Anna virus rushes the Net

By Robert Lemos CNET News.com, CNET.com
Tuesday, February 13, 2001 06:21 AM
A virus posing as a photo of Russian tennis player Anna Kournikova spread aggressively on Monday, as major security companies rushed to update their antivirus software to detect the fast-spreading email virus.

"Compared to the Love Bug, it's spreading twice as fast," said Alex Shipp, antivirus technologist with British email service MessageLabs. In the five hours since MessageLabs detected the infection, its users have received almost 2,900 copies of the infected email sent from more than 290 different domains.

Also known as VBS/SST, the virus initially poses as an attachment--AnnaKournikova.jpg.vbs--included in a message with one of three similar subject lines: "Here you are ;-)," "here you have ;o)" and "here you go ;-)."

The virus uses the Visual Basic scripting language to infect Windows systems and then, on systems using Microsoft's Outlook email program, mails itself out to the entire address book. The ability to mail itself out to a large number of Internet users classifies the virus as a worm.

The virus does not damage the systems it has infected, said Vincent Weafer, director of Symantec's AntiVirus Research Center.

And while the virus has only a few subject lines--which makes it easy for network administrators to filter it out before it ever reaches the desktop--it does use encryption to make it harder for antivirus software to detect it.

"Internally, it's highly polymorphic, which means it changes its signatures to hide itself from antivirus software," said Weafer. He said SARC has only seen 20 copies of the virus but expects it to spread quickly.

As of 11:15 a.m. PST, major antivirus software makers had either posted patches to detect the virus or were already detecting it with the latest version.

"We are working on detection right now," said Weafer.

Businesses which had detected the virus or had been infected by it kept the security companies busy early Monday. Symantec had received 20 calls from clients in the morning, Network Associates almost 50, Computer Associates nearly 25 and Trend Micro a dozen.

Antivirus software maker Trend Micro said the virus had hit many different types of companies.

"We have heard from a government agency that has seen 200 hits per hour," spokeswoman Susan Orbuch said. "Others include a banking institution, a major networking company, a beverage company and an insurance company. You are not just seeing it in one sector."

Several experts believe the worm to be the product of a so-called "virus creation kit," a program that lets any online vandal with rudimentary computer skills to point-and-click their way to creating malicious code.

Trend Micro's software detected the virus originally as VBS_KALAMAR, and believes that Kalamar is the name of the author of the virus creation kit.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

10 open source projects worth checking out

Open Source

The open source field is pretty crowded, but certain projects stand above the rest. Here are 10 tools and solutions you don't want to overlook.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. battery
  2. camera
  3. graphics
  4. hard drive
  5. hewlett - packard co.
  6. high tech computer corp.
  7. intel corp.
  8. keyboard
  9. microsoft windows
  10. microsoft windows mobile
  11. mobile
  12. network
  13. notebook
  14. performance
  15. screen
  16. server
  17. storage
  18. touchpad
  19. usb
  20. vat