Advertisement
Promo

Online business Toolkit

Nimda worm causes Internet slowdown

Wendy McAuliffe ZDNet.co.uk

Published: 19 Sep 2001 16:22 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Internet virus, which has been recognised as a hybrid of the Code Red worm, is expected to have a much greater impact on Internet traffic than its predecessor, according to antivirus experts.

Nimda uses multiple methods to attack servers and PCs using Windows software. It combines elements of the Web-based Code Red virus, which targetted servers using Microsoft's Internet Information Server (IIS) software, with a mass-mailing component enabling the virus to propagate on a massive scale. It can also spread across open network shares or across shared drives that allow connections via the username guest without the need for a password.

"It is generating a lot of Internet traffic, and a lot of Web sites have been receiving a lot of bogus requests," said Graham Cluley, senior technology consultant at antivirus firm Sophos. "Web surfers will definitely be seeing a slow-down."

Analysis of the worm's activity by Matrix.org reveals that at 18:00 GMT yesterday, the reachability of Web pages dipped late on Tuesday to 91.3 percent -- a 2 percent drop from the average length of time that it has been taking to load Internet pages in the last 24 hours. Some antivirus experts believe this suggets that the worst of Nimda'a effects may be over. "From a worm-tracking standard, Nimda appears to have peaked already," said David Perry, global director of education at Trend Micro.

Home computers are most at risk from the Nimda virus, as most corporate systems running IIS software will already have been patched against the Code Red exploit. "Nimda is vastly more complex than Code Red as it is able to affect end users' PCs," said Perry.

Nimda arrives as an attachment entitled "Readme.exe", which is programmed to exploit a MIME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express and Internet Explorer. The email automatically archives the attachment, enabling the executable file to run without the end user having to double-click on the attachment.

Trend Micro reports that in the last 24 hours, 24,000 infected computers have been identified out of the 60,000 that have visited antivirus.com for scanning.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
44 out of 98 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters