On CBSSports.com: Mike Tyson's daughter dies in accident
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matthew Broersma
Posted on ZDNet News: Jan 2, 2004 8:15:00 PM

Antivirus experts are warning of a troublesome, Christmas-themed e-mail worm and a virus that spreads via MSN Messenger, the popular instant-messaging application.

The Jitux.A virus is not destructive but has already begun to spread via MSN Messenger, according to Panda Software. When executed, the file becomes resident


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


in memory and sends messages to other MSN Messenger users every five minutes, prompting them to download the virus' code, contained in a file called jituxramon.exe.

The virus started to spread more rapidly Friday, affecting mainly Portugal, Spain and Mexico, said Panda Software. It affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003 and Windows XP. Users can remove the virus simply by scanning their PCs with antivirus software that has up-to-date virus definitions, from Panda, Symantec, McAfee or others.

More troublesome is the PE_QUIS.A worm, according to antivirus company Trend Micro; it is also called W32.HLLP.Belzy@mm by Symantec and has been detected in the past few days by several other companies. Quis spreads itself via Outlook as an e-mail containing a destructive payload. The worm affects Windows 95, 98 and ME.

The worm infects all .exe files in the My Documents and C:\progra˜1\mirc folders. Among its less disruptive effects, it overwrites ring-tone files (using the extension .rtx) with the tune "Jingle Bells" and subjects the user to a quiz.

The worm arrives in an e-mail with the subject line, "Merry Christmas!" The body reads: "You've probably received enough e-cards. Here's a nice Christmas screensaver instead :)," and the message carries an attachment called xmas.scr.

Removal involves identifying infected files with an antivirus program, deleting them and then undertaking the tricky process of removing autostart entries from the registry. Detailed instructions can be found on Trend Micro's Web site. Updated virus definitions can be obtained from Trend Micro, Symantec and others.

When an infected system is restarted, Windows automatically runs an application called "startup.exe", which begins by informing the user that the PC is infected. The pop-up message reads, in part: "Your computer is infected with Win32.HLLP.Quizy. However, if you complete the quiz, you may be able to disinfect it."

The quiz contains such seasonal questions such as "Which animal would Santa have if he actually existed?" (reindeer) and "Which season do I hate the most?" (winter). The virus writer's nationality is signposted in some questions, such as, "In which country do I live?" (Belgium) and "Which keyboard layout is used in Belgium?" (azerty).

Other questions are technical, such as "Which chipset does a U.S. Robotics 22Mbps Wireless PC Card have?" (acx100), or whimsical, such as "What does antivirus person Graham Cluley have between his toes?" (cheese).

Upon completion of the quiz, the program executes the infection code again, and directs the user to a Web site which promises information on how to remove the worm.

Matthew Broersma of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 44 Talkback(s)
And still.
It's everything windows wants to be, innovative, stable,
secure, intuitive. Did I mention secure and stable? Seems
that MS is still playing catchup, because they can't innovate.... (Read the rest)
Posted by: Rick_K Posted on: 01/05/04 You are currently: a Guest | | Terms of Use
Happy New Worm  Loverock Davidson | 01/02/04
Must be...  Nullifidian | 01/02/04
Nope  Loverock Davidson | 01/02/04
Loverboy would leave his wife @ the altar...  GRindinAxTaRupy | 01/02/04
Like you wouldn't  Loverock Davidson | 01/02/04
Actually...  GRindinAxTaRupy | 01/02/04
Could have fooled me...  DarbyOhara | 01/05/04
slow day at work???  guitar player | 01/03/04
Work on saturday, do you flip burgers?  Suicida| | 01/04/04
Hmmmm  DarbyOhara | 01/05/04
You are truly...  GRindinAxTaRupy | 01/02/04
Newsflash: Linsux replaces Unix  guitar player | 01/03/04
Sorry strummer boy  GRindinAxTaRupy | 01/03/04
Wow...  Martin Marvinski | 01/02/04
More wow...  pschroeder@... | 01/03/04
yes but...  stephen732@... | 01/03/04
..and...  pschroeder@... | 01/04/04
Why bother with OSX  Suicida| | 01/04/04
And still.  Rick_K | 01/05/04
You have some serious issues  NoB$ | 01/02/04
Who am I to let you down?  prime21 | 01/02/04
Not only that...  GRindinAxTaRupy | 01/02/04
Summary  Martin Marvinski | 01/02/04
Yeah yo left something out  Suicida| | 01/04/04
not to be picky as I agree with you but...  help4pki | 01/02/04
Oh, come on...  prime21 | 01/02/04
sorry  help4pki | 01/02/04
dont be  Suicida| | 01/04/04
Oh, I forgot to mention...  GRindinAxTaRupy | 01/02/04
And therein lies the problem with Linux  d_jedi | 01/03/04
Eh?  Chad_z | 01/04/04
Being that......  Rick_K | 01/04/04
and  Suicida| | 01/04/04
Who am I to let you down?  swordjp1@... | 01/05/04
Never . . .  FilledOut | 01/02/04
Linux is junk  Mike Cox | 01/02/04
perhaps youo meant...Oracle is junk  help4pki | 01/02/04
awww, dude...  Martin Marvinski | 01/02/04
Mike isn't a troll,  MalumRegnat | 01/02/04
Much needed  Suicida| | 01/04/04
your idea of quick  JWatson77 | 01/04/04
Especially if done correctly  Suicida| | 01/04/04
You are in the minority Mr. *****  menk | 01/05/04
Well, that Big Bounty...  Yen_z | 01/02/04

What do you think?

SmartPlanet

advertisement
Click Here