Analyst at Top Investment Bank

Exchange, List Server, Active Directory, Blackberry Enterprise Server, TREND (virus protection), MindAlign chat and MailMarshal. Top Tier Global Bank ...

1st - 2nd Line support East Sussex

Anti-virus software (McAfee) Windows XP Pro, Vista 3. My media client is a leader in their field looking for a contractor to take on a 3 -3 6 month ...

Vista programmer sought for Oxfordshire leading service firm

This is a unique role for a Vista programmer to join a leading distribution firm, which is based in Oxfordshire. Vista/Access applications. You will ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment