Advertisement
Promo

Security threats Toolkit

Netsky.D worm spreading at 'record speed'

Munir Kotadia ZDNet.co.uk

Published: 01 Mar 2004 15:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the Netsky worm was spreading very quickly on Monday. The news comes on a day where firms are already dealing with five new variants of the Bagle worm.

Previous Netsky worms scanned the hard drives of infected computers to collect email addresses, which were then used to spread the worm via a built-in SMTP email engine. The worm also copied itself to any shared folders it discovered. The latest variant is different because it does not copy itself into a "shared" folder and is slightly smaller in size.

However, the worm is spread as an executable attachment and will cause infected computers to play a series of beeps from their PC speakers between 6 a.m. and 8.59 a.m. on 2 March.

Graham Cluley, a senior technology consultant for Sophos, told ZDNet UK that Netsky.D is already filling up email gateways and is expected to get much worse before it gets better. "We are getting reports from companies that thousands of copies of the virus have started clogging up their email systems -- in a similar way to the Sobig virus last year," he said.

According to Cluley, these types of worms are as much of a spam problem as they are a virus problem: "The main problem this kind of virus causes is it turns your email connection into porridge because it clogs it up. Even if you are stopping the virus at your gateway, your gateway has to churn through all this extra email it is suddenly receiving," he said.

Cluley said the worm will spread even more as the US "wakes up" and  Americans start turning on their PCs. "America has just woken up and will be opening its inboxes, and hopefully won't be double-clicking on the attachment, but we anticipate the worm will increase in its prevalence over the coming hours," he said.

Finnish security company F-Secure has given Netsky.D its highest alert (Level 1) because the worm continues to spread at "almost record-breaking speeds".

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
68 out of 124 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters