Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Sobig Virus Spread is Fastest Ever; Nachi Worm Continues
Dow Jones Newswires | Riva Richmond

Posted on 08/20/2003 8:36:10 PM PDT by HAL9000

NEW YORK (AP)—A virus that debuted this week has been declared the fastest spreading e-mail plague of all time, while another malicious program that hit last week continued to disrupt computers worldwide.

MessageLabs Inc., a company that filters e-mail for corporate clients around the world, Wednesday said it had intercepted more than a million copies of the "Sobig.F" virus the previous day, the most it has ever intercepted in a single day. That was one in every 17 e-mail messages the firm scanned.

"That's just a number we've never seen before," said Brian Czarny, MessageLabs' marketing director. The most widespread virus of all time, "Klez," at its peak accounted for one in 125 messages scanned.

Sobig.F continued to spread aggressively on Wednesday, though the pace eased off a bit to about one in 60 messages, he said.

The virus, which is the sixth and latest strain of a virus that first emerged in January, spreads through Windows PCs via e-mail and corporate networks. Besides clogging e-mail systems with messages carrying subject lines like "Re: Details" and "Re: Wicked screensaver," the virus also deposits a Trojan horse, or hacker back door, that can be used to turn victims' PCs into relayers of spam e-mail.

"It's a seeding," Czarny said. "All they're looking to do is plant that Trojan."

Another virus, of the self-spreading kind called a "worm," first appeared last week and was still causing problems Wednesday. The worm, dubbed "Blaster," spreads through Internet connections to PCs using versions of Microsoft Corp.'s Windows operating system that haven't been fixed for a programming flaw. Microsoft disclosed the error, and provided a patch, on July 16.

Blaster was followed this week by the derivative "Nachi" or "Welchia," which attempts to inoculate computers by downloading the patch from Microsoft. However, the new worm is causing more problems than Blaster, and brought down Air Canada's ticketing systems Tuesday.

Railway giant CSX Corp. said a "worm virus" brought down its signaling systems early Wednesday morning, causing delays and canceled trains through the Eastern states.

Andy Ellis, chief security architect at Web services company Akamai Technologies Inc. said "Nachi" may not be more widespread than Blaster, but it is technically superior and is now generating twice as much Internet traffic as Blaster.

A lot of companies have been reporting problems inside their networks, he said, and there have been "a couple of points where parts of the backbone had performance issues" in the last 24 hours.

"Nachi is a long-term problem that has to be dealt with. These systems absolutely have to be patched," Ellis said.

Copyright 2003 Associated Press. All rights reserved.



TOPICS: News/Current Events; Technical
KEYWORDS: lowqualitycrap; microsoft; nachi; sobig; virus; windows; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-74 last
To: HAL9000
Help! I've got the blaster worm on my Dell computer that's running Windows XP. I can't stay online long enough to download the patch from Microsoft. I followed the directions Microsoft gave about enabling a firewall but that didn't help. Windows reboots every 5 minutes and that isn't enough time to get the patch. I wonder why my McCaffee anti-virus software didn't catch this?
61 posted on 08/21/2003 11:45:22 AM PDT by Sweet Hour of Prayer
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
I've been battling this Welchi virus all day. I have no idea how it managed to get past the firewall.
62 posted on 08/21/2003 11:48:38 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Stefan Stackhouse
I wonder if that Compaq was a return sold as new.
63 posted on 08/21/2003 11:48:50 AM PDT by brianl703
[ Post Reply | Private Reply | To 54 | View Replies]

To: Sweet Hour of Prayer
Your best option may be to ask a friend to download the patch and provide you with a copy on floppy or burn a CD-R. Good luck.
64 posted on 08/21/2003 11:53:17 AM PDT by HAL9000
[ Post Reply | Private Reply | To 61 | View Replies]

To: Sweet Hour of Prayer
When it comes up with the message saying it will reboot in X seconds, change your clock time to 2002
65 posted on 08/21/2003 1:52:05 PM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 61 | View Replies]

To: Question_Assumptions
I must say Apple has greatly improved the Mac, but still for the money a PC can run all the same software and more and you're not tied down with expensive prorietary parts, or the inane restrictions you have with some of the lower end Macs like the iMac. I do like Macs for one thing they look nice and even the OS is pretty spiffy looking, (and when I say Macs I mean real machines like the G4 and G5, not that iMac stuff). The day they let me build my own Mac to my liking then I may consider it.

