All the latest UK technology news, reviews and analysis

Email virus poised to strike

by Iain Thomson

03 Jan 2003

Be the first to comment

  • Tweet this

New variants of the Yaha worm are making it an unpleasant new year for some IT managers, but only a few antivirus software vendors are worried.

First identified on 21 December, the worm has spread slowly due to the lack of business computer use. But it could start to proliferate on Monday.

Yaha arrives as a double attachment with a .exe or .scr suffix. The worm has its own SMTP engine and distributes itself to all addresses in Windows Address Book, MSN Messenger and .Net and Yahoo Messenger software.

The virus sends emails with fake headers and has a large variety of subject headings. Only Windows machines are affected.

A secondary payload attempts to use the infected computer to launch a denial of service attack against a Pakistani government domain, infopak.gov.pk.

The fast initial infection rate sent the worm straight to number four in MessageLabs' December infection survey, and Symantec upgraded the worm's alert status on 30 December.

However, other companies are less worried.

Graham Cluley, antivirus specialist at Sophos, said: "We've only had a few dozen calls about it.

"We've had a cure since before Christmas, which has certainly helped, and there's a removal utility for anyone on our website.

"It's not going to be on the same scale as Bugbear. One of the main reasons for the slow spread could also be the increasing number of businesses which are blocking these kind of emails en masse. But some may slip through."

The Yaha types causing the most trouble are the 'K' and 'E' variants. The original virus was first detected in March.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

2%

14%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Project Manager (FATCA)

A client, a major financial services organisation, is...

Sharepoint Administrator, Birmingham, West Midlands

Sharepoint Administrator, Sharepoint 2010, Sharepoint...

PLC Control Engineers Wanted!

Proteus Europe, operating as an employment business...

Salesforce.com Senior and Leads

Salesforce.com Senior Consultants and Leads Salesforce...

To send to more than one email address, simply separate each address with a comma.