
By Sally Watson
Published: 11 October 1999 14:11 BST
Russian anti-virus company, Kaspersky Lab, has discovered what it claims is the world's first known virus to act as a Windows NT system driver.
The virus - known as Infis - infects the highest security level of the Windows NT Operating System (OS) and was found 'in the wild' - i.e. outside a laboratory environment.
According to Nimrod Vered, head of product management at virus specialists Finjan, Infis works by introducing itself to the OS as a driver "which is a very fundamental OS layer. There are not many people worldwide who can write in-depth drivers. They are embedded very deep in NT." Once inside the OS, the virus destroys programs like calculator, MS Paint and CD Player.
"I'm surprised to see this type of virus," Vered added. "It's appeared a year earlier than any virus company expected."
According to Phil Ryan of security firm Peapod, the virus presents little immediate threat because it doesn't self-replicate. "Given that the infection will spread relatively slowly and that there is no destructive payload, then this virus is not a big threat to industry," he said.
"But the important point is that it is a new type of virus and, as often happens, it may be succeeded by others using the same technique but with more harmful payloads," Ryan added.
Vered agreed that Infis is currently of more interest technically than as a threat to corporate networks, but warned: "It won't take long to copy the method of the driver and make it more damaging. If hackers mutate it and add a more sophisticated distribution method, we will be facing more serious danger."
Windows NT This is a brilliant opportunity to be part of a team looking after internal projects and client solutions! Technically you must: Active ...
The role will include supporting the Desktop Support Application Packaging Engineer in the implementation and operations of the Desktop packaging ...
Open GL - Comms - Ethernet - Multithreading ADVANTAGEOUS SKILLS- * Device driver and file system * Audio industry experience (Pathway Resourcing ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...
Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?