The Mudcat Café TM
Thread #99494   Message #1983130
Posted By: JohnInKansas
01-Mar-07 - 03:56 PM
Thread Name: Tech: New virus
Subject: RE: Tech: New virus
From Truth or Fiction

"This virus warning is true and the virus is real, according virus protection sites such as Mcafee, Symantec, and F-Secure. It was first reported in September, 2006 but a warning about the virus circulated heavily in February, 2007 as well.

"F-Secure names the virus Warezov. Other virus protection sites called it Stration.bb or W32/Stration-X.

"The email says that it has been determined that emails containing a worm are being sent from your computer and that you should install the attachment to update your computer and, presumably, stop the virus from being sent. The problem, of course, is that the attachment itself is a virus that searches your computer for email addresses and sends itself to them."


The virus itself is not anything new. The use of an email claiming that you must "click something" is not in itself a virus, but should be recognized as a "Phishing attack."

If anything, the appearance of new virus forms and new worms planted by viruses may have decreased in recent months, possibly down to one or two significant ones per month. The use of "phishing" (and/or "spear phishing"1) has dramatically increased recently.

Many AV and more general Anti-Malware programs have begun to incorporate various forms of "anti-phishing" controls, but the method seems almost invulnerable to any practical control, as it relies on the recipient being STUPID enough to click on the requested link.

As no one has yet invented an effective ANTI-STUPID device or program, any such phishing attack has a fairly good chance of producing the intended criminal result, even with a moderately invasive virus or worm.

1 "spear phishing" is the name some have applied to phishing email disguised to look like it comes from a high ranking executive in your own company. ("Hi there. This is Bill Gates, and I want to report that Microsoft servers have detected ..." from one reportedly received by several Microserfs.) Some people possibly extend the name usage to phishing email disguised to look like it's from a "government agency," but that's not widely accepted usage.

John