November 27, 2001 8:20 AM PST

Worm hits home for the holidays

A computer worm that was spreading at an alarming rate has begun to slow, according to security experts.

Known as as BadTrans.B, the worm installs hacking software on infected computers. It hit home e-mail users hard last weekend, but the damage to corporate consumers was less than previously anticipated.

"We have captured upward of 13,000 of these (infected messages) since we first started seeing them, but for the most part I think corporate users are going to be just fine," said John Harrington, with e-mail screening service MessageLabs. "It is probably going to affect home users more than anyone else because they tend not to update their (virus protection) as often as corporate users."

While the 13,000 figure is significant, it would have been even higher had the malicious program spread through company networks.

"When it first broke, it was one of the fastest-propagating worms that we had seen to date, but that has slowed a bit," Harrington said.

MessageLabs said it has seen around 30,000 copies to date in about 90 countries.

The worm is spreading mainly due to people's relaxed approach to security during the holiday season, said April Goostree, virus research manager for computer security company McAfee.com.

"The fact that it comes around this time makes more end-users vulnerable, because they are expecting holiday e-mails," she said.

Reports of the worm, a variant of the original BadTrans virus that started spreading last April, started coming in Friday night. By Saturday, Goostree said, McAfee.com had intercepted several hundred copies of the worm. On Sunday, reports of worm infections were coming in at a rate of three to five every minute.

Data provided online by e-mail screening service MessageLabs showed the virus accelerating quickly, with more than 700 infected e-mail messages intercepted on Saturday and several thousand stopped on Sunday.

The numbers knocked SirCam from the No. 1 slot in MessageLabs' daily rankings of the Top 10 bugs, a spot the persistent e-mail worm has held for more than four months.

The worm doesn't play on the holidays, however. Aside from a handful of general names for the e-mail attachment that spreads the worm--such as "card" and "pics"--the worm makes no overt connection to either Thanksgiving or Christmas.

While Badtrans.B is not destructive, it does install a keylogger, a program that records what a person using the infected PC types and then sends the information to the virus writer's e-mail address. The key-logging program, known as Backdoor-NK.server, focuses specifically on four software functions that are used by programs to allow a person to enter a password, so it mainly records account information entered.

The FBI is reportedly using just such a program to collect the digital keys to suspected criminals' accounts.

A PC user will first encounter the worm as an e-mail message--possibly from someone he or she knows--with an executable attachment. The worm propagates by sending itself as a reply to any unread messages in the person's Outlook mailbox. It also sends itself to e-mail addresses culled from images of Web pages contained in the "My Documents" folder and the browser's cache.

The virus uses a vulnerability in Microsoft's Internet Explorer 5.01 and 5.5 to automatically execute itself on PCs that don't have a patched Web browser. Opening the e-mail in a separate window or Outlook's preview pane will cause the worm to execute on unpatched machines.

The vulnerability had also been used by the Nimda worm as one of its four ways of spreading.

"That's the vulnerability du jour," said Roger Thompson, lead antivirus researcher for security firm TruSecure.

On PCs with patched Web browsers, a dialog box will open, asking the person what to do.

Staff writer Wendy McAuliffe contributed to this report from London. Staff writer Sandeep Junnarkar contributed from New York.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.