Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
iPhone 5 rumor rollup for the week ending Feb. 10
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Much of Western U.S. is a 3G wasteland, says FCC
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
/

New worm disables Microsoft mail systems

Today's breaking news
Send to a friendFeedback


Network administrators who struggled to clean up the mess left by Melissa now face another worm that can quickly clog their mail servers with large amounts of bogus e-mail - and delete user files.

The new worm, dubbed Worm.ExploreZip or TROJ_EXPLOREZIP, apparently only affects Windows machines running MAPI e-mail clients, such as Microsoft Outlook and combines the worst attributes of Melissa and the Happy99.exe file.

It spreads when unsuspecting users open a message, apparently from a correspondent they already know, and then click on an attachment. The message says "I received your e-mail and I shall send you a reply ASAP. Till then, take a look at the attached zipped docs."

Launching the attachment sets up a monitoring application that responds to all incoming mail with this note and attachment. But unlike Melissa, which only existed to replicate, this worm copies itself to the user's system directory as explore.exe - so that it runs on every reboot - and scans the hard drive, rendering useless Microsoft Word, Excel and PowerPoint files, as well as C programs.

According to Trend Micro, it only affects users with a personal folder in their desktop mail clients; it does not run off shared Exchange servers.

One East Coast company effectively lost its network for more than 24 hours this week after administrators discovered the worm on their NT mail servers. Administrators not only shut down the mail servers but began a desktop-by-desktop search for the worm, according to one worker lucky enough to be able to shift his work to his home office - and his non-Microsoft mail client.

One consulting firm that relies heavily on e-mail to communicate with clients had to send out this note on Thursday: "About an hour ago, I opened an attachment contaminated with that virus and may have inadvertently sent it to you. The virus caused my e-mail system to automatically send messages."

RELATED LINKS

Contact Online Editor Adam Gaffin

I-Worm.ZipExplore alert
Description of the worm from Panda Software.

TROJ_EXPLOREZIP
Overview from Trend Micro.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.