Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Worm hits corporate networks hard

Robert Lemos, ZDNet.com ZDNet.co.uk

Published: 14 Jun 1999 08:36 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Judging from the number of reports we have had, this looks a little less prevalent than Melissa," said David Chess, an anti-virus researcher at IBM Corp.'s Watson Research Laboratory in Hawthorne, N.Y. Melissa spread through Internet e-mail at the end of March, reportedly infecting nearly 100,000 computers.

While first noticed in Israel on Sunday, the worm -- also known as TROJ_EXPLORE.ZIP and I-Worm.ZippedFiles -- struck hardest in the United States on Thursday, shutting down several major companies for hours and deleting critical files. Researchers also warned that once a single corporate user's PC was infected with ExploreZip, the worm can quickly spread to other users by a secondary mode of infection.

"The worm not only spams itself out," said Eric Chien, senior researcher at the Symantec AntiVirus Reseach Center, "but when it searches through the network drives (looking to delete files), if it finds another Windows installation out there, it will infect it as well."

In other words, users sharing their hard drives with each other -- a practice common in some workgroups -- will automatically be infected if one of the group gets the virus. The lesson: It may take a village to teach a child, but it only takes one gullible user to infect an entire company.

On Thursday, major companies were shutting down their servers and disconnecting from the Internet in order to put protections in place. Microsoft Corp., Intel Corp., Boeing Co., SBC Communications Inc., and AT&T were among the companies hit. By Friday, most companies had gotten the hint. "As of today, people are getting a handle on it," said Chien, who added that, of Symantec's customers, almost 20 major U.S. companies had been hit.

On Friday, reports from employees at the San Francisco-based Jamba Juice and the game publishing giant Electronics Arts reported both companies had been infected. Neither company responded to calls by press time.

While the worm hit the U.S. fairly hard, ExploreZip seems to have done little damage abroad, reported anti-virus firm Trend Micro Inc. "I think the rest of the world benefited by the U.S. getting it first," said Susan Orbuch, spokeswoman for the Cupertino, California, company.

The worm combines the reproductive capabilities of the Melissa virus and the destructive force of the CIH virus. Those two pieces of malicious code struck the Internet in March and April, respectively. ExploreZip proliferates over e-mail based on the messaging application programming interface, or MAPI, such as Microsoft's Exchange, Outlook and Outlook Express. When a user sends an e-mail to an infected computer, he or she will receive a response that contains the virus payload in an attached file called ZippedFiles.exe. The message header will appear the same with "RE:" but the text inside will be changed. It will say:

"Hi (Recipient Name)! "I received your email and I shall send you a reply ASAP. "Till then, take a look at the attached zipped docs. "Bye"

Once opened, the worm, called Worm.ExploreZip, deletes Microsoft Word, Excel, and PowerPoint files off hard drives. In addition, it targets development files created by C, C++ and assembly language editors, deleting those as well.

Computers in the U.S., Germany, France, Norway, Israel, Japan, Taiwan and the Czech Republic were infected by the worm, said Finnish computer security firm Data Fellows Corp.

Take me to the Melissa Virus special.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
35 out of 64 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Linux is shipped on a third of all net...

A third of netbooks shipped in 2009 came with GNU/Linux rather than Windows preinstalled, according to analysis from ABI Research. The firm's figures strongly contradict Microsoft's... More

Post a comment

the PsiXda - at last a real computer i...

The PsiXpda is an homage to the long gone but still much loved and greatly missed Psion portable computers. Many who have been in this industry for long enough to have experienced the... More

1 comment

Nokia halves smartphone portfolio

Nokia has reduced the number of smartphone models it intends to introduce in 2010 by half, according to reports. Quoted in an article on Reuters, the Finnish handset maker's new... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters