Worm
Worm

'Microsoft' worm has 13-day timebomb

Palyh virus spreading quickly in the wild

Written by Iain Thomson

A new worm which pretends to have been sent by Microsoft technical support has started to appear in the wild.

Palyh (pronounced Pale-H) is a basic worm which copies itself to the Windows system memory as MSCCN32.EXE, and spreads by mailing itself out to a host's contacts and via corporate networks.

Advertisement

The worm has the ability automatically to update itself from a remote web server, and install spyware on infected PCs. But it is also time locked to become inactive after 31 May.

"We've had a lot of reports worldwide," said Graham Cluley, virus consultant at Sophos.

"It showed up around midnight and seemed to hit Australia and New Zealand hardest due to the time of release.

"There's a danger to home users who might not be blocking attachments, and for companies which only scan emails and don't monitor network shares."

The worm scans for TXT, EML, HTML, HTM, DBX, WAB files and emails itself to any address it finds, although it also tries to send out a small number of garbled emails due to its poor construction.

All emails purport to come from support@microsoft.com and contain an EXE file that looks like a PIF or PI file.

"There's an awful lot of it about in the UK this morning," said Jack Clark, of Network Associates.

"That being said it looks like a similar low-level threat to last week's Fizzer worm. We've got our DAT files out already and it shouldn't be a problem for anyone with a sensible policy on virus updates."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Windows 7 screenshot

Microsoft defends choice of 'Windows 7'

But still does not satisfy Windows followers   More...

Apple MacBook

Apple rolls out new MacBooks

New case design and lower prices   More...

Novell UK office

Novell snaps up Managed Objects

Acquisition adds performance monitoring to Novell datacentre range   More...

Storage Expo

Better storage management key to success

Resource optimisation can offer a range of benefits, claims HP   More...

Primary Navigation