Anna virus rushes the Net

By Robert Lemos CNET News.com, CNET.com
Tuesday, February 13, 2001 09:09 AM
A virus posing as a photo of Russian tennis player Anna Kournikova spread aggressively on Monday, as major security companies rushed to update their antivirus software to detect the fast-spreading email virus.

"Compared to the Love Bug, it's spreading twice as fast," said Alex Shipp, antivirus technologist with British email service MessageLabs. In the five hours since MessageLabs detected the infection, its users have received almost 2,900 copies of the infected email sent from more than 290 different domains.

Also known as VBS/SST, the virus initially poses as an attachment--AnnaKournikova.jpg.vbs--included in a message with one of three similar subject lines: "Here you are ;-)," "here you have ;o)" and "here you go ;-)."

The virus uses the Visual Basic scripting language to infect Windows systems and then, on systems using Microsoft's Outlook email program, mails itself out to the entire address book. The ability to mail itself out to a large number of Internet users classifies the virus as a worm.

The virus does not damage the systems it has infected, said Vincent Weafer, director of Symantec's AntiVirus Research Center.

And while the virus has only a few subject lines--which makes it easy for network administrators to filter it out before it ever reaches the desktop--it does use encryption to make it harder for antivirus software to detect it.

"Internally, it's highly polymorphic, which means it changes its signatures to hide itself from antivirus software," said Weafer. He said SARC has only seen 20 copies of the virus but expects it to spread quickly.

As of 11:15 a.m. PST, major antivirus software makers had either posted patches to detect the virus or were already detecting it with the latest version.

"We are working on detection right now," said Weafer.

Businesses which had detected the virus or had been infected by it kept the security companies busy early Monday. Symantec had received 20 calls from clients in the morning, Network Associates almost 50, Computer Associates nearly 25 and Trend Micro a dozen.

Antivirus software maker Trend Micro said the virus had hit many different types of companies.

"We have heard from a government agency that has seen 200 hits per hour," spokeswoman Susan Orbuch said. "Others include a banking institution, a major networking company, a beverage company and an insurance company. You are not just seeing it in one sector."

Several experts believe the worm to be the product of a so-called "virus creation kit," a program that lets any online vandal with rudimentary computer skills to point-and-click their way to creating malicious code.

Trend Micro's software detected the virus originally as VBS_KALAMAR, and believes that Kalamar is the name of the author of the virus creation kit.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

OpenAmplify developer's diary Pt. 4: Using OpenAmplify via SOAP

Web Development

Justin James walks you through the process of using the SOAP interface to OpenAmplify from Visual Studio 2008.


Read more »



When technology costs more than human

Blog thumbnail

Movie director James Cameron waited 15 years for technology to catch up before it was sufficiently advanced for him to create the much-anticipated upcoming film, Avatar.

To be released in..... by Eileen Yu

Read more »

Tags

  1. 3g
  2. 3g third generation
  3. apple inc.
  4. apple iphone
  5. broadband
  6. cellular phones
  7. google inc.
  8. handset
  9. mobile
  10. mobile platforms / communications
  11. mobile / wireless
  12. network
  13. phone
  14. revenue
  15. smart phone
  16. smart phones
  17. software
  18. u.s.
  19. web
  20. wireless