Searching for Code Red Source
Virus writing group 29A denies creating the costly worms, as experts debate the possible origins.
Joris Evers, IDG News Service
A virus writing group called 29A is denying reports that any of its members created the Code Red or Code Red II worms.
The denial comes after a German media report pinpointed 29A as the brains behind the malicious Internet worms. A Deutsche Presse Agentur report on Tuesday says that 29A has been bragging on online chat rooms about unleashing Code Red onto the Net. DPA also described 29A as a Dutch hacker group.
"Some Chinese guy is responsible [for Code Red] not any 29A member," says a Spanish member of 29A using the alias VirusBuster in an e-mail interview. He adds that 29A is not a hacker group, but a virus writing group. Most members are from Spain and the Czech Republic; none are Dutch, he says.
Mikko Hypponen, manager of antivirus research at antivirus software vendor F-Secure, has investigated the source of both Code Red and Code Red II and says he "is pretty confident 29A is not involved with any version of Code Red" as they lack the traditional 29A signature.
"The string 29A exists in the code of Code Red II. It is a binary reference to the number 666. The string is part of the code that is executed and not something that was set apart as a signature. In viruses created by a 29A member the signature is not part of the code, but separate and is always in a special format," he says.
Looking for Clues
Experts and authorities worldwide are trying to determine who is responsible for Code Red and Code Red II. There is some speculation that the first version was made in China because the worm placed a message saying "hacked by Chinese" on infected systems. The economic cost of both worms has reportedly risen to nearly $2 billion.
F-Secure's Hypponen thinks Code Red II was made in the United States by virus writers who believe the original Code Red came from China. Hypponen himself doesn't believe the original worm was created in China, although he doesn't have anything concrete to back that.
"This [Code Red II] is an anti-Chinese virus. It checks whether it has infected a Chinese machine and then doubles the spreading rate. We think Code Red II was made in the U.S. as a retaliation," says Hypponen.
Code Red is a self-propagating worm that exploits a flaw in Internet Information Server, a part of Microsoft's Windows 2000 and Windows NT software. It scans the Internet for vulnerable systems and infects these systems by installing itself. The amount of traffic Code Red generates can slow down the flow of information across the Internet.
The more dangerous Code Red II installs a back door in servers that allows attackers to access the infected computer without the usual passwords. Once logged in through the back door, attackers can gain control of the machine.
A patch for the flaw in IIS that is exploited by Code Red and Code Red II has been available from Microsoft since mid-June.
Laptop Showcase
Full Windows 7 coverage
- Great year-end deals

for small business! -
Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors) and save up to 200!
-
HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!
- *Other names and brands may be claimed as the property of others. ©2009 Intel Corporation. Intel, the Intel logo, vPro and Core trademarks of Intel Corporation in the United States and other countries. All rights reserved.
People who read this also read:
Best Prices on Antivirus Software
Norton Antivirus 2010 (Full Product, 1 User)Price: $17.90
Anti-virus 2010 (OEM Product, 1 User)Price: $21.56
AntiVirus Plus 2010 - 3 Users (Full Product)Price: $14.99
Norton AntiVirus 2009 (Full Product)Price: $16.89
AntiVirus 2010 (Full Product)Price: $24.95
Anti-Virus 2009 (Full Product)Price: $15.04
- Perfect Printing Solutions Find just the right All-in-One Printer for you from HP. Visit the HP Resource Center.
- Acer Laptop Center Forget the Mouse...check out the next generation multi-gesture touch screen technology from Acer.
- Dell Shopping Center Check out great deals from Dell!
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage







