ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Nimda resurgence falls flat

Robert Lemos, ZDNet.com ZDNet US

Published: 01 Oct 2001 09:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A resurgence of the Nimda worm failed to materialize Friday, leaving unfulfilled warnings that several security companies made this week.

The e-mail component of the worm, which sends infected messages to each entry in an infected computer's Outlook address book, reactivates 10 days after the original infection. That part of the program had antivirus researchers and security experts worried that the Nimda worm was again set to spread quickly.

But Friday morning, 10 days after the first infections started to take hold, few signs heralded a return of the worm.

"We have been checking throughout the entire day, and we are not seeing anything," said John Harrington, director of marketing for e-mail filtering service MessageLabs. "Our gut feeling is that it is not going to happen."

According to MessageLabs' Web site, the company has detected fewer than 1,600 copies of the virus since the start of the epidemic 10 days ago.

Nimda -- which is "admin," the shortened form of "system administrator," spelled backward -- started spreading Sept. 18 and quickly infected PCs and servers around the world. Also known as "readme.exe" and "W32.Nimda," the worm is the first to use four different methods to infect not only PCs running Windows 95, 98, Me and 2000, but also servers running Windows 2000.

The worm spreads by e-mailing itself as an attachment, scanning for and then infecting vulnerable Web servers running Microsoft's Internet Information Server software, copying itself to shared disk drives on networked PCs, and appending JavaScript code to Web pages that will download the worm to surfers' PCs when they view the page.

The e-mail component of the worm sends Nimda-infected messages every 10 days, counting from when the victim was originally infected. Since the virus is thought to have started early in the afternoon of 18 September, the first new e-mails should have started going out early on Friday.

Only a few infected computers may be left, however.

Anti-virus software maker Trend Micro said that while some companies reported infections Friday, the number is still low.

"We've seen a few infections in organizations that haven't done a complete cleaning, but it's limited," said company spokeswoman Susan Orbuch.

Furthermore, compromised servers and PCs without Outlook installed will only have a limited number of e-mail addresses to which to send messages. The worm also scans the browser cache on computers for saved Web pages that contain e-mail addresses and sends infected messages to those addresses as well.

Servers that aren't used to browse the Internet will not have such a cache.

See the Viruses and Hacking News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
37 out of 80 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Software Engineer - C#, .NET, Web Services - Reading - Insurance - 40k

You will develop new components and web pages using the latest features in .NET 2.0/3.0 and additional frameworks such as Ajax. Key Skills: C# ...

WEB DESIGNER - PHOTOSHOP/CSS - DIGITAL- S LONDON - 45K

This exciting role will allow you to design new web pages, email promotions, SEO, Banner and other exciting web advertising. Photshop/CSS, ...

McAffee Anti Virus Rollout Engineer CRB Cleared

The role will require the following - - Experienced in field support - Windows 2000 / XP / Vista - Anti - Virus experience For an immediate telephone ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains