Feeds

Worm turns Japanese

Fbound impounded

  • alert
  • submit to reddit

Security for virtualized datacentres

A worm which tries to disguise itself as a security patch is hitting Asia particularly hard.

Fbound normally arrives as an email with the subject line 'Important' and has an attached file called 'Patch.exe'. Once activated, the worm forwards itself to everyone in the victim's email address book using its own SMTP routines.

When sending itself to an email address ending in .jp, the worm uses one of sixteen different subject lines - written in Japanese characters, in a deliberate attempt to fox Asian as well as English speaking users. The worm doesn't harbour a particularly dangerous payload, though it could affect the speed of Internet connections.

MessageLabs, a managed services firm which scans its users' email for viruses, reports blocking 4,943 copies of the worm since it first appeared yesterday. It's become the most common piece of malware on the Internet though its spread is far short of that of other recent outbreaks, such as the Goner or the infamous Anna Kournikova worm.

Fbound's main trick of pretending to be a security patch is a well known virus writer ploy, most recently seen in the Gibe worm, which poses as a patch for a MIME header vulnerability in Internet Explorer. Half a dozen of you have contacted us about this virus over the last week, so it's obviously doing the rounds.

Credit Microsoft with enough sense never to send out its security patches by email. Messages along these lines should simply be deleted.

Antivirus vendors have updated their software to detect both Gibe and Fbound, both of which only affect Windows machines, so now might be a good time to update your protection. ®

Related Stories

Stupid worm spreads like wildfire
Israeli kids fess up to stupid worm attack
Britney Spears virus fails to chartl
German worm makes PCs kaputt
All quiet on the malware front
CA cans updates for free personal AV package
Users haven't learned any lessons from the Love Bug
Rise in viruses within emails outpacing growth of email
Hybrid viruses set to become bigger threat

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.