topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Revamped Melissa requires antivirus update

January 23, 2001, 04:58 PM —  Network World — 

Remember Melissa? It's been almost two years since that infamous worm swept through the world's e-mail servers, spreading faster than any virus ever had before. Now a new variant of Melissa threatens to get past the defenses designed to protect us from the original.

Reports of the new strain, Melissa.W, started appearing midweek, mainly in Europe. By Thursday afternoon the Symantec Corp. Antivirus Research Center had upgraded the variant's severity rating to Category 4 (Severe).

Not surprisingly, the major antivirus companies are rushing to get out their solutions. Most of the first fixes will likely be definitions specific to Melissa.W. Some products can identify the new strain of the virus without yet repairing it.

The definition will also be part of McAfee.com Corp.'s next weekly update, due to become available on January 24. Symantec expects to have a fix available on Friday.

Subject Lines to Watch For

In most ways, the new Melissa acts pretty much like the old one. The macro-based worm comes alive when you open an infected Word file, spreading to other documents and mailing itself as an attachment to the first 50 listings in your Microsoft Outlook address book. If one of the recipients opens the attachment, the cycle starts all over again.

How do you defend yourself against the new Melissa?

"The best defense is education," says Kevin Haley, group product manager for Norton AntiVirus. If you can recognize the virus, you can catch it.

If you receive an e-mail message with a subject line that begins with "Important message from," be afraid.

If the body of the e-mail message itself (and yes, you can safely open the message) tells you that "Here is that document you asked for ... don't show anyone else ;-)," be very afraid.

In fact, if you get such a message, delete it and notify the poor slob who accidentally sent it to you. And whatever you do, don't open the attached file.

Not everyone who gets the virus will spread it. If you don't open the document, you'll never get infected. And if you're not using Outlook, you won't mass-mail the virus to others, although you can still spread it by sharing Word files.

On the other hand, a lot of people use Outlook, especially in offices (Melissa can't mass-mail through the similarly-named Outlook Express program). If enough people open their attachments within a company that is standardized on Outlook, the mass of extra e-mail can overload the server.

Meeting the Mac

Melissa.W has actually been around almost as long as the original. Like all variants of Melissa, the virus is a Microsoft Word macro that spreads itself far and wide by e-mailing infected files through Microsoft Outlook. And also like all Melissa variants, antivirus programs were catching and neutralizing it with ease.

That is, until it met Microsoft Word 2001 for the Macintosh.

The version of Melissa.W currently making the rounds is a Word 2001 file, something the antivirus programs aren't ready to handle.

"The [antivirus software] engine has to understand the file format to detect a virus," says Vincent Gullotto, director of Network Associates' McAfee Antivirus Emergency Response Team.

So what transformed the virus?

"We don't know," admits Symantec's Haley.

Someone saved an infected file on a Mac-converting the file format and changing the nature of the virus-and then e-mailed it to a PC user.

"It could have been malicious, or it may have simply been someone sending a file," he says.

» posted by ITworld staff

Network World

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources