ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

FBI Most Wanted: A computer worm?

Published: 04 Apr 2000 09:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A largely unsuccessful computer worm has garnered national attention in the States after an FBI agency posted a warning of the malicious code on its pages over the weekend.

On Saturday, the National Infrastructure Protection Center -- a joint agency created by the FBI and the Department of Justice to pursue cybercrime -- posted an advisory about the computer worm, dubbing it a "self-propagating 911 script."

"I think getting out the information is important," said Vincent Weafer, director of Symantec's AntiVirus Research Center, which posted information on the worm last Friday. "I can understand why -- in the case of the 911 system -- they put up a report." The NIPC was not available for comment by press time.

According to the April 1 advisory, and information from anti-virus software makers, the worm code is actually several batch files -- each a collection of commands -- that run on Windows 95 and 98.

After an infected computer boots up and goes online, the batch files command the computer to "ping" the Internet addresses belonging to eight domains: ATT.net, BellSouth.net, Level3.net, AOL.com, Mindspring.com, Earthlink.net, Air.on.ca, and PSI.net. When a target computer using a pinged address responds, the batch file checks to see if the computer is sharing an unprotected hard drive. If so, it infects it.

According to the NIPC, the worm has not had much success in spreading. "To this point, case information and known victims suggest a relatively limited dissemination of this script (worm) in the Houston, Texas area," stated the advisory.

For the NIPC and the FBI, the worm's worst aspect is that 20 percent of infected computers will dial 911 emergency services upon startup.

When the worm copies itself to a new computer, one out of five times it modifies the new machine's autoexec.bat file, causing it to dial 911 when during startup.

Despite the concern, that's nothing new, said Weafer. "Certainly we have had a number of 911 viruses in the past," he said. However, he added that the danger resides in copycats who may create a better and faster spreading virus.

"Certainly if someone was try and copy cat this and was more successful, it would be a very bad thing," he said.

The worm can be deleted by deleting the C:Program FilesChode directory and the following three files:

C:WindowsStart MenuStartupashield.pif

C:WindowsStart MenuStartupnetstat.pif

C:WindowsStart MenuStartupwinsock.vbs

The worm as been dubbed BAT.Chode.Worm and BAT_Chode911 by anti-virus firms.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
14 out of 32 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment