ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Worm's growth contained as deadline looms

Published: 15 Aug 2003 08:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The MSBlast worm's infection rate has slowed as companies and home users clean up compromised computers, according to antivirus firms.

Click here for help on countering the worm.

Named after the msblast.exe file that contains the program, MSBlast continued to spread to new computers on Thursday, but the rate of infection has slowed significantly. Since Monday at noon, the worm had infected as least 330,000 computers, according to security company Symantec.

"We had an exponential growth on Monday, but it has dramatically slowed down," said Vincent Weafer, senior director for the company's security response team. Symantec has dubbed the worm "W32/Blaster."

Far fewer computers may currently be infected with an active copy of the worm. Symantec's data does not take into account the number of infected computers that have been cleaned of the program. Since Monday, business and home users have been securing their PCs and deleting the worm from computers that had been compromised.

Unlike the more-common mass-mailing email viruses, an Internet worm like MSBlast spreads automatically, by exploiting weaknesses in computers that are connected to the Internet. The worm uses a widespread Windows flaw that Microsoft warned about and patched a month ago. People who have not applied the patch -- by downloading it from Microsoft's Windows Update service or the company's Web site -- are the only ones vulnerable.

Security company Network Associates said it has received reports of infections from several hundred companies and PC users.

"We are seeing a continual drop off -- Tuesday was the day it really had the opportunity to spread," said Vincent Gullotto, vice president of Network Associates' antivirus emergency response team. "Our process today is really focused on any problems that customers are having."

If true, the drop in the number of computers infected could be good news for Microsoft.

The primary payload of the MSBlast worm is a denial-of-service attack against the network from which most Windows users get their updates. If successful, the manoeuvre will frustrate efforts to patch the Windows vulnerability that the worm exploits. The strategy is also a way of simply harassing the software giant; the worm's code contains a message for the company's founder: "billy gates why do you make this possible? Stop making money and fix your software!!"

Computers infected with the worm will start sending connection requests to the Windows Update service at midnight Friday, according to the clock on a given user's computer. That will first happen in Russia, just over the International Date Line, at about 4 a.m. PT.

Not everyone agrees that the worm is going away just yet. Some organisations are seeing indications that the worm's spread is growing, or at least, that more people are becoming aware of the self-spreading program.

The Computer Emergency Response Team (CERT) Coordination Centre, a clearinghouse for information on Internet threats, continued to see about the same number of reports on Thursday as the previous day.

"It is really hard to say up or down," said Art Manion, an Internet security analyst with the CERT Coordination Centre. "Reports are fairly steady. Our numbers are not good enough to say up or down."

The group previously said that as many as 1.4 million Internet addresses had become the homes of computers infected by the worm or an earlier attack program on which the worm was based.

However, Manion stressed that the numbers do not correspond to computers on a one-to-one basis. Many computers are connected to broadband providers that assign a different Internet address to a computer each time it connects to the network.

"We can't give any finer resolution than hundreds of thousands of computers," Manion said.

Enterprise antivirus firm Trend Micro reported that reports of worm infections had jumped threefold overnight from Wednesday to Thursday, but acknowledged that PC users may have only recently realised that performance issues with their computers were connected to the worm.

"People say, 'OK, maybe I am infected,' and then they go online to check," said Joe Hartman, director of North American antivirus research for Trend Micro. "We haven't seen all of it yet."

Hartman also stressed that it is very hard to estimate the number of computers that are actually infected at any given time, but believed that it's holding fairly steady.

"It isn't increasing all that much, because more people are using antivirus software and are using firewalls," he said. As more people become protected, the worm has fewer places to go.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
67 out of 134 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

C#Net/Silverlight eCommerce Developer - Finance/Trading systems

C#, ASP.Net, Flash, Silverlight - eCommerce - Spreadbetting/FX Trading - Greenfield development - London The market leading provider of financial ...

Graduate Quality Engineers, Yorkshire, Permanent

The business is spread across locations all over the world and they are currently looking for Graduate Quality Engineer to join their team. An ...

Java & C++ Developer - Spreadbetting - 50-60K+ Finance

JAVA/C++ developers Excellent Java developer who has strong C++ experience required to join a leading financial spread betting company that has ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation