Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
AT&T builds $23M IPv6 network for U.S. military
Nearly 1 million jobs could be created by IT stimulus package, think tank says
Mumbai gunmen used U.S. VoIP service to talk to their superiors during their spree
Rogue SSL certificate exploit puts VeriSign on the spot
Kerio unveils Mac client for its VPN
Apple lacks broad corporate strategy but still sees gains
Sun buys cloud-computing vendor Q-layer
Data breaches rose sharply in 2008, says study
Cisco: Huge international interest in developer contest
Group's plan for Inauguration Day: Telework
'Leap second' snafu affects Oracle clusterware
Microsoft makes Muglia server/tools president
Microsoft layoff rumors continue their swirl
Network failure spurs IT overhaul at law school
Security /

New worm disables Microsoft mail systems

Today's breaking news
Send to a friendFeedback

Advertisement:


Network administrators who struggled to clean up the mess left by Melissa now face another worm that can quickly clog their mail servers with large amounts of bogus e-mail - and delete user files.

The new worm, dubbed Worm.ExploreZip or TROJ_EXPLOREZIP, apparently only affects Windows machines running MAPI e-mail clients, such as Microsoft Outlook and combines the worst attributes of Melissa and the Happy99.exe file.

It spreads when unsuspecting users open a message, apparently from a correspondent they already know, and then click on an attachment. The message says "I received your e-mail and I shall send you a reply ASAP. Till then, take a look at the attached zipped docs."

Launching the attachment sets up a monitoring application that responds to all incoming mail with this note and attachment. But unlike Melissa, which only existed to replicate, this worm copies itself to the user's system directory as explore.exe - so that it runs on every reboot - and scans the hard drive, rendering useless Microsoft Word, Excel and PowerPoint files, as well as C programs.

According to Trend Micro, it only affects users with a personal folder in their desktop mail clients; it does not run off shared Exchange servers.

One East Coast company effectively lost its network for more than 24 hours this week after administrators discovered the worm on their NT mail servers. Administrators not only shut down the mail servers but began a desktop-by-desktop search for the worm, according to one worker lucky enough to be able to shift his work to his home office - and his non-Microsoft mail client.

One consulting firm that relies heavily on e-mail to communicate with clients had to send out this note on Thursday: "About an hour ago, I opened an attachment contaminated with that virus and may have inadvertently sent it to you. The virus caused my e-mail system to automatically send messages."

RELATED LINKS

Contact Online Editor Adam Gaffin

I-Worm.ZipExplore alert
Description of the worm from Panda Software.

TROJ_EXPLOREZIP
Overview from Trend Micro.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.