[an error occurred while processing this directive]
CurzTech News Network
CurzTech News Network | CurzTech World News | CurzTech U.S. News | CurzTech Entertainment News | CurzTech Political News | CurzTech Conspiracy News | Yesterday's News | Offsite Archive
Panda Software's Virus Laboratory has detected the appearance of Densux (W32/Densux) a new e-mail worm. This new malicious code spreads via e-mail, sending itself out to all addresses in Outlook's Address Book.
Densux exploits a know vulnerability in Microsoft Internet Explorer to run automatically simply when the infected message is viewed in the Preview Pane. Panda Software's antivirus solutions detect this vulnerability, known as -Exploit/Iframe <http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=36556>- preventing the worm from running, even if the Microsoft patch, which fixes the flaw has not been installed.
When Densux runs, it creates a file called Scandisk.exe in the Windows directory, along with another executable with a name generated at random. The worm also makes an entry in the Windows Registry to ensure it is run on every system start-up..
Densux also has traditional virus characteristics, as it infects and copies part of its code to PE files.
Panda Software's Tech Support services have received a number of reported incidents involving Densux, and the company therefore advises users to update their antivirus solutions. Panda Software users can now download this update, which ensures their antivirus detects and eliminates this malicious code, from the company's website at <http://www.pandasoftware.com>.
Detailed technical information on Densux <http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=39156><http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=38875>is available from Panda Software's Virus Encyclopedia.
About Panda Software's virus laboratory
On receiving a possibly infected file, Panda Software's technical staff start work immediately. The file is analyzed and depending on the type, the action taken may include: disassembly, macro scanning, code analysis etc. If the file does in fact contain a new virus, the disinfection and detection routines are prepared and quickly distributed to users.
Copyright IDG Communications Ltd, 2003
[an error occurred while processing this directive]