Millions of Bagle worms kill the Windows XP2 firewall

Three new variants of the Bagle worm, which can disable the latest firewall protection in Windows, were discovered on Friday and antivirus companies are expecting a surge of infections during the day.

Earlier this year Microsoft released a major security update for Windows XP, which was designed to strengthen the operating system's defences against attack from viruses and hackers. One major part of the update was an improved version of its firewall software.

Graham Cluley, senior technology consultant at antivirus firm Sophos, said the latest Bagle variants are designed to attack and disable Microsoft's new firewall application.

"Just because you are running the latest version of Windows XP you shouldn't think you are necessarily protected from this worm. If it infects a PC running Windows XP SP2 the worm can turn off its firewall and open the door to hackers and other Internet attacks," said Cluley.

Neil Campbell, the national security manager at Internet security specialists Dimension Data, said it is common for viruses and worms to try and disable any firewall and antivirus programs on the system.

Campbell said the latest version of Microsoft's Windows firewall is a "huge leap forward" when compared to the previous version but he recommends that users should install a third party firewall - such as the free version of ZoneAlarm - for better protection.

"There is a window of opportunity when the system boots and loads the network and before the third party firewall becomes active. Windows firewall gives you good coverage during that time," said Campbell.

E-mail security firm Messagelabs said it has intercepted around 900,000 copies of the new Bagle variants this weekend and expects that figure to peak later today as people in Europe and the US switch on their computers.

David Banes, technical director of MessageLabs in Asia Pacific, told ZDNet Australia  that the company sees around one percent of all Internet traffic, so picking up almost one million copies over a weekend is very significant. But he expects the worm to start fading as users update their security software over the next few days.

"I imagine that when we look back at the end of this week we will see a dip in interceptions on Sunday - when the whole world is offline - and then they will peak on Monday and tail off again by the end of the week," said Banes.

Advertisement

Talkback 1 comments

    Hi I think I got hit by this n ...Anonymous -- 02/11/04

    Hi I think I got hit by this nasty worm. The other day I got a suspicious email. It said thankyou in the subject line. My antivirus trend micro picked it up.

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured