On TechRepublic: 10 Firefox add-ons you gotta have
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: May 12, 2004 6:44:00 PM

A new mass-mailing virus called Wallon, which wipes out Windows Media Player and is activated when a user tries to play MP3 or video files from an infected PC, was discovered in Europe on Tuesday.

Traditionally, mass-mailing viruses such as Netsky and Bagle are spread as attachments. When an unsuspecting user opens the infected attachment, it executes a piece of code that usually attempts to steal the user's address book and often opens a back door to give hackers easy access to the system's resources.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Maikel Albrecht, a product manager at Finnish security company F-Secure, said that because of recent virus outbreaks, users are less willing to open e-mail attachments, which is why Wallon's author is counting on users clicking on an e-mail link instead.

"The link in the e-mail points to the actual virus, so if you click the link, you download the virus," Albrecht said.

However, once the PC is infected, Wallon remains dormant until the user tries to run a media file such as an MP3 or a video. If the system uses Windows Media Player by default, the virus is activated and attempts to send HTML e-mails, each with a link to the virus file, to the addresses in the computer's e-mail address book.

"If you try and play media content, the worm will activate and start spreading, but the user will not see the media player," Albrecht said.

Wallon requires intervention by the user before it can replicate, so Albrecht expects it will not spread very quickly. But unlike common viruses, Wallon is destructive because it replaces the wmplayer.exe file, which means that users infected by the worm will need to reinstall Media Player.

Stuart Okin, the chief security officer at Microsoft UK, said anyone worried about Wallon should install Microsoft's MS04-13 patch, which was released in mid-April and solves the problem.

Okin said that if a PC has been infected and Media Player can no longer be run, the user should first ensure the system is no longer infected by the virus and then reinstall Media Player either from the original Windows CD or by downloading it from the Microsoft Web site.

Additionally, Okin said users should remain cautious about opening e-mail attachments and they should avoid clicking on links in e-mail messages whenever they can.

"When you receive a link to a Web site that you normally visit, don't click on the link, use your 'Favorites' or type in the address in manually," he said.

Munir Kotadia of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 47 Talkback(s)
But I'm not in email when it hits
Twice this week Wallon has gotten into my system, even though I hadn't been in email at the time, and have multiple firewalls in place. In both cases it has occurred during an on-line session, at dif... (Read the rest)
Posted by: fbt01 Posted on: 05/23/04 You are currently: Logged In as: a Guest  | Login | Terms of Use
Is there anything  michael-t | 05/12/04
(nt) not bugs - 'features'  toadlife | 05/12/04
(NT) . . . WAD . . . Working as Designed  Bit's_Conscience | 05/12/04
Interesting  Letophoro | 05/12/04
You mean  michael-t | 05/12/04
Not quite  PB_z | 05/12/04
Um...Hello?  TechDiva_z | 05/13/04
Ha Ha!  cuervo-gold | 05/12/04
That one got our entire IT department laughing  Arrg | 05/12/04
We have a winner  Rick_K | 05/12/04
Windows Unplugged  Chad_z | 05/12/04
now you don't need the 3rd party hack,  ryusen | 05/12/04
Did anybody else notice this?  Linux User 147560 | 05/12/04
i might have been assuming, but  ryusen | 05/12/04
cant be I patched that one twice  Hanover Phist | 05/13/04
Also, www.microsoft.looks-like.com ... (NT)  Robert Carnegie | 05/14/04
(NT) No loss... Don't use it.  Bit's_Conscience | 05/12/04
Exactly..no need for forced DRM crapware  Jeff Spicoli | 05/12/04
90%  V Sanders | 05/15/04
This is the type of bullcrap  ParadigmOdyssey | 05/12/04
(NT)Wanna bet the EU released this hack after MS gave 'em the finger? happy  Spin_Masterz | 05/12/04
Or else...  eskayp | 05/14/04
"A_ mass_ mailing_virus" fsked up WMP?!?! WTF?!?  dicktaurus@... | 05/12/04
Of course not!  Sniper_z | 05/13/04
Look everyone! Mike changed his screen alias!  TechDiva_z | 05/13/04
Where's bitty and company?  Spam-ZD | 05/12/04
Wow, this one brought out the player haters  FilledOut | 05/13/04
in all fairness...  ryusen | 05/13/04
in all fairness ...  Ardian Daka | 05/13/04
SOSDD  ShadeTree | 05/13/04
Another sad attempt to deflect critical attention  jellyclock | 05/13/04
Thank you  ShadeTree | 05/13/04
gee thanks  jellyclock | 05/13/04
Near as I can tell....  ShadeTree | 05/13/04
actually  ryusen | 05/13/04
Point taken...  ShadeTree | 05/13/04
i think you are wrong...  ryusen | 05/13/04
Who's Bitty?  voska | 05/13/04
No_AXE_to_Grind = Bit_byte = ....  MacCanuck | 05/13/04
Thanks!  ShadeTree | 05/13/04
Thank goodness  jdahs@... | 05/13/04
And SSDD to you, as well  TechDiva_z | 05/13/04
Pot calling kettle black  ShadeTree | 05/14/04
The only problem with this virus  TWRX | 05/13/04
Ummm nope not Quicktime  Squawkbox | 05/13/04
LOL  V Sanders | 05/15/04
But I'm not in email when it hits  fbt01 | 05/23/04

What do you think?

CIO Sessions

advertisement
Click Here