Feeds

First JPEG virus not a threat

Low risk, in captivity

  • alert
  • submit to reddit

High performance access to file storage

ComputerWire: IT Industry Intelligence

Anti-virus firms have discovered a Windows virus that infects JPEG image files, though the chances of it causing a major security risk any time soon are close to zero. W32/Perrun, as Networks Associates Inc named the virus, was assessed as low risk, and has not been found in the wild.

"It is believed to be the first of its kind," said Vincent Gullotto. "It's no danger, but it shows that virus writers are looking at other methods of infection." In the last year, virus writers have started using other file types, such as PDFs and Flash animations, to spread themselves.

Perrun arrives as an executable file. When run, it drops a further "infector" executable onto the machine and adds it to the Windows registry, Gullotto said. Whenever a JPEG file, or a file with a .jpg extension is opened, the infector appends the virus to the end of the file before the image is displayed via the user's preferred image viewer.

Sending infected JPEGs to other, uninfected computers will have no effect, NAI confirmed. Image files do not have the ability to execute malicious code, so simply viewing a JPEG, without the infector running on the same machine, will not have any effect, other than slowing it down while any installed anti-virus software scans it.

"Not only is this virus not in the wild, but also graphic files infected by this virus are completely and utterly harmless, unless they can find an already infected machine to assist them," said Chris Wraight of Sophos Plc. "It's like a cold only being capable of making people who already have runny noses feel ill."

Based on NAI's assessment of the code, the firm believes the Perrun author is also the writer of the W32/Alcop virus, a mass mailer Outlook worm that poses as a pornographic Flash animation of adult actress Aria Giovanni. Alcop was discovered in January, and is also classified as low-risk.

The emergence of the virus also highlighted again the occasional cattiness of the anti-virus industry. NAI's McAfee Security division was the first major vendor to come out with an alert yesterday, but a few hours later, Sophos's US division released a missive urging "vendor restraint."

"Some anti-virus vendors may be tempted to predict the end of the world as we know it, or warn of an impending era when all graphic files should be treated with suspicion. Such experts should be ashamed of themselves," said Wraight at Sophos. A spokesperson added that Sophos was not singling out any of its competitors.

© ComputerWire.

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.