*EARLY EDITION* Computer Security Weekly, June 14, 1999


© Robert Slade

The past few days have seen reports of a "virus" which is generally being referred to as "Explore." Explore is real, and is quite dangerous. Hopefully the recent Melissa scare will have made people more aware and alert. It is not yet known how widespread the virus is.

Explore uses a reproductive strategy similar to Melissa: trust for people with whom one regularly corresponds. The easiest way to describe the worm is to outline the similarities and differences with Melissa.

Melissa used Microsoft Outlook to spread itself, but was a Microsoft Word macro virus, and used the functions of Word for both infection and payload. Explore is not a virus, in that it does not infect another object. It is technically more like the Internet Worm of 1988 in that it sends itself as a single object. Explore uses Outlook to spread itself. Whereas Melissa read the address book, Explore parses the Outlook Inbox, and "replies" to all messages. Part of what this means is that Explore messages appear to be replies to messages that you have sent.

Like Melissa, Explore arrives as an attachment. Again, we reiterate: DO NOT RUN ANY ATTACHMENTS IF YOU DO NOT KNOW WHAT THEY ARE!

Explore is a regular executable program, and does not require Word for any functions. Unlike Melissa it will install itself on the computer in such a manner that it starts at boot time, and will continue to run in the background, replying to all new mail. As an executable file, Explore will not run on Macs or other non-Wintel machines.

The subject of "infected" messages will appear to be a reply to a prior message. The test of "infected" messages reads:

================================================== Hi [Receipient Name]!

I received your email and I shall send you a reply ASAP.

Till then, take a look at the attached zipped docs.

bye (or sincerely [Receipient Name]) ==================================================

If the executable file is run, it may generate a false alert message stating that the file is corrupted. This appears to be an attempt to persuade people that the program has not actually run.

The major point about Explore, however, is that is carries a damaging payload. It truncates to zero length (empties the contents of) files with extension .c (C language source code), .h (C "header" libraries), .asm (assembler source), ..doc (Word document), .xls (Excel), and .ppt (PowerPoint). Thus, the payload targets software developers using the C language, and office work by people using Microsoft's Office suite. Loss of these files can be much more damaging than loss of system or program files.

Go To Page: 1 2


The copyright of the article *EARLY EDITION* Computer Security Weekly, June 14, 1999 in Computer Security is owned by . Permission to republish *EARLY EDITION* Computer Security Weekly, June 14, 1999 in print or online must be granted by the author in writing.

Post this Article to facebook Add this Article to del.icio.us! Digg this Article furl this Article Add this Article to Reddit Add this Article to Technorati Add this Article to Newsvine Add this Article to Windows Live Add this Article to Yahoo Add this Article to StumbleUpon Add this Article to BlinkLists Add this Article to Spurl Add this Article to Google Add this Article to Ask Add this Article to Squidoo