ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Nyxem virus set to bite next week

Tom Espiner ZDNet.co.uk

Published: 26 Jan 2006 17:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Businesses have been warned to brace themselves for a possible traffic spike next week caused by the Nyxem virus.

The Nyxem virus was first reported on 16 January. It is thought to have infected more than half a million PCs, and security vendor Ironport warned on Thursday that these machines are now hard-coded to propagate the virus on 3 February.

Companies will be unlikely to be directly affected if they are running up-to-date antivirus software because the major antivirus vendors have now released patches. But Ironport warned that firms could experience secondary effects as the virus tries to propagate itself by harvesting email addresses on an infected machine.

"The knock-on effects will come as compromised PCs try to communicate with businesses. This will cause additional email and network traffic, and possible slow down email response time," said Jason Steer, technical consultant at Ironport.

Security company F-Secure has reported that Nyxem.E reached the top position in its virus statistics with 21.7 percent of all reported infections. On Saturday the Web counter used by the Nyxem worm itself showed over 510,000 infections and continued to rise, according to F-Secure.

Once active, Nyxem will delete all Word, Excel, PowerPoint, and PDF file types from a compromised PC. The multi-faceted malware will also attempt to propagate itself both through email and as a network worm, which can be particularly damaging on closed networks.

"Nyxem is certainly malicious. It can be delivered via email, but also as a network worm. It probes other PCs on a closed network to compromise them and send itself to the other computers, to infect as many hosts as possible," said Steer.

The malware hides in attachment types not typically blocked by attachment filters, IronPort said.

The Internet community will not know the scale of the February attack until it occurs. "It depends on how many hosts are infected," said Steer. "At the moment it's just sitting there quietly, and we won't know how many home users have been infected until 3 February."

Businesses should warn their employees not to open suspicious emails, and to know what these emails may look like. "The subject lines may contain some references to pornography — fairly typical stuff," said Steer.

"Be vigilant. Update your antivirus patches, and make sure your hard-disk has been scanned to detect and remove the virus," he added.

Nyxem has the potential to cause havoc throughout the year, as infected PCs are set to activate on the third day of every month, unless they are cleaned up.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
93 out of 168 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment