News

Windows 2000 Faces First Virus

Despite the fact that Windows 2000 has not yet shipped to the general public, the first virus for the pending OS has been found. But the company that found the virus says it does not appear to be on the prowl.

F-Secure Corp., a provider of security solutions, discovered the new virus called Win2K.Inta or Win2000.Install, and believes it was written by the 29A virus group.

It operates only under Windows 2000 and is not designed to operate at all under older versions of Windows.

The most important feature of the virus is its capability to spread under the new operating system. Win2K.Inta infects program files and spreads when these files are exchanged. The virus infects files with the following extensions: EXE, COM, DLL, ACM, AX, CNV, CPL, DRV, MPD, OCX, PCI, SCR, SYS, TSP, TLB, VWP, WPC and MSI. This includes several classes of programs that were not susceptible to virus infection before. For instance, Win2K.Inta analyzes the Windows Installer files (MSI files), scans them for embedded programs and infects them.

The virus contains this text string, which is never displayed: [Win2000.Installer] by Benny/29A & Darkman/29A.

Mikko Hypponen, manager of Anti-Virus research at F-Secure (www.f-secure.com) says that this virus has greater implications than a single, contained virus.

"Now we can expect virus writers to include Windows 2000 compatibility as a standard feature in new viruses," he says.

Further technical information is available at www.F-Secure.com/virus-info. – Thomas Sullivan

About the Author

Scott Bekker is editor in chief of Redmond Channel Partner magazine.

Featured

  • Office Mobile Apps To End as Microsoft Highlights New Office App

    Microsoft plans to end support for Windows 10 Mobile applications on Jan. 12, 2021, according to a Friday announcement.

  • Is Microsoft Finally Reinventing Office?

    Microsoft is testing out a new technology called "Fluid Framework." It could mean that Brien's dream of one Office app to rule them all might soon become reality.

  • Azure Active Directory Connect Preview Adds Support for Disconnected AD Forests

    Microsoft on Thursday announced a preview of a new "Cloud Provisioning" feature for the Azure Active Directory Connect service that promises to bring together scattered Active Directory "forests."

  • Microsoft Defender ATP Gets macOS Investigation Support

    The endpoint and detection response (EDR) feature in Microsoft Defender Advanced Threat Protection (ATP) has reached the "general availability" stage for macOS devices.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.