Trojan horse scanner pitch is a sneaky worm

Robert Vamosi

26 October 2001 05:40 PM

Tags: e-mail, worm, virus, trojan, scanner, trojan horse, anti-virus, worms

An e-mail message announcing a new Trojan horse scanner is itself an Internet worm that could flood servers with useless e-mail.

With more people all the time connected to the Internet, the danger of Trojan horses, malicious programs that communicate passwords and other private information to others on the Internet, is very real. Antset is a worm that arrives by e-mail and claims to be a Trojan horse scanner. It is not. At least three variations of Antset (W32.Anset.A@mm, W32.Anset.B@mm, and W32.Anset.C@mm) are floating around the Internet. Antset is capable only of sending multiple e-mail messages and does not damage PCs, so this worm ranks a 4 on the CNET Virus Meter.

How it works

Antset arrives as an e-mail solicitation for a Trojan horse scanner. The subject line reads "ANTS Version 3.0." The body text for the original worm is in German and reads:

"Hi, Anhängend die neue Version 3.0 von ANTS, dem bislang einzigartigen kostenlosen Trojanerscanner. Zum installieren einfach die angefügte Datei ausführen."

The English translation reads:

"Hi, attached you will find the brand new version 3.0 of ANTS, the unique freeware Trojan scanner. To install ANTS, simply run the attached setup file."
The body text concludes with the following salutation
"Adieu, Andreas webmaster@avnetwork.de http://www.ants-online.de."
The named Web site is legitimate but contains a disclaimer regarding this worm. Antset also contains an attachment named ants3set.exe.

If a user clicks the attached file, Antset searches the Microsoft Outlook address book for addresses to which to send copies of itself, then looks for more e-mail addresses within the following file types: PHP, HTM, SHTM, CGI, and PL.

Worms like Antset usually contain a Registry key that prevents the worm from installing itself more than once. Antset does not have this feature and could produce multiple Registry entries and numerous extra files in the Windows subdirectory. Antset also has a few programming bugs that affect its ability to spread and may not function on all Windows computers.

Removal

Most antivirus software companies have updated their signature files to include this worm. For more information on removing Antset from your system, see Kaspersky, McAfee, Sophos, Symantec, and Trend Micro.

Like this article? Click below to send it to your mobile for free!

Talkback 1 comments

  1. There won't be an end to these problems until the likes of Microsoft, ISP's and the authorities come down hard on the authors. None of them have shown any sign of taking much action. They do almost NOTHING which is really effective, even when you report t Keith Styles -- 26/10/01

    There won't be an end to these problems until the likes of Microsoft, ISP's and the authorities come down hard on the authors. None of them have shown any sign of taking much action. They do almost NOTHING which is really effective, even when you report the source to them.


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Will the NSW Govt put Linux in schools?
    The NSW Government's release this week of an expressions of interest tender to give low-cost laptops to every senior public school student in NSW is a big step, but will these systems be Windows or Linux?
  • Array Naked Mac versus protected PC: What wins?
    What's easier to manage — 200 Mac OS X systems without antivirus or 200 Windows systems running a leading antivirus package?
  • Array Dear Telstra: pack up your toys, go home
    Rejecting Telstra's proposal, after all, is the only conclusion Conroy can reach: as someone whose entire philosophy is built around transparency and process, he simply cannot keep Telstra as part of the NBN bidding process anymore.
  • More blogs »

Tags

Back to top

Featured