16 Jan 2004
The latest variant of the MiMail worm is using a software downloader to spread its payload, in an effort to fool anti-virus software.
The downloader arrives in inboxes as a file, called paypal.exe or paypal.zip, in an email headed 'PAYPAL.COM NEW YEAR OFFER'.
Further reading
It offers a credit equal to 10 per cent of the host's PayPal account if the user registers with their credit card details.
MiMail was created in Russia and first appeared on the internet at the beginning of August 2003.
"To date, isolated incidents of infection by this malicious software have been reported in various countries throughout the world," said Denis Zelkin, head of communications at Kaspersky Labs.
"The new modification of the worm differs from previous versions only by the fact that it is compressed using UPX."
Once activated the Trojan contacts a Russian web server and downloads the latest copy of the MiMail worm.
This then harvests email addresses on the host and stores them in a file called outlook.cfg in the Windows folder. It also copies itself onto the registry so that it is reloaded with every reboot.
Major antivirus firms already have identity files on the malware and users are advised to update.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Project Manager – Retail / eCommerce / Prince 2 – City...
Project Manager - Business Change - Financial Services...
My client a leading IT Service Provider requires an AIX...
As a key UK and worldwide brand, we are constantly looking...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?