Oh and I wouldn't mind that nice 23" Mac monitor either, "great display, just don't attach it to a Mac" as one reviewer put ;-)
66 posted on 08/21/2003 8:16:23 PM PDT by battousai (Hello... Hello... is this thing on?)
[ Post Reply | Private Reply | To 35 | View Replies]

To: AppyPappy
I've been battling this Welchi virus all day. I have no idea how it managed to get past the firewall.

A good hardware firewall will block all ports by default, then let you open just those needed for specific services. I was doing great until the firewall died. I was stupid not to have a software firewall running as a backup. Live and learn.

67 posted on 08/21/2003 8:29:23 PM PDT by js1138
[ Post Reply | Private Reply | To 62 | View Replies]

To: HAL9000
How would I know if I've caught SOBIG.F or the others. I have a win98 box with PC-Cillin.

In the case of a buddy's winxp machine that I disinfected last week, I knew he had msblaster by running a search for the msblast file. Is there a similar tell-tale for these new virii? Or is the lack of any symptoms/warnings proof that I'm not infected?

68 posted on 08/21/2003 8:32:33 PM PDT by Petronski (I'm not always cranky.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: js1138
No stupid for having an SQL server on the internet, thats what DMZ's are for..
69 posted on 08/22/2003 5:35:38 AM PDT by N3WBI3
[ Post Reply | Private Reply | To 29 | View Replies]

To: Fishrrman
No the PC world, from the Windows world..
70 posted on 08/22/2003 5:36:30 AM PDT by N3WBI3
[ Post Reply | Private Reply | To 30 | View Replies]

To: battousai
I must say Apple has greatly improved the Mac, but still for the money a PC can run all the same software and more

The only thing I miss on my Mac is games and, frankly, I'm better of saving my money and my time by not having them.

and you're not tied down with expensive prorietary parts,

Not much of a problem any more since they mostly use IDE drives and standard memory and they include so many ports and such standard that most people will only need peripherals, which are USB or Firewire. If you break something, that could be a factor but I haven't had a problem with breaking things since they are built pretty solidly.

or the inane restrictions you have with some of the lower end Macs like the iMac.

For example? The only problem I'm aware of is that hard drives can be very difficult for an end user to replace in some Macs.

I do like Macs for one thing they look nice and even the OS is pretty spiffy looking, (and when I say Macs I mean real machines like the G4 and G5, not that iMac stuff).

My iBook works just fine. Of course the 12" PowerBook would now be my option. I'm waiting to see if they can pull off a G5 laptop before I upgrade.

The day they let me build my own Mac to my liking then I may consider it.

What do you want to build into it that isn't included standard or that you can't easily get?

71 posted on 08/22/2003 7:37:18 AM PDT by Question_Assumptions
[ Post Reply | Private Reply | To 66 | View Replies]

To: HAL9000
Besides clogging e-mail systems with messages carrying subject lines like "Re: Details" and "Re: Wicked screensaver," the virus also deposits a Trojan horse, or hacker back door, that can be used to turn victims' PCs into relayers of spam e-mail.

All known spammers should be hauled in for some investigation, as they clearly have the motive, means, and opportunity.

72 posted on 08/22/2003 7:42:03 AM PDT by steve-b
[ Post Reply | Private Reply | To 1 | View Replies]

To: N3WBI3
Possibly, but this is a 10 computer office with one server. SQL is completely isolated by the hardware firewall and ZoneAlarm now.
73 posted on 08/22/2003 9:14:06 AM PDT by js1138
[ Post Reply | Private Reply | To 69 | View Replies]

FREE PC PROTECTION:

74 posted on 08/23/2003 5:41:29 AM PDT by martin_fierro (A v v n c v l v s M a x i m v s)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-74 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson