ALKHOBAR, 29 September — Malicious code is spreading through the Kingdom’s networks at Internet speed. Three new destructive worms have been detected in three days. The trouble began on Sept. 25 with TROJ_VOTE.A.

This mass-mailing Trojan propagates via Microsoft Outlook, sending e-mails to all addresses listed in an infected user’s address book. It arrives in an e-mail that contains the following information: Subject: Fwd:Peace BeTween AmeriCa And IsLam! Message Body: Hi! iS iT A waR Against AmeriCa Or IsLam! Let’s Vote To Live in Peace! Attachment: WTC.EXE.

TROJ_VOTE.A deletes certain antivirus products installed in a system and drops the files WTC.exe MixDaLaL.vbs, and Zacker.vbs. It modifies the infected user’s Internet Explorer startup page, and formats the infected user’s drive c. It also damages HTM and HTML files.

VOTE.A was followed on Sept. 26 with TROJ_VOTE.B. This worm is also known as Anti_TeRRoRisM.exe or VBS_VOTE.B. It is a variant of TROJ_VOTE.A. It arrives in an e-mail with the subject line: “This War Must Be Done!” Its attachment is Anti_TeRRoRisM.exe.

Yesterday, the variant TROJ_VOTE.C arrived in the Kingdom. Its e-mail has the same subject line and attachment as TROJ_VOTE.A.

These viruses are taking down networks throughout Saudi Arabia and spreading rapidly.

Mirza Asrar Baig, chief executive officer of the local network security firm IT Matrix, has this advice for network administrators and PC users: “Update anti-virus programs today and check for updates everyday for the foreseeable future.

“Set anti-virus programs to scan HTTP traffic as well as e-mails. Network administrators must ensure that the latest Microsoft patches are installed correctly on their servers.

“If at all possible, simply reject or delete e-mails with attachments, especially .exe attachments. New variants of these Trojans are arising daily and it takes anti-virus companies time to create detection patterns. If you receive a virus, let the sender know immediately.”