26 Sep 2006
IT security experts have issued a 'severe risk' threat warning after detecting a virulent new worm spreading in the wild.
Kaspersky Lab warned that Win32.Warezov.at uses its own SMTP engine to send itself to email addresses harvested from the Windows address books on infected machines.
The subject line, message body and attachment name vary, but mail system messages like 'Mail Server Report', 'Mail Delivery System' and 'test' are typical.
The worm runs when the user clicks on the attached file, a portable executable of around 117KB, packed using UPack. The worm copies itself to disk and modifies the registry to ensure that it loads automatically on start up.
David Emm, senior technology consultant at Kaspersky Lab, said: "It has been some time since we've seen an email worm outbreak. But email worms still have all the ingredients necessary to spread successfully, not least through social engineering.
"Users should be wary of emails received from unknown sources, and make sure that their antivirus protection is up to date."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Field/Site Engineering Manager/Leader Brief: Polar...
Product Manager, Open Repository (ref:BMC/PMR) End...
Java/J2EE Software Developer/Programmer - Dotcom/ eCommerce...
Field/Site Engineering Manager/Leader Brief: Polar...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
This is why I use McAfee
McAfee has a default rule built into their AV product which won't allow user/admin defined mail engines to operate. I'm protected with no update and nothing to configure. Risk? What risk? Only to those who are using inferior products.
Posted by: Chipper 28 Sep 2006