"Early propagation reports indicate that this virus is spreading faster than many of the biggest viruses we saw last year," said Mykko Hypponen, manager, Anti-Virus Research, F-Secure. "It seems to be spreading almost as fast as LoveLetter."
LoveLetter infected an estimated 15 million computers last year.
Onthefly is spread through an e-mail with the subject "Here you have,;o)". Execution of its VBScript attachment, AnnKournikova.jpg.vbs, causes the worm to create a key -- HKEY_CURRENT_USERSoftwareOnTheFly = "Worm made with Vbswg 1.50b" -- in the infected computer's registry. It then copies itself to the Windows directory as "AnnaKournikova.jpg.vbs" and then e-mails itself to all addresses in a recipient's Outlook address book. It also adds a marker to the registry which prevents the mass mailing from occurring more than once. The worm uses encryption to prevent recipients from seeing the attachment's .vbs extension.
Also, for some as-yet-unknown reason, the virus sets the computer to launch a browser aimed at a Dutch Web site on Jan. 26 of every year.
As was the case with LoveLetter, due to the large number of e-mails generated by the worm, it can overload and crash e-mail servers.
Computer Associates International Inc. (CA) have rated the worm, which it calls SST, a medium risk.
"E-mail-based threats continue to spread at alarming rates as illustrated by the number of reports CA's antivirus research centers have received on SST in a short period," said Ian Hameroff, business manager, antivirus solutions, CA. "A comprehensive security policy with the inclusion of gateway-based protection will provide the means to protect organizations from the propagation of these threats."
Still, it is important to note that outbreaks like Onthefly and LoveLetter utilize the very same Outlook features that Melissa used when it rampaged across the Net. Microsoft has created a patch for Outlook to prevent worms and viruses of this sort. The patch is available here.
LATEST NEWS
Foes Unite: Google, Telcos Team on Broadband Push
Oracle Helps Linux Get Enhanced Data Integrity
IBM Pitches Tool for Tighter App Dev
Tech Firms Still Ready to Deal
Does Facebook Connect Go Far Enough?



Digg
Del.icio.us
furl
StumbleUpon
Facebook
Tailrank
Technorati
Google Bookmarks
Yahoo Favorites
Windows Live
Ask
More stories by this author
