Feeds

First JPEG virus not a threat

Low risk, in captivity

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

ComputerWire: IT Industry Intelligence

Anti-virus firms have discovered a Windows virus that infects JPEG image files, though the chances of it causing a major security risk any time soon are close to zero. W32/Perrun, as Networks Associates Inc named the virus, was assessed as low risk, and has not been found in the wild.

"It is believed to be the first of its kind," said Vincent Gullotto. "It's no danger, but it shows that virus writers are looking at other methods of infection." In the last year, virus writers have started using other file types, such as PDFs and Flash animations, to spread themselves.

Perrun arrives as an executable file. When run, it drops a further "infector" executable onto the machine and adds it to the Windows registry, Gullotto said. Whenever a JPEG file, or a file with a .jpg extension is opened, the infector appends the virus to the end of the file before the image is displayed via the user's preferred image viewer.

Sending infected JPEGs to other, uninfected computers will have no effect, NAI confirmed. Image files do not have the ability to execute malicious code, so simply viewing a JPEG, without the infector running on the same machine, will not have any effect, other than slowing it down while any installed anti-virus software scans it.

"Not only is this virus not in the wild, but also graphic files infected by this virus are completely and utterly harmless, unless they can find an already infected machine to assist them," said Chris Wraight of Sophos Plc. "It's like a cold only being capable of making people who already have runny noses feel ill."

Based on NAI's assessment of the code, the firm believes the Perrun author is also the writer of the W32/Alcop virus, a mass mailer Outlook worm that poses as a pornographic Flash animation of adult actress Aria Giovanni. Alcop was discovered in January, and is also classified as low-risk.

The emergence of the virus also highlighted again the occasional cattiness of the anti-virus industry. NAI's McAfee Security division was the first major vendor to come out with an alert yesterday, but a few hours later, Sophos's US division released a missive urging "vendor restraint."

"Some anti-virus vendors may be tempted to predict the end of the world as we know it, or warn of an impending era when all graphic files should be treated with suspicion. Such experts should be ashamed of themselves," said Wraight at Sophos. A spokesperson added that Sophos was not singling out any of its competitors.

© ComputerWire.

Internet Security Threat Report 2014

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
Carders punch holes through Staples
Investigation launched into East Coast stores
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.