Feeds

Virus prevents you asking for help

Clever design

  • alert
  • submit to reddit

The Power of One Brief: Top reasons to choose HP BladeSystem

A virus which blocks victims from reaching antivirus web sites or even emailing for help is spreading around the internet after laying dormant for weeks.

MTX was first identified in August and was thought to pose relatively little risk, but its clever design is now leading to widespread problems.

November statistics from antivirus vendor Sophos will show the virus produced the most calls to its help desk during November, although these figures are skewed by the fact victims had no other means of asking for help.

The virus, which is also known as Apology-B, arrives as an email attachment with a variety of different names designed to entice careful users into opening it including NEW_NAPSTER_site.TXT.pif and the cunningly titled IS_LINUX_GOOD_ENOUGH!.TXT.pif. Opening the attachment triggers an infection.

The virus replaces wsock32.dll with a modified version which monitors network traffic. When the virus detects the user sending an email, it will send another to the same recipient. The message will have no subject or body text, only an attachment.

The virus also has the ability to open up a backdoor on a victim's machine. It places a file, called MTX_.exe, on a victim's hard disc drive which, once executed, tries to connect to a website and download further programs to run.

However the bug's most sinister feature is that a user will be prevented from accessing antivirus website from an infected machine or sending emails to specified security firms.

The bug has one very sinister feature: once it infects a user, it's programmed to stop the victim from visiting antivirus Web sites and sending "mayday" emails to antivirus companies.

Users can be infected by MTX only if they haven't updated their antivirus software for the last two months.

The growing prominence of MTX, and other viruses which have lain dormant for weeks before raising their ugly head, shows that people aren't applying this simply procedure. ®

The Essential Guide to IT Transformation

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
KDE releases ice-cream coloured Plasma 5 just in time for summer
Melty but refreshing - popular rival to Mint's Cinnamon's still a work in progress
NO MORE ALL CAPS and other pleasures of Visual Studio 14
Unpicking a packed preview that breaks down ASP.NET
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
Put down that Oracle database patch: It could cost $23,000 per CPU
On-by-default INMEMORY tech a boon for developers ... as long as they can afford it
Another day, another Firefox: Version 31 is upon us ALREADY
Web devs, Mozilla really wants you to like this one
Google shows off new Chrome OS look
Athena springs full-grown from Chromium project's head
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.