Log In

Reset Password

Experts battle malicious computer worm

Local Internet providers have intercepted thousands of e-mails infected by a malicious worm program that has struck the network worldwide.

The mass-mailing worm has different names including ?Novarg?, ?MyDoom? or ?WORM_MIMAIL.R? that appears as an error message and is activated if the attachment is opened.

?What it does is masquerades as an error message and drops this worm on your computers as denial of service,? said Stephen Davidson, vice president of product development at QuoVadis, a computer security provider. ?When a computer is infected by MyDoom, the worm immediately looks for new e-mail addresses and attempts to propagate to those new computers.?

He added that small communities like Bermuda can suffer a ?disproportionate? amount of damage from fast-spreading computer attacks like MyDoom.

On Tuesday and Wednesday the company, which services about 1000 mailboxes in about ten companies across the Island, had stopped a few thousand worm-infected e-mails. ?Yesterday (Tuesday) we had about 35 percent of e-mails carrying the virus. That?s about one in three e-mails coming through that were carrying the virus. As of 10 o?clock this morning (Wednesday) we had intercepted 500 e-mails.?

Mr. Davidson recommended that people continue to update their anti-virus protection as parts of the virus can be changed.

Nigel Hickson, e-commerce consultant for the Government, said: ?We?re reasonably confident that we won?t be affected but we?re not being complacent,? he added.

Similar sentiments were apparent at internet service providers.

Logic Communications has spam catcher program and they have added security patch on their website that subscribers can download.

North Rock and Fort Knox all have virus software that detects suspicious e-mails.

?Fortunately, our network operators were able to download the latest virus identity file as soon as it was available on Monday and that was installed on the mail server and that version has been able to protect the North Rock subscribers,? said Vicki Coelho, sales and marketing manager for North Rock.

Suspicious e-mails possibly containing the worm are sent by random addresses and subject lines. ?Test?, ?hi?, ?hello?, ?Mail Delivery System?, ?Mail Transaction Failed?, ?Server Report?, ?Status? and ?Error? are subject lines that are usually used.

The body of the e-mail usually includes a message such as: ?The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.?

The attachment included in the message has to be opened in order for the virus to attack the computer allowing a hacker into a computer system.

Attachments usually read as one of the following: ?Document?, ?readme?, ?doc?, ?text?, ?file?, ?data?, ?test?, ?message? or ?body?.