New entry: Mytob-Z

May 2, 2005 14:05 GMT  ·  By

Last Friday, Sophos posted the top 10 most active viruses from April and the "winner" is Zafi-D, discovered last year.

Although since its appearance four months have passed, Zafi-D continues to be the leader with 46.6% of the total number of infections. Zafi-D is a mass-mailing type of worm that creates files in the Windows directory, files composed of 8 characters and having the .DLL extension. Some of these files are exact copies or archives of the worm, while others are log files.

Zafi-D searches for e-mail addresses in the Windows Adress Book and in other files on the hard drive, which the worm uses to spread.

Together with Zafi-B, responsible for 4.5% of the total number of infections from April, Zafi is the leader for the fifth month in a row, which proves that there are still many users who haven't updated their antivirus.

Aside from Zafi-D, another well-known worm is Netsky which occupies 6 positions from ten. The only new virus that has found its way into the Top10 is Mytob-Z, another e-mail spreading virus, which also installs a backdoor on the infected systems, so that they can be remotely controlled.

Sophos identified in April 1,146 new viruses and the company's antivirus is currently protecting the user against 103,269 viruses.

These are April's top 10 viruses:

1 W32/Zafi-D 46.6%

2 W32/Netsky-P 20.6%

3 W32/Zafi-B 4.5%

4 W32/Netsky-D 4.5%

5 W32/Netsky-Z 2.5%

6 W32/Netsky-B 2.4%

7 New W32/Mytob-Z 1.3%

8 W32/MyDoom-O 1.2%

9 W32/Netsky-C 1.1%

10 W32/Netsky-Q 1.0%

Others 14.3%