November 30, 2006

Existing malware could affect Vista users

Sophos identifies three viruses that can infect Vista customers who use a third party Web e-mail client

Microsoft has touted Vista as a more secure version of Windows, but on the day of Vista's official launch, a security company has identified malware already in circulation that can infect computers running the OS.

Sophos identified three viruses typically spread through e-mail that can infect Vista customers who use a third party Web e-mail client. While Vista's e-mail client stops Stratio-Zip, Netsky-D, and MyDoom-O, the malware slips past Vista's defenses when users receive infected messages through a Web-based e-mail service, Sophos said.

Stratio-Zip topped Sophos' list of malware affecting computer users in the month of November, accounting for 33.3 percent of malware in circulation. Combined, the three viruses that can affect Vista users make up 39.7 percent of all malware in circulation during the month, Sophos said.

However, even if the malware Sophos identified slips through in an e-mail, customers won't necessarily be affected, another researcher said.

Additional Vista security mechanisms should protect users, said Mikko Hyppönen, chief research officer at F-Secure. If a customer opens an infected malware file, Vista would warn and question the user before allowing the malware to wreak havoc. "These particular examples of malware probably wouldn't still be able to successfully infect the machine unless the user specifically allows it," he wrote in an e-mail exchange.

Sophos applauded the security improvements in Vista, saying that the variety of popular third party applications used by consumers inevitably will open doors to hackers.

Other anti-virus companies haven't been so kind. McAfee has been highly critical of changes in the operating system that it says will make Vista less secure than previous versions of Windows. Symantec said it has discovered vulnerabilities in Vista's networking software which makes it less stable than Windows XP.

Sophos found that overall, the proportion of infected e-mail remained low in November at 0.28 percent, but identified a record number of new threats, 7,612, during the month.

Close

On Twitter now

Application development

Powered by Twitter

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Developer World Newsletter

Receive a weekly roundup about the art and science of software development.

©1994-2009 Infoworld, Inc.