Skip to content

Biting the hand that feeds IT

The Register ®

Security:


Related Whitepapers

[Print][Mobile][Alerts]

Flea bugs Windows users

VBS malware on the loose

Published Friday 24th October 2003 09:11 GMT

A new virus called Flea is on the loose. The Visual Basic Script worm disguises itself as the ‘signature file’ in HTML-formatted mail.

Flea can execute automatically when users open HTML formatted emails in Microsoft Outlook or Outlook Express. Unlike most Windows nasties, the bug does not depend on a user opening an infectious file to do its mischief, Finnish AV vendor F-Secure warns.

When an infected HTML email is rendered a webpage is loaded. This page contains JavaScript which in turn loads another webpage containing the VB Script which drops a file (C***.HTM) in the Windows folder.

This file is also set to the signature of Outlook Express, furthering the spread of the worm. Flea changes Internet Explorer settings on infected machines as explained in F-Secure's advisory .

To hide itself and to make analysis more difficult, Flea uses several encryption layers.

F-Secure has received "multiple reports of this worm from Asia and Europe". Rival AV vendors give Flea a much lower risk rating.

AV vendor Sophos, for example, has so far received just one report of this worm in the wild.

Vendors have updated signature definition files to detect Flea, which once again highlights the security risks of using Microsoft email clients in default configurations. ®

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

The Perfect (Virtual) Marriage

Get consistent virtual machine storage savings of 50% (often as high as 90%) with virtually no performance impact with NetApp deduplication..
whitepaper title

Gartner Paper: US Data Centers

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
Whitepapers

Top 20 storiesAll The Week’s HeadlinesArchiveSearch