New worm aims to infest Australian systems

By Patrick Gray
01 November 2002 04:00 PM
Tags: security, worm, software, antivirus, patrick gray, peer, merkur, p2p
An Internet worm, posing as an anti-virus update arriving in an email, is also using peer to peer (P2P) software to spread.

The Merkur worm, aka W32.HLLW.Merkur@mm arrives in email form with the subject "Update your Anti-virus Software" and has an attachment named "Taskman.exe".

The worm relies solely on the recipient being fooled into running the attachment to spread.

Like similar worms that have used "social engineering" to lure in unsuspecting victims, the Merkur worm sends itself to everyone in the victims' address book when it is opened.

The also worm deletes any multimedia files located in p2p file sharing directories. It targets share directories used by KaZaA, Bearshare and eDonkey software.

The "process" the worm uses to delete these files is named "Pr0n.bat". Pr0n is common hacker slang for "porn".

The Merkur worm then copies itself into the p2p share directories under many different names. One of the names is "Virtual Sex Simulator.exe", chosen to appear more appealing to other users on file sharing networks.

If this file is downloaded over the p2p network and then run the infection process starts on the new victim's computer.

It will also affect users of the chat program mIRC. The worm creates a script that attempts to send itself to other users in the same chat channel under the name "screensaver.exe".

Concerned users should update their antivirus definitions.

Advertisement

Talkback 7 comments

    Is this the beginning of the M ...a chavez -- 02/11/02

    Is this the beginning of the MPAA's global war against P2P FSNs, or just supposed to look like it?

    Thanks for the tip. The Merku ...brian gardner -- 02/11/02

    Thanks for the tip. The Merkur worm sounds like a real charmer

    Thanks for the tip. The Merku ...brian gardner -- 02/11/02

    Thanks for the tip. The Merkur worm sounds like a real charmer

    I think it is about time that ...Anonymous -- 04/11/02

    I think it is about time that ISP's took some responsibility for stopping email virus's when they arrive on their servers. If you take a look at the Malaysian site www.jaring.my you will see that they provide a service for MYR$20 per annum to get check for virus's on their email servers (and they are supposed to be a 3rd world country). We receive email from Malaysia and it has the following message appended!
    -------------------------------------------------
    Scanned by JARING E-Mail Virus Scanner (http://www.jaring.my)
    -------------------------------------------------
    The big advantage is that professional IT people can be employed to focus on checking emails before the user downloads them. It is also great for novice internet users as they probably find it difficult to cope with installing and keeping virus checkers up to date.
    So maybe some pressure should be put on ISP's to do something about it,. Surely if a Malaysian ISP can do it Australian ISP's can! It is also in their interest's as I am quite sure that the negative press about the perils of being on the internet and having to cope with virus's etc turns a lot of people off using the net. I would be interested in your response.

    Looks like an attempt to wipe ...Anonymous -- 04/11/02

    Looks like an attempt to wipe out p2p illegal images and video if you read the norton AV sevtion about it as it is ment to only delete .mp3 .jpg and mpg think they are a few other files there as well but i cant remember. so surly it cant be all that bad if thats the only damage it does?

    If this worm is a creation of ...Anonymous -- 09/11/02

    If this worm is a creation of the MPAA/RIAA forces (as seems quite possible if not probable) how long before they get their claws into the antivirus services (as would be used by ISPs) to have detection delayed until there is noticeable public outcry?
    Already there is the nagging question of how many bugs come from the "defenders" to bolster their value (can we believe there are so many programmers clever enough to release a successful delivery system but too dumb to spell the name of the bomb right?)

    And Klez is spreading through ...Anonymous -- 11/11/02

    And Klez is spreading through zdnetonebox.com. How about updating your Anti-virus software?

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured