virus alert
virus alert

'Robin Hood' virus on the loose

Nachi worm adds another string to its bow

Written by Iain Thomson

A new variant of the Nachi worm is patching PCs that are vulnerable to MyDoom.A.

Nachi B, also known as Welchi, copies itself onto systems using the same flaw as MyDoom.A, as a file named 'Svchost.exe'.

It then attempts to delete MyDoom and downloads patches to fix the security hole.

Carole Theriault, security consultant at Sophos, said: "It's an interesting case - some kind of Robin Hood virus.

"We're seeing some spreading but it's not going too fast. We're hoping everyone with MyDoom would have stripped it out by now. If IT managers haven't updated by now they are way behind the curve."

Viruses to deal with viruses are nothing new. In the mid 1990s a boot sector virus called Chinese Fish attempted something similar by removing a virus called Stoned.

Nachi's first incarnation emerged last year as an attempt to patch the security hole exploited by the Blaster worm.

David Emm, product marketing manager at McAfee Security, explained that such code is a bad idea.

"I see code like this as a little bit of a blind; a ruse to calm people's fears," he said.

"Nachi A did not do a particularly good job at patching systems and this one doesn't look much better. At the end of the day it's still self-replicating code and that's a bad medium."

Infection rates are low so far, but an antivirus signature is under development.

Tags:

Further reading

MyDoom delivers second payload

'Doomjuice' instructs infected machines to launch distributed DoS attack against Microsoft   More...

Related articles

Cyber-criminals launch PDF malware offensive

PDFex storms into the charts   More...

Yahoo Messenger web chat flaw emerges

Chinese security boards reveal new vulnerability   More...

New malware-infected site found every five seconds

Experts warn of 'dramatic rise' in web-based threats   More...

Microsoft patches eight 'critical' holes

August update covers four web browsing risks   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement