November 14, 2003 12:05 PM PST

New virus disguised as PayPal e-mail

A computer virus that camouflages itself as a message from PayPal has started spreading among home users, antivirus companies said on Friday.

The program is a variant of the Mimail virus, which has previously spread by appearing to be a security advisory from Microsoft. The latest version of the program is attached to an e-mail forged to look as though it came from PayPal, an online payment service bought by eBay last year. Running the program infects the victim's computer and asks the PC user for credit card information, which the virus then sends to the attacker.

"It is a new trend among virus authors to get deeper into criminal acts and attempt to generate revenue," said Craig Schmugar, virus research engineer for security company Network Associates.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Another virus, Sobig, is believed by many researchers to have been spread by a group that sells a list of the machines the program compromises to spammers. The latest variant of Mimail takes a more direct approach to illicitly obtaining funds.

The virus appears as an attachment--"www.paypal.com.scr"--to an e-mail that purports to be from PayPal.

"PayPal would like to inform you about some important information regarding your PayPal account," the message reads. "This account, which is associated with the email address will be expiring within five business days. We apologize for any inconvenience that this may cause, but this is occurring because all of our customers are required to update their account settings with their personal information. We are taking these actions because we are implementing a new security policy on our website to insure everyone's absolute privacy."

When a person opens the e-mail attachment, a window appears bearing the PayPal logo and asking for credit card information. The virus stores any information provided by the victim in a file called "ppinfo.sys" and the file is sent to four e-mail addresses stored in the program.

Antivirus companies are in the process of blocking access to the e-mail boxes.

The virus also searches through the Internet browser files cached on a victim's computer and grabs e-mail addresses from the sources found there. It will then send itself as an attachment to the original e-mail to every address found.

Companies tend to respond to such virus threats very quickly, and many block e-mail attachments as a matter of policy, so it's mainly home users that have to worry, said Vincent Weafer, senior director for incident response at security software company Symantec.

"We see a lot of corporate submissions in the very beginning and then it moves almost exclusively to those from home users," he said.

The companies recommended that PC users update their virus definitions.

See more CNET content tagged:
PayPal, Mimail, virus, antivirus company, home user

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    Dell's new CFO Brian Gladden has said that the company "more work to be done," to improve profitability and decrease costs. The Wall Street Journal is reporting that the company is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.