new virus [Archive] - Ceramic Tile Advice Forums - John Bridge Ceramic Tile

PDA

View Full Version : new virus


flatfloor
09-19-2001, 10:24 AM
Here's a site that gives details http://www.internetnews.com/dev-news/article/0,,10_886981,00.html Ok that doesn't work let me try pasting it.

The Federal Bureau of Investigation and private sector security experts Tuesday warned of a sophisticated new virus dubbed Nimda, which spreads both as a worm exploiting the same vulnerabilities used by the recent Code Red and sadmind/IIS worms, and as an e-mail virus. Experts said the worm could proliferate as widely as Code Red.

The Computer Emergency Response Team Coordination Center (CERT/CC), based at Carnegie-Mellon University, said "User machines that are infected by this virus might see an increase in scanning as the virus tries to compromise IIS servers. Many sites are experiencing high loads of e-mail and network traffic as a result of this activity."

London-based GFI Security Labs said Tuesday afternoon that Nimda replicates quickly and has the ability to spread through e-mail clients even if recipients don't open the attachment, ReadMe.exe, which comes with infected e-mails.

GFI said Nimda can run without user intervention by using an exploit in Microsoft Outlook reported in a Microsoft Security Bulletin on March 29, 2001. The user simply reads the e-mail and the attachment executes. If the recipient's e-mail client has been patched, a pop up dialog window appears, inviting the recipient to execute the attachment.

"Anyone responsible for users' computers (both home users and corporate users) should be sure that the latest version of anti-virus definitions are installed," CERT said. "Users should exercise extrem caution in handling e-mail attachments."

Nimda also seeks out and infects vulnerable Microsoft IIS servers and defaces Web sites using the software. In addition, Medina, Ohio-based Central Command Inc. warned, "This worm also spreads through a local area network. The virus activates the user guest with no password and adds itself to the Administrator group. Also it creates a share for C:\ with all access rights." GFI added that, potentially, any user vulnerable to the exploit that visits an infected site may become infected simply by visiting the defaced site.

When the worm executes, it copies itself in the system directory with the name load.exe. It also copies over the library file riched20.dll and modifies itself to be loaded as a Dynamically Linked Library (DLL). The worm also modifies system.ini in the boot section with the line "shell=explorer.exe load.exe -dontrunold" in order to activate itself at every reboot.

Central Command said the worm uses MAPI functions to read users' e-mails, and extracts SMTP addresses and e-mail addresses in order to spread itself.

"Although it has not yet reached the severity of Code Red, F-Secure believes that it's quite possible that Nimda will reach Code Red's level of proliferation," said Finnish security company F-Secure Corp. F-Secure has classified Nimda a Level 1 Security Alert, its most severe threat classification.

Nimda sends itself out with a random subject line and no message text. GFI said that because of its highly replicative nature, Nimda can clog mail servers.

"The Nimda virus has taken e-mail threats one step further in its use of complex replication mechanisms and the fact that it is transmitted in a multitude of ways," said David Vella, product manager for GFI. "It appears to be a concept virus and it has worked successfully. This suggests that Nimda variants and other similar e-mail viruses are on their way and could possibly make use of new exploits. E-mail security at server level is an absolute must to block this new threat."

CERT recommended that infected machines be removed from networks for recovery, and said system administrators should follow the steps listed in "Steps for Recovering from a UNIX or NT System Compromise." CERT also warned that Web server content may be altered on compromised Web servers and Web content should be verified for integrity.



InternetNews - Developer News Archives






[Edited by flatfloor on 09-19-2001 at 12:30 PM]

Sponsored Links


flatfloor
09-21-2001, 05:13 PM
CX, you got that? If so, please explain it to me.

cx
09-21-2001, 05:57 PM
I like when you make little jokes like that, Jim.

I think the worst thing I read in there is that the virus activates without your opening the attachment. Doesn't even give a fella a chance!

Best defense is to keep your virus protection updated, I suppose. I looked in mine yesterday and Nimda was not listed. Dullard that I am, I haven't updated yet. But I'm afixin to rat quick.

Where is JC, anyway?

JC
09-21-2001, 08:44 PM
Two lessons...don't use Microsoft and don't ever open anything that says "read me.exe". And don't even read any mail unless you know the sender. Also if your mail program allows it allways chose to view e-mail directly from the ISP and that way it is not downloaderd to your machine.
If you are a die-hard Outlook guy then make sure to get the patch.

Me personally I just don't worry bout these things myself. If my computer starts doing something strange then I just format the thing and re-load.
When you add up all the virus updates(that your supposed to do) and all the time trying to figure out what you have, the resources spent on these programs.etc..it is just faster/easier to just format once or twice a year and clean your system out anyways and make it faster and cleaner.
Just keep all sensitive data off your machine(ie. credit card numbers etc..) or do what I do just keep a debit card just for internet puchases and only put money in that account for a particular purchase and nothing more that way they can't get anything anyways.
If you notice many worms/exploits/viruses tend to affect certain programs so if you use programs and browsers that are not the norm you seem to be safer also.
Beware of virus warnings that are actually viruses themselves.