Site Directory
Popular Links
|
ExploreZip Worm ReturnsMiniZip compressed version sneaks past anti-virus appsITinfo SponsorERROR: Random File UnopenableThe file was not found on your file system. This means that it has either not been created or the path you have specified in $trrandom_file is incorrect.
ExploreZip Jr. Foils Anti-Virus Softwareby Dave MurphyISSN 1535-3613
A new compressed version has attacked several major companies. According to Dan Schrader, Trend Micro's Vice President of New Technology, "ExploreZip hasn't been altered at all: all someone did was store it in a very unusual compression format, called Neolite. We already scan for compressed files, but they chose one that we don't [detect] so far." It's being dubbed MiniZip by some security vendors. It's the same technology as the worm's first iteration, but because it's signature is altered by the Neolite compression, anti-virus programs can't yet detect it. All three leading anti-virus security firms, Network Associates, Symantec, and Trend Micro have received copies of the virus from infected customers. If the worm's infection follows the same pattern as the original ExploreZip, Asia will see a marked increase in rates of infection overnight Tuesday evening, and the U.S. and Europe will follow with infections on Wednesday. The worm's payload is the same as before: deleting files, and automatically sending infected email messages to address book lists. It affects systems running Microsoft Outlook, Outlook Express, and Exchange.
Call for CommentsWhat do you think? Have you run across the ExploreZip virus? Leave your comments on the message center: http://itrain.org/msg/
Related ArticleWorm.ExploreZip Does More Damage
ReferencesTrend MicroNetwork Associates Symantec AntiVirus Research Center
Previous issues are on our website at http://itrain.org/itinfo/.
International Association of Information Technology Trainers
410.567.5366 Copyright © 2000 International Association of Information Technology Trainers, Ltd., All Rights Reserved
http://itrain.org/itinfo/1999/it991130a.html |