Virus
Zhelatin first appeared on 19 January and 26 variants have been detected so far
R E L A T E D   C O N T E N T
ADVERTISEMENT

Zhelatin mutants storm virus charts

Raft of new variants detected

Robert Jaques, vnunet.com 13 Feb 2007
ADVERTISEMENT

The Zhelatin virus is challenging Bagle and Warezov for the dubious honour of number one virus after eight new variants were detected in the past four days, security experts have warned.

Kaspersky Lab said that Zhelatin.s, .t and .u were detected on 8 February, while Zhelatin.v was detected on 9 February. Four more variants, .w to .z, were detected during the weekend of 10-11 February.

The most significant of these is Zhelatin.u, which Kaspersky Lab currently rates as a 'moderate' risk.

Zhelatin first appeared on 19 January and 26 variants have so far been detected by Kaspersky since 22 January.

Zhelatin.u spreads via email as an infected attachment. The subject line, message body and attachment are variable.

The worm itself is a Portable Executable, between 5KB and 54KB in size, packed with UPX. The worm copies itself to the hard disk and modifies the registry to load automatically on start-up.

The worm terminates a range of antivirus and firewall applications and adds a rule to the system firewall to prevent its own activity from being blocked.

It also launches an SMTP proxy server on TCP port 25, allowing a remote hacker to use the infected machine as part of a spam botnet.

Zhelatin.u registers itself on the remote site, sending the network address of the victim machine before downloading a file containing the botnet configuration. This file is used to get data from the victim machine and to send spam.

The worm uses a rootkit to hide its own processes, files and registry changes. Kaspersky detects this component as 'Email-Worm.Win32.Banwarum.f'.

David Emm, senior technology consultant at Kaspersky Lab, said: "Zhelatin.u is just a re-packed version of an earlier Zhelatin variant. It is broadly similar in behaviour to several earlier variants, although there are significant differences.

"The Proactive Defense Module in KAV 6.0 and KIS 6.0 is able to block this new threat without the need for new signatures. Nevertheless, we recommend that users update their antivirus databases as soon as possible."


All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Maidstone, United Kingdom | Kent Police
  Forensic Computer Analyst - Police Headquarters, Maidstone, £27,891 - £38,476 Permanent Contract Digital devices and information communication technology are present in almost every investigation the police service undertakes. Kent Police Digital Forensics Unit is ... more >
London, United Kingdom | InterSystems
ARCHITECT / DEVELOPER, London, Very Competitive £  OBJECT ORIENTED DEVELOPER / PROGRAMMER / ARCHITECT with strong OO (object oriented) development experience required by world leading global software provider to act as Senior Technical Consultants. InterSystems Corporation ... more >
United Kingdom | Swansea University
Programmer/Analyst (Content Management System), £25,135 - £28,290 pa Administrative Computing Unit   Joining an established team your role is to develop and enhance the University's use of the Terminal-Four Content Management System. Working closely with technical ... more >
London, United Kingdom | Tru-Est Ltd
Head of E-Commerce & IT, London, £35,000 - £40,000 + BonusMain Responsibilities - To identify, develop and improve the commercial opportunities for the company's existing online productsTo identify and develop new online opportunities and products ... more >
More job opportunities