Killer virus ravages internet

Latest worm has the worst elements of Sir Cam and Code Red

Written by Robert Jaques and John Geralds

Millions of internet surfers are in danger from a devastating virus which is currently spreading much more rapidly than Code Red, security experts warned today.

The self propagating worm, known as Nimda, which spells admin backwards, is particularly virulent as it can spread through email attachments, shared hard disks inside networks, or across HTTP. It is doubly dangerous as it attacks both PCs and servers running Microsoft software.

An alert by TruSecure, which discovered the worm, said the rate of growth and spread is exceedingly rapid, significantly faster than any worm to date and much faster than any variant of Code Red.

TruSecure pointed out that Nimda sends itself by email, as SirCam does, and also scans for and infects web servers like Code Red does.

When Nimda, which is known to affect all 32-bit Windows systems including Windows 98, 2000, ME and NT, arrives in an email, it appears as an attachment named readme.exe.

"This worm bites you right on the nose, you can get stung by browsing the internet or by opening an infected email," said Graham Cluley, senior technology consultant at Sophos Anti-Virus.

An FBI representative said the agency was "assessing the incident", but so far it found no relationship between the online attack and last week's US terrorist attacks.

Security firm Panda software said: "W32/Nimda.A@mm [alias Nimda] is a dangerous mass-mailing worm that runs automatically when the message that contains it is viewed through the preview pane. It spreads by email by means of a vulnerability in Internet Explorer 5 and the email clients Outlook and Outlook Express.

According to Panda the vulnerability has two main characteristics: it uses HTML code to generate a frame together with an attachment coded in Base64, marked as audio/x-wav. Both actions trick the Internet Explorer component which offers browser services to Microsoft's email clients.

Antivirus specialist McAfee said the worm attacks 16 known vulnerabilities in Internet Information Services (IIS) servers, including the security hole left by the recent Code Red II worm.

Experts at McAfee added that, using the vulnerability in Microsoft's IIS web server software, the worm corrupts websites with malicious code. The worm then forwards itself by email to all addresses found on the user's computer.

Infected sites may also display a web page prompting users to download an Outlook file containing the Nimda worm.

Experts said Nimda had appeared in Europe, Latin America and the US and was likely to spread to additional regions.

The following links offer help on how to fix the Nimda virus:

www.McAfee.com

www.microsoft.com's round up

Symantec.com

Tags:

Further reading

Internet Information Server - don't do it

Software too vulnerable to attack, warn analysts   More...

Script kiddie launches 'war vote' virus

Virus writers sink to new low with World Trade Center worm   More...

Linux users in Trojan debate

Remote Shell virus raises hackles in the open source community   More...

Code Blue virus exploits IIS hole

Goes for the 'Folder Traversal' vulnerability   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement