You are here: silicon.com > Software > Malware

Malware

Virus warning: Multilingual anti-firewall worm found

Zafi.B disables virus protection – but don't panic yet…

By ZDNet Australia Staff

Published: 15 June 2004 16:15 GMT

A new worm variant that can terminate antivirus applications has been discovered, prompting internet security vendor F-Secure to issue a level two warning.

The variant, called Zafi.B, is spread through email attachments in PIF., EXE. or Com attachments, and according to F-Secure, the worm "terminates all applications that have 'firewall' or 'virus' in their file-name".

The worm is capable of transmitting in several languages, including English, Italian, Spanish, Russian, Swedish, German or Finnish, said F-Secure, and spreads itself by collecting email addresses from the recipient's address book.

Zafi.B copies itself to the Windows System Directory when activated, and replicates itself as either "winamp 7.0 full_install.exe" or "Total Commander 7.0 full_install.exe" files in folders that contain "share" or "upload" in their names, according to F-Secure.

Manager for F-Secure, Mikael Albrecht, says the worm is particularly complicated as it has the capacity to penetrate firewalls and antivirus applications in order to "help itself spread further".

"Another interesting thing about this worm is that the infected messages come in many different languages. As most of the widely spread worms use only English, this feature may confuse the user to open the message - and the worm spreads on", he said.

However, internet security firm Symantec has listed the virus as having an "easy" threat-containment rating and a "low" geographical distribution area.

A Symantec spokesman maintained that the worm is still "nothing significant".

"The worm tries to disable the security processes on the machine to make it more vulnerable to other attacks," said the spokesman.

He said that users who notice unusual messages regarding system vulnerability may be infected and should scan their computers to guard against further infection.

For more news from ZDNet Australia click here

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Symantec Security Consultant, Symantec Endpoint, SEE, Cisco, London

Security Engineer / Network Security Consultant will be focused (but not exclusively) on Symantec Endpoint Technologies like encryption, antivirus, ...

Network Operations Centre (NOC) Analyst

s services.Escalation management including tracking, recording provision of conference calls etc.Proactively inefficiencies with elements of the ...

SEO Specalist with International Experience

SEO Specalist - Trading Software- London Essential Skills- Extensive SEO (Search Engine Optimisation) knowledge, Fluent in English and either French, ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: