Home PCs at most risk from Nimda

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
As antivirus experts complete a more detailed analysis of the Nimda worm and companies clean up their networks on Wednesday, several security groups are worried that home computer users will not secure their PCs. (See News Focus: "Nimda worm attacks the Web".) A coalition of government security officials and antivirus software industry experts released a warning to home computer users on Wednesday morning to take Nimda--and the security of their computer systems--seriously. "It is still out there, and home users are going to be the primary mechanism for the email spread of this virus," said Vincent Weafer, a senior director of Symantec's security response centre, who took part in the coalition's discussions on Tuesday. Nimda--which is "admin", the shortened form of "system administrator", spelled backwards--started spreading early Tuesday morning and quickly infected PCs and servers across the Internet. Also known as Readme.exe and W32.Nimda, the worm is the first to use four different methods to infect not only PCs running Windows 95, Windows 98, Windows Me and Windows 2000, but servers running Windows 2000 as well. The worm spreads by emailing itself as an attachment, scanning for and infecting vulnerable Web servers running Microsoft's Internet Information Server software, copying itself to shared disk drives on networks, and appending Javascript code to Web pages that will download the worm to Web surfers' PCs when they view the page. Much of the worm's virulence is due to its automated spread. The email attachment will open automatically under Microsoft's Outlook email program if the program's security settings are at "low" and a security patch has not been installed. On PCs that don't use Outlook, the worm can still spread using its own email engine, but it won't execute automatically. In addition, the worm generates an avalanche of Internet traffic when it scans local chunks of the Internet for vulnerable servers to which it can spread. The automated scanning caused many connectivity problems for businesses on Tuesday. "It seems to randomly be going through every IP (address) of my network," said Ian Neubert, director of information services for online telecommunications equipment seller TWAcomm, which found itself inundated with scans from infected machines. "This is ridiculous." By midday Tuesday, each of TWAcomm's IP addresses had seen upwards of 9,000 scans from infected machines. Other companies' Web servers had become infected with the worm, putting at risk any PC user viewing a Web page hosted on such a server. In one case, the marketing site for fast-food chain Carl's Jr. had been infected with the worm. Several News.com readers noticed the compromised server when the site attempted to upload the Nimda worm to their PCs. "That server is hosted elsewhere," said Daniel Baker, director of IT security for Carl's Jr. parent company CK Restaurants. "They are aware of the problem and will have it resolved soon." Baker added that the worm had not infected the company's own network. Other companies weren't so lucky. A representative of network-protection service Counterpane Internet Security said that several of its customers' servers had to be shut down to clean them of the Nimda worm. Security services firm Neohapsis also confirmed that a Fortune 500 client's network had been extensively infested with copies of the worm. Antivirus firm Trend Micro upped the number of infections reported through its World Virus Tracking Center to 26,000 from 15,000 late Tuesday. Yet most businesses seem to be controlling the infections, said Symantec's Weafer. "They have a handle on the initial problem of blocking the virus," Weafer said. "Now it's recovery mode, and that can take weeks and months." Almost 700 customers reported incidents of infections to Symantec on Tuesday, he said, evenly split between businesses and home users. It's those home users that have antivirus experts worried. Owners of home PCs generally fall behind in securing systems with new software updates and the latest virus definitions for antivirus software, Weafer said. "Yesterday, the large part of the problem was getting good analysis of the worm," he said. "Today, it's getting home users to protect their systems." David Dittrich, senior security engineer for the University of Washington and a computer forensics expert, agreed. "The home users are the hardest ones to deal with," Dittrich said. "We have tried to get the word out that they need to do something, but they don't listen." Dittrich said software makers will have to become more pro-active about contacting customers when major security threats like Nimda arise. Rather than post an advisory on a hard-to-find Web site, software companies should send email to customers telling them to update their software immediately. "Somehow, as the number of patches coming out is going up exponentially, the word has to get out to a larger number of people to apply the patches," he said. "In the end, it may be like automakers, with recalls and everything." See the Internet News Section for full coverage. See the Viruses and Hacking News Section for the latest headlines. Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Telecoms forum. Let the editors know what you think in the Mailroom. And read other letters.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

3 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

6 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

8 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

22 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint