back to article New Windows virus attacks PHP, HTML, and ASP scripts

Researchers have identified a new strain of malware that can spread rapidly from machine to machine using a variety of infection techniques, including the poisoning of webservers, which then go on to contaminate visitors. The malware is a variation of a rapidly mutating virus alternately known as Virut and Virux. It has long …


  1. Angry clown

    What the author forgot to mention

    As usual, only certain users of a certain operating system from a certain large North-American vendor are at risk. No offense to those who got their computers infested with winlogon.exe or explorer.exe in the first place but they should take better care of their systems.

    Please lower your flamethrowers while I put on my flame retardant underwear.

  3. Jason Togneri

    @ What the author forgot to mention

    So, in your roundabout, circumspect, and extremely subtle way you're trying to say, is that the author forgot to mention it was a Windows virus? So you didn't even read the title of this article ("New Windows virus") before you began your bandwagon trolling?

  4. The Fuzzy Wotnot

    @Angry clown

    I too am curious to know if this affects the product of large org starting with the letter A or is it simply Master G(B)ates and his little toys?

  5. Anonymous Coward

    Re: Angry Clown

    You woke up at 3am to post that? Cock.

  6. Ash

    @Angry Clown

    OMG U R 2 DUM!!!1

    Nah, just kidding. I stopped browsing as Admin a long time ago. If I could get my wireless network working in openSUSE I wouldn't have Windows.

    It seems that there is nobody who would help someone who's never done it before, though, and I'll have to trawl through forum after forum of "OMG STFU NOOB GO BAK 2 WINDD0S" posts before I get somewhere.

    Unfortunately, i've spent more time researching this issue than I spend rebuilding Windows after an attack. That's possibly the largest stumbling block "Linux on the desktop" faces.

  7. David Farinic

    for Angry clown

    Ye and those compromised php all run on OSyou mentioned.. wake up and check your webserver

  8. Anonymous Coward

    If you are reading this...

    ... it could have happened to you ?

  9. Anonymous Coward

    @ Angry clown

    Did you not read the title ?

    Maybe I should move away from the market leader and move to and OS even the hackers don't care about ?

  10. Anonymous Coward
    Anonymous Coward

    well done...

    angry clown, you saw the word "windows" in the title and started foaming at the mouth,moron.

    Actually useful info this, thanks reg!

  11. Wortel

    Knock knock

    Who's there? the scanning gateway.

    Junk like that doesn't even make it past this machine in my network, which sits just behind the router.

    Problem solved before it even becomes one. Of course that could be a problem for people in home situations, because machines like that (Astaro, SonicWall, big muscle custom made layer 7 packet scrubber servers for many users, etc) cost a pretty penny.

    For smaller wallets have a look at, or perhaps Yoggie over at

    Just to name two options for simple home use.

  12. Humph


    Can we get a "smug grin" icon for us Linux users?

  13. André Marques

    @Angry Clown

    IT'S IN THE TITLE!!! Right there! New WINDOWS virus!

    Damn OS fanboys sink humanity lower every day...

  14. Anonymous Coward
    Anonymous Coward


    is also able to infect web scripts based on languages such as PHP, ASP, and HTML.

    ????? HTML ?????

    are you sure?

    Are they actually saying their is a security exploit using HTML and only HTML that can infect a web server? if so which web servers are effected?

    I'm confused more information if you please.

  15. Death_Ninja

    What the poster forgot to mention...

    ...was that funnily enough cross platform code execution isn't actually possible.

    Like duh

  16. steogede

    Re: What the author forgot...

    I don't see any mention (or anything that implies) that this only infects Windows Servers. Or by trying to make a reference to Red Hat - i.e. PNAELV ?

    Yes it only infects Windows desktops, but there is no suggest that it is so picky about the servers it chooses.

    >> Please lower your flamethrowers while I put on my flame retardant underwear

    Surely you mean climb out from under your bridge and set your table?

  18. Roger Hughes

    @ Euh!

    If all the thing is doing is searching for accessible and editable files that will be served as HTML from a server and inserting <iframe width=1 height=1src="">, then yes, plain HTML files will be as vulnerable as those which include scripting. Don't even have to be on a server, in fact - HTML opened locally in a browser will do the job too.

  19. Anonymous Coward

    @ Ash

    Hi Ash,

    One of the main reasons I switched to Ubuntu from Gentoo/Debian/SuSE (I've tried a few, what can I say??!!) was because my wireless just worked.

    The more I think about it the more it pains me to say it, but Ubuntu is rapidly becoming the operating system with all the "ease of use" of windows without the malware and virus crap.

    /me wonders if the next virus to hit Linux will be aimed @ ubuntu...


  20. Matthew Macdonald-Wallace

    attack vector?

    Just read the MS and TM blog posts, am I right in believing that this virus can only infect locally stored PHP scripts that could potentially be uploaded to a server, or can this virus run multiple exploits against PHP and thereby infect servers that are visited by an infected machine?

  21. Mike Crawshaw

    @ Ash 12/02 08:25

    That level of "help" on Linux forums is precisely why I know dozens of people who have given Linux of various flavours a try, and then returned to Windows. They're generally above-the-average level for Windows home users - quite comfortable settings up home networks or tweaking for performance gains etc. To them, asking a reasonable enough question for a new user of a product, to be shouted down with nonsensical abuse by "the elite" (who sound like 13yo's writing text messages) is enough to make them say "Fuck that for a lark".

    Say what you like about Windows, but generally speaking, the majority of "help" areas for home users are at least somewhat helpful, and don't just take the piss out of a new user for not being instantly familiar with the intricacies of unfamiliar, and often quite daunting, tasks.

  22. Apocalypse Later

    Not mutation

    "rapidly mutating virus" is just wrong. Mutation in nature is an uncontrolled process which usually leads to the mutated organism being damaged or even non-viable. True mutation in software might come about by some kind of corruption such as a disk read or write error, but this would also very likely stop the software working at all, and is nothing to do with what the author means when he uses the word in relation to viruses. Such use is misleading.

    Further reading reveals that what the author is describing is "new polymorphic tricks" which are not mutation but simply code routines in the virus that vary the way it it appears from one instance of infection to another. This is entirely in the control of the writer of the virus, not a mutation brought about by a random event. The virus code remains the same, including the carefully designed part that paints the virus' face anew for each infection.

    Talk about a virus "fingerprint" is also misleading. Viruses do not have fingerprints (nor "signatures") in the way that people do. Different virus researchers and their AV software will use different search strings (the non-misleading term) and other techniques to identify viruses. There is no one "fingerprint" or "signature" that is relied on by everyone in the way implied by these terms.

    The polymorphism makes the use of such search strings difficult, as the virus must be decrypted before they can be applied, and both the encryption and the virus' own decrypting stub (necessary for the virus to decrypt its own code to run it) vary from one instance of the virus to the next. Techniques to identify such viruses reliably are therefore complex, but no mutation is involved.

  23. Player_16

    @Angry Clown

    Why are you Angry? You should be Embarrassed. You just gave *nix a bad rap - somewhat.

  24. BlueGreen

    Not a very helpful article

    As @AC 10:25 above says, HTML???

    How does it infect stuff? What are the vulnerabilities? If I forbid IFRAMES with noscript is that the cure? Does it needs JS (which I block)? Does it rely on plugins like flash (that I never use) or can it manage without?

    Or does it try to break stuff at a lower level which the browser can't catch?

    And as one of your links says: "Win32/Virut creates a mutex named VT_3 which it uses to prevent multiple copies of itself from running on the host system" then perhaps a trivial script which takes and holds a same-named mutex would be a pretty effective hack at blocking it as a short term measure.

    Not enough info!

  25. Aaron

    Re: title

    "Can we get a "smug grin" icon for us Linux users?"

    Only if everyone else gets an "actually getting work done while Humph fiddles with his xorg.conf for the nine hundred and thirty-seventh time" icon.

  26. B

    Best of both worlds, get a Mac

    Unleash the flaming dogs of war on me, but I'm going to go ahead and make the observation that the choice of OS is not limited to Winblows or Linux. Winblows is. . . .well .. . .. .Winblows, so it's obvious why you wouldn't want to use it. Linux is powerful, but as several people have mentioned it doesn't seem ready for the masses, and online message boards leave you with the fear of getting gang raped if you ask any questions. So what is a person to do? If only there was an OS that was very easy to use . . . it "just worked" . . . and it also had the power of certified Unix under the hood. . . . .if only . . ...

    Sorry if that sounded sarcastic, it wasn't intended that way. Just thinking out loud that there is an alternative that combines the best of both worlds.

  27. Robert Grant Silver badge

    Weird this

    When a Linux *fixed, unexploited vulnerability* appears on El Reg, no end of people comment on how it's not just Windows that's insecure, but when Windows is *actually compromised* and someone points out that it wouldn't happen on Linux then everyone jumps down their throat.

  28. Apocalypse Later

    Users and how to attract them

    Below is just part of the installation instructions for Doom 3 on Ubuntu. I don't think anything else has to be said re: Windows/Ubuntu/Users. But others will no doubt continue to say many things.

    Installation of the Linux binary

    The installation writes to /usr/local/games/doom3 by default. You should install using sudo to ensure write permissions to /usr/local/games/doom3, and make sure that the installation file is executable.

    chmod +x

    sudo ./

    # As of 2008-03-19 this is:

    sudo ./

    Add the missing files

    The following files need to be copied from the win32 install CDs to your base/ directory. by default, /usr/local/games/doom3/base






    # On Ubuntu 7.04, you can find these by inserting discs 1-3 one-after-the-other

    # and then doing, for each disk:

    sudo cp /media/cdrom0/Setup/Data/base/pak00*.pk4 /usr/local/games/doom3/base

  29. Wortel


    Try if you haven't gone too sour from the unfortunate meeting(s) with the lesser tactful of the human race of some Linux forums.

    You should be able to find what you need there perhaps even without actually posting a question.

  30. Fred

    Needs clarification

    Ok - while i would also like for the 'smug ubuntu' user icon as well, there is one important thing that has not been addressed: if this virus/malware is capable of getting to executable code, and since the CPU instruction set is the same for the IBM clone PC, is this virus limited to just the windows OS?

    As for those of you who state that getting advice for new comers to Linux/Ubuntu - you are totally wrong. Simply use the IRC chat channel to ask your questions and there are very decent folk there that will help you. Any form of noob bashing is a big no-no on many ubuntu forums!

  31. Anonymous Coward
    Anonymous Coward

    Ubuntu questions.... - helped me with a ton of Ubuntu stuff. Very friendly folk there because the admins don't let folks run wild (unlike the typical snotty *nix fuck-heads).

  32. Mike Crawshaw

    @ Fred + Wortel & AC. Oh, and "B"

    Fred: "As for those of you who state that getting advice for new comers to Linux/Ubuntu - you are totally wrong."

    Erm, no, not *wrong*. Maybe the users in question (who are, to be fair, not "tech-heads", but are basically pretty competent as home users go) went to the wrong place (AFAIK, they Googled the issue they were having and clicked the links) - but they definitely did come out with a bad impression of the community (I won't repeat verbatim their comments!), and were thus quite discouraged from progressing any further.

    I've made a note of the locations mentioned by the 3 of you above (visible at this time), and will pass them to anyone who mentioned similar issues in the future.

    B - "if only...." they weren't £x00 more than the price of a comparable-spec PC...! (just priced up: £700 for an iBook, £400 for a higher-specced (RAM, HDD & processor all higher) Toshiba laptop...) - there's a credit crunch on y'know!! ;-)

  33. patrick allen


    Can we just have more real conversations with less continual flaming and inanities? Some real dialogue? Please.

    Many of us are starting discontinue reading the comments because there is just more and more unsubstantial comments making it a waste of time trying to find constructive data from the real info sec professionals who might be posting and/or reading The Reg's articles.



  34. Quirkafleeg

    Re: @ Ash 12/02 08:25

    “That level of "help" on Linux forums is precisely why I know dozens of people who have given Linux of various flavours a try, and then returned to Windows. […]”

    Some of us prefer Usenet because you can filter out the 13-year-olds.

  36. Scott

    @ AC (08:21 GMT)

    .... it might be 3am in your part of the world, but it would have been 3pm in mine.....

  37. J

    @ @ Ash 12/02 08:25

    Where have you people been looking for help, I wonder?

    OK, I suppose you have googled for something and clicked on links. I've been using Linux for more than 8 years now, and I google (or whatever it was I did before) all the time for help on many things both OS and app-related. Have rarely seem the (in)famous responses you guys mention. Many times the responses are too technical for a newbie or whatever. But rarely they are as you mention. They DO exist, but are very minority as far as I've seen. Have I just been lucky all along?

    Maybe ye are just delicate flowers that get scared by a few posts from the inevitable arrogant idiots to be found everywhere (not just software communities)?

  38. Matt
    Thumb Down

    This one's nasty

    Seen it a few times in the past week, the giveaway is in the hosts file: "" at the top. Lockups, slow performance, script and Internet problems, occasional virus alerts....

    And the fact that every ruddy .exe and .htm is infected when you scan the disk from another uninfected pc. No live-CD trojan removal here, full format and reload I'm afraid. Bloody nightmare.

    It even tried spreading to my network install drive (which is now most definitely read-only) and my USB stick.

  39. Goat Jam

    Re: Online support forums


    Try Ubuntu. I've installed it on several laptops with different wireless cards and it has always worked out of the box.

    Re: Online support. Again, with the Ubuntu plug, but their support forums are nothing like that. I participate in the "Absolute Beginners" forum occasionally when I'm bored and I have yet to see the behaviour you and others describe. The mods there do a pretty good job and people there are generally keen to see newbies succeed.

  40. Neoc
    Thumb Down

    Re: Users and how to attract them

    @Apocalypse 14:42 GMT "Below is just part of the installation instructions for Doom 3 on Ubuntu."

    Let me get this straight... you are trying to install a *windows* version of a game (the instructions specifically mention the Win32 install CDs) on a Linux machine - which requires patching some of the game's executables/libraries - and you are complaining about the complexity of the instructions? Let me guess - you're the kind of person who think that modifying a ULP car engine to run on diesel simply requires changing the nozzle you use at the pump, right?

    Geez. Can we have a Luser icon? This is why I left Support as soon as I could - perfectly rational people somehow have their brains switched off as soon as a computer is involved in the "problem".

  41. BlueGreen

    A bit more info, & @Matt

    I followed a link I'd missed before in the article (oops) and got some useful info. <> mentions that the page you're redirected to has some javascript (weirdly obfuscated in a way I've not seen before; can anyone explain?).

    So, it looks like blocking JS will block the exploit. Request to author of this article - make this clear in future.

    Matt, as you're one of the few not posting about ubuntu here, what do you reckon to the 'grab the mutex first' suggestion. In fact, if the users are running as users not as admin, would that be enough to stop it, ye reckon?

    And the sooner we get to some intelligent, fine grained control of browsers' scripting, the better. Why should xmlhttprequest be on by default.

    Disclaimer: I'm not a web developer. This may be obvious.

  42. Schroeder


    The issue Ash is referring to is actually caused by Microsoft Trolls polluting Linux support groups. I can probably finger a few posters in this thread of being guilty of this practice. Yes, you know who you are.

    There's one particularly sad individual who inhabits the unbuntu and advocacy groups, who amongst other things has claimed to be a kernel hacker, yet has been show to have actually never run Linux from their lack of knowledge. All he does is use foul language and insist Microsoft is better, whilst claiming to have hit x number of Linux issues, all of which are generally shown to be either made up, or a willingly obtuse issue like the Doom install above, found by googling.

    I'd probably find it amusing, if wasn't part of an orchestrated campaign ( yes boys, it is, we've all read the docs Microsoft wanted buried in Comes V Microsoft, so don't bother tinfoil hat comments), that is ultimately is aimed at making sure that I don't have the freedom to install whatever operating system I want on the hardware I own.

    On the Doom issue above, as Neoc points out it is a hack created to allow a win game run cross platform - here's a hint to Mr Later - try installing UT2k4 on a linux distro from that time - you'll probably find the install script provided (with Epic's blessing) on the original DVD works first time ....

    But then even Microsoft has pretty much given up on PC gaming, even cutting FS - there's just no profit in it compared to the consoles. Then what do you really need Windows for in the home? After all, if your a Microsoft fanboi you'll already be browsing the web and downloading your movies via your Xbox 720...

  43. Anthony

    Re: c'mon

    Amen to that! I seem to remember posting something similar myself - but perhaps I just typed it out and closed the window in a huff ...

    @amanfrommars - The post you congratulated is exactly the kind of thing that is interesting to read. Perhaps you could also start thinking through your own posts a bit more in future ...

  46. Anonymous Coward

    Nobody's going after the domain owner?

    "The iframe surreptitiously directs visitors to (don't visit it unless you're a security professional)"

    What I want to know is why someone isn't busting down the door of whoever owns the "" domain and hauling the bastard(s) off to some suitably horrible prison in a 3rd world country where torture is allowed. But apparently the relevant authorites don't give a rat's ass about internet crime otherwise they'd put a stop to such things. Vigilantes anyone? ;)

  47. Anonymous Coward

    One wonders about the advertisers...

    "Many of us are starting discontinue reading the comments because there is just more and more unsubstantial comments making it a waste of time...."

    Oh, darn, and I was just starting to get the hang of Reg-accepted disgusting obscenities and allowable swear-words (anything goes) and off-topic flaming and such ;)

    But, you're right, of course (seriously). The seedy stuff turns a lot of people off. Something else for the Reg to consider, is the *advertisers* - if I was running a company looking for adspace, I would absolutely *not* advertise on these pages because it would put my company in a bad light. Maybe this website should run ads for public threesomes and flourescent condoms and such, it would be more appropriate to some of the stuff I've read here.

