iTnews
  • Home
  • News
  • Technology
  • Security

Zhelatin mutants storm virus charts

By Robert Jaques
Feb 14 2007 9:04AM
Follow google news

Raft of new variants detected.

Zhelatin mutants storm virus charts
The Zhelatin virus is challenging Bagle and Warezov for the dubious honour of number one virus after eight new variants were detected in the past four days, security experts have warned.

Kaspersky Lab said that Zhelatin.s, .t and .u were detected on 8 February, while Zhelatin.v was detected on 9 February. Four more variants, .w to .z, were detected during the weekend of 10-11 February.

The most significant of these is Zhelatin.u, which Kaspersky Lab currently rates as a 'moderate' risk.

Zhelatin first appeared on 19 January and 26 variants have so far been detected by Kaspersky since 22 January.

Zhelatin.u spreads via email as an infected attachment. The subject line, message body and attachment are variable.

The worm itself is a Portable Executable, between 5KB and 54KB in size, packed with UPX. The worm copies itself to the hard disk and modifies the registry to load automatically on start-up.

The worm terminates a range of antivirus and firewall applications and adds a rule to the system firewall to prevent its own activity from being blocked.

It also launches an SMTP proxy server on TCP port 25, allowing a remote hacker to use the infected machine as part of a spam botnet.

Zhelatin.u registers itself on the remote site, sending the network address of the victim machine before downloading a file containing the botnet configuration. This file is used to get data from the victim machine and to send spam.

The worm uses a rootkit to hide its own processes, files and registry changes. Kaspersky detects this component as 'Email-Worm.Win32.Banwarum.f'.

David Emm, senior technology consultant at Kaspersky Lab, said: "Zhelatin.u is just a re-packed version of an earlier Zhelatin variant. It is broadly similar in behaviour to several earlier variants, although there are significant differences.

"The Proactive Defense Module in KAV 6.0 and KIS 6.0 is able to block this new threat without the need for new signatures. Nevertheless, we recommend that users update their antivirus databases as soon as possible."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
chartssecuritystormvirus

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.