Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Author apologizes but fails to fix Panda worm

The worm's author claims to have written a fix, but Symantec says it doesn't undo file and registry changes made by the worm and is ineffective against variants


The accused mastermind behind the Panda Burning Incense worm has not done a very good job of making amends, according to security vendor Symantec.

Li Jun, a 25 year-old man from Wuhan, in central China, was arrested last month for allegedly selling copies of Panda. He is the first man to be arrested in China for virus-writing, according to China's Xinhua state news agency.

In an effort to make an example of Li, state police said they made Li write software that would remove the worm, but after analyzing the software, Symantec says this program fails to undo many of the file and registry changes made by Panda. Worse, it is completely ineffective against some variants of the malware.

"This removal tool is not effective against most of the samples we have tested against and isn't fully effective against any of them," wrote Symantec researcher Hon Lau, in a Wednesday blog posting. "For Li, perhaps he may have learned the hard way that ... it is much easier to write a program to cause destruction than it is to repair the damage."

Panda, which is also known as Fujacks and Radoppan.T, was written in October 2006 and has since spread widely within China. According to Xinhua, Li made 100,000 renminbi ($12,876) by selling copies of the worm to criminals, who then distributed it. Li was one of eight men arrested in connection with the affair.

Li's uninstaller tool comes with an apology from the worm-writer himself, claiming that the program was written for research purposes, Symantec's Hon said. "He ends with a warning to beware of future threats (from others) and to take the necessary precautions," he wrote.

 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





REMOTE ACCESS: MAINTAIN SECURITY AND DECREASE THE BURDEN ON IT
Join this interactive webcast to discover how IT Managers can control access rights, end-user security settings and end-point authorization. Sponsor: Citrix(R) GoToMyPC(R) Corporate

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 10/10/2008

A look back at the week: AMD splits into two, Panasonic sets world record...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist