Nothing festive about this Zafi D variant
Nothing festive about this Zafi D variant
R E L A T E D   C O N T E N T
ADVERTISEMENT

Christmas worm speaks in many tongues

Where's the early bird when you need it?

Iain Thomson, vnunet.com 14 Dec 2004
ADVERTISEMENT

A new worm with a Christmas message has been detected as it began spreading around the world this afternoon.

Zafi D, originally designed by Hungarian programmers, arrives with the subject line 'Happy Christmas'. However, the mutant version of the infection has become multilingual, appearing in English, Italian, Spanish, Russian, Swedish and several other languages.

Once the .pif, .cmd, .bat, .com or .zip file attachment is opened the worm copies itself to the Windows System Directory with a random .dll name and 'Norton Update.exe'. The .exe file is added to the registry key.

Zafi D then harvests email addresses and sends itself on to entries in the host address book. But in a stealthy move, email addresses featuring the names of antivirus companies are not touched.

The worm also shuts down any firewall or antivirus applications and overwrites them with copies of itself. Windows tools like task manager and registry editor are also disabled. The worm also spreads via peer-to-peer file sharing software as a 11,745-byte file.

Five antivirus vendors have identified the virus to date and protection should be available for download.

See also:

Top 10 viruses and hoaxes in JanuaryMass-mailer refuses to go away during relatively quiet month  01 Feb 2005
Virus carried spam Trojan16 year-old Brit receives six-month suspended sentence for Randex worm  21 Dec 2004
Beware bogus Christmas greeting emailsZafi-D spreading rapidly around the world  16 Dec 2004
Promise of nude pics carries nasty surpriseGlamour model virus launches DoS attack against Chechen rebel websites  10 Dec 2004
Sober-I worm rises to number twoOld favourites still top of the virus pops  01 Dec 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities