Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Resistant virus strains to hit the Net?

ZDNN, US ZDNet US

Published: 15 Jun 1999 08:04 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"We seem to have a Darwinian evolution of viruses going on," said Abner Germanow, an analyst at International Data Corp. in Framingham, Mass. "The viruses are becoming more powerful." While Melissa, which struck in March, spread fast, it was merely an annoyance for most companies. And, the April attack of CIH (sometimes called Chernobyl) did a great deal of damage, but the virus took more than a year to spread.

But the ExploreZip virus is sort of a digital platypus. It combines features of its two predecessors, using e-mail to spread like Melissa and deleting files like the malicious CIH.

That makes ExploreZip a whole lot deadlier. Not only does the virus spread more quickly, but its method of wiping out files is more effective than CIH, said Greg Olson, operations manager at data recovery firm Ontrack International Inc.

Unlike CIH, which deletes the file allocation table -- the road map to the files on the disk -- in the first 1MB of the hard drive, ExploreZip creates a file of zero length and then names it the same as an existing Word, Excel, PowerPoint, C or C++ file, essentially overwriting the original file. "Recovery is more difficult than (with) the CIH virus," he said. "But in most cases, we've been able to recover at least some of the data." The company has had more than 100 customers call for services, with an average of 50 PCs downed per company.

That means that the majority of the companies hit by the virus have lost at least some data.

Network administrators at game company Electronic Arts Inc. worked late Thursday and part of Friday last week to recover data from system backups.

"We back up to tape every night," said Vicki Gordon, director of operations and networking for the game publisher. "About a quarter of our users lost a day or so of work. Those not on the backup service lost all their documents."

But a more subtle form of evolution is in the virus' packaging. Wrapped in an e-mail seemingly from a known user, ExploreZip is camouflaged, which helped it gain entry into the networks of Microsoft Corp., Intel Corp., Boeing, AT&T and other major companies.

"The social engineering on this virus is astounding," said David Perry, researcher with anti-virus firm Trend Micro Inc. All viruses in existence today need the user, or someone in the user's workgroup, to act in some way -- usually to open an e-mail attachment. That's what so-called social engineering is designed to do. Increasingly, the package in which the virus is embedded looks respectable enough to fool users into opening it.

These sorts of evolutions are not new, said IDC's Germanow. "It's not so much the start of a trend, but the continuation of one that has been there for a while," he said.

It's survival of the fittest in the digital world. Seeing their futures tied to that simple concept, companies are beefing up their Internet security and policies. With three major virus incidents slamming Internet-connected companies in the past four months, these companies are taking Internet security more seriously.

Electronic Arts, for example, is sitting down for a heart-to-heart with its anti-virus software provider, said EA's Gordon. "The virus was first discovered on Sunday," she said. "We didn't find about it until Thursday. That's a problem." Many, however, are responding in the wrong way, said virus expert Rob Rosenberger, Webmaster of the Computer Virus Myths Web page. "Companies are starting a trend of precautionary shutdowns," he said. "They are not aware of what their users are doing on the Internet, so when they encounter a virus, they shut down just to make sure."

With companies finding out the hard way the value of their information, those sorts of shutdowns may only increase. But IDC's Germanow points out that such a solution can be as bad as the problem itself.

"As little as two years ago, if e-mail went down for two hours, it wasn't a big deal. Today, it's enormous."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
32 out of 69 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

On the Saving Edge: New Tech in Disast...

By Matthew Cordell A new report commissioned by the UN Foundation and Vodafone Foundation has found the intersection between two incredible trends -- the significant uptick in disasters... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV licence?... More

Post a comment

Linux is shipped on a third of all net...

A third of netbooks shipped in 2009 came with GNU/Linux rather than Windows preinstalled, according to analysis from ABI Research. The firm's figures strongly contradict Microsoft's... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters