You are here: silicon.com > Software > Security Strategy

Security Strategy

First NT system driver virus found in the wild

By Sally Watson

Published: 11 October 1999 14:11 GMT

Russian anti-virus company, Kaspersky Lab, has discovered what it claims is the world's first known virus to act as a Windows NT system driver.

The virus - known as Infis - infects the highest security level of the Windows NT Operating System (OS) and was found 'in the wild' - i.e. outside a laboratory environment.

According to Nimrod Vered, head of product management at virus specialists Finjan, Infis works by introducing itself to the OS as a driver "which is a very fundamental OS layer. There are not many people worldwide who can write in-depth drivers. They are embedded very deep in NT." Once inside the OS, the virus destroys programs like calculator, MS Paint and CD Player.

"I'm surprised to see this type of virus," Vered added. "It's appeared a year earlier than any virus company expected."

According to Phil Ryan of security firm Peapod, the virus presents little immediate threat because it doesn't self-replicate. "Given that the infection will spread relatively slowly and that there is no destructive payload, then this virus is not a big threat to industry," he said.

"But the important point is that it is a new type of virus and, as often happens, it may be succeeded by others using the same technique but with more harmful payloads," Ryan added.

Vered agreed that Infis is currently of more interest technically than as a threat to corporate networks, but warned: "It won't take long to copy the method of the driver and make it more damaging. If hackers mutate it and add a more sophisticated distribution method, we will be facing more serious danger."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Technical Support Engineer - French Speaking

Windows 2000, Windows NT, Novell, Lotus Notes, Mac OS). Support Engineer required by Logic Engagements Ltd to work for our client, based in ...

Senior Infrastructure Engineer

Enterprise Infrastructure Services to include: Directory, Messaging, Updates, Anti Virus and Malware, Network, PKI, Redundancy / Clustering, Backup ...

Support Analyst

The skills and experience that any person applying for this IT support analyst role should have are; MS office, Windows OS server and workstation in ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: