Virulent strain of Virut virus apears in the wild

Microsoft warned Wednesday that a particularly nasty variant of the Virut virus has been unleashed, and businesses should ensure their anti-virus products are updated to deal with the new threat.

The malware infects portable executable files, such as .exe and .scr, and is therefore able to spread from machine to machine, according to Microsoft. Each time it propagates, Virut uses polymorphism — or mutated code — to evade detection.

Once on a machine, the virus opens a backdoor, connecting with an internet relay chat (IRC) server, which allows a remote attacker to download additional malware onto the computer, Jimmy Kuo, principal architect for the Malware Protection Center, told SCMagazineUS.com on Wednesday.

Typically, with past variants of Virut, users did not know when they were infected.

“However, the additional complexity of this particular variant will likely cause instability in affected systems,” Kuo said.

The virus — originally believed to be the ubiquitous Conficker worm — was responsible for shutting down the court system in Houston this week. About 475 of the city’s 16,000 computers were affected by the virus, which first appeared last Wednesday and was identified Sunday, Frank Michel, a mayor’s spokesman, told SCMagazineUS.com.

“It was a new variant, so the protection companies hadn’t created their patches yet,” Michel said.

So far this week, the city has suspended court hearings but hopes to resume them on Thursday, he said.

“All of those 475 [infected machines] were isolated and are now being scrubbed,” Michel said. “In some cases, they’re rebuilding servers.”

Updated anti-virus may not always be enough to rectify the virus. According to Microsoft, Virut can destroy certain files beyond repair, meaning companies may be required to install a clean version of the operating system to return a machine to a safe state.

The virus also affected computers in Springfield City, Mo., forcing the city to shut down its website earlier this week, according to reports.


Sursa
2009-02-13 16:34:30



Comenteaza





Ultimele 25 posturi adăugate

17:53:18POEMUL APUSULUI —» Andrei LANGA. Blogul personal
05:59:16JURNALUL DE LA HYPERION (VI) —» Leo Butnaru
19:06:0019 mai 2024 – fatalitate și destin —» codul omega
16:02:38AVIZUHA —» Andrei LANGA. Blogul personal
07:14:16De azi am stație de autobuz în fața blocului —» Andrei Albu - omul alb cu gînduri negre
12:36:19O nouă ediție a Concursului literar „La izvoarele înțelepciunii” s-a desfășurat la biblioteca din Ungheni —» BPR Ungheni's Blog
07:34:02Trei noutăți de la Crama Mircești —» Fine Wine
06:03:20ÎN PREAJMA UNEI CĂRȚI NOI —» Leo Butnaru
09:44:08Rusia în anii 90…pregătindu-l pe Putin…(reflecții pe marginea unui film). —» blog cultural
05:15:16DIN POEZIA FRANCEZĂ CONTEMPORANĂ —» Leo Butnaru
05:11:09JURNALUL DE LA HYPERION —» Leo Butnaru
06:34:16O MARE POETĂ DIN FINLANDA —» Leo Butnaru
16:08:35PORȚI / PUERTAS —» Andrei LANGA. Blogul personal
04:19:45Atenție la semne! 9 mai ne-a dezvăluit cam cum va arăta „concursul” de ocupare a funcției de președinte al RM —» Nicolae Federiuc
19:13:15Hyde Park împlinește 21 de ani —» Curaj.TV | Media alternativă
18:47:41UN ALTFEL DE RĂZBOI —» Andrei LANGA. Blogul personal
22:49:14Nemo —» APort | "Pentru un român care știe citi, cel mai greu lucru e să nu scrie." I.L. Carag
19:53:38Drapele vandalizate pe clădirea unui minister —» Curaj.TV | Media alternativă
19:46:01Comemorare Mihai Creangă la Memorialul Sighet —» Curaj.TV | Media alternativă
17:40:39FLASH (trad. al español) —» Andrei LANGA. Blogul personal
12:46:32UN ALTFEL DE RĂZBOI —» Andrei LANGA. Blogul personal
11:18:14Cântărețul Ștefan Petrache ar fi împlinit 75 ani —» CHIŞINĂU MUZICAL | Blogul Bibliotecii de Arte "Tudor Arghezi"
08:09:45#NoSugarPolitics: Mobilizarea si drepturile omului, rezolutia PE, investigatie Italia —» Curaj.TV | Media alternativă
01:16:40from the director of the boondock saints —» turn up the silence
13:23:16RETRATOS VOLADORES* (Portrete plutitoare, trad. al castellano) —» Andrei LANGA. Blogul personal