Sponsor for PC Pals Forum

Author Topic: Destructive Windows Virus set to activate on 3rd Februray  (Read 794 times)

Offline sam

  • Administrator
  • *****
  • Posts: 19966
All, this came to all the system admins at my uni:

Credit: SANS diary
http://isc.sans.org/diary.php?storyid=1067

Quote

BlackWorm Summary
Published: 2006-01-24,
Last Updated: 2006-01-25 00:17:00 UTC by Johannes Ullrich
(Version: 1)

About BlackWorm
Over the last week, "Blackworm" infected more then 700,000
systems as measured using a counter web site used by the
worm to track itself. This  worm is  different and more
serious then other worms for a number of reasons. In
particular, it will overwrite a user's files on February
3rd.

At this point, the worm will be detected by up to date anti
virus signatures. In order to protect yourself from data
loss on February 3rd, you should use current (Jan 23rd or
later) anti virus signatures.

The following file types will be overwritten by the virus:
DOC, XLS, MDE, MDB, PPT, PPS, RAR, PDF, PSD, DMP, ZIP. The
files are overwritten with an error message( 'DATA Error [47
0F 94 93 F4 K5]').
- sam | @starrydude --

Offline Clive

  • Administrator
  • *****
  • Posts: 74245
  • Won Quiz of the Year 2015,2016,2017, 2020, 2021
Destructive Windows Virus set to activate on 3rd Februray
« Reply #1 on: January 27, 2006, 16:44 »
Kama Sutra wipeout
Warning over 3 Feb viral payload explosion
The Register
By John Leyden
Published Friday 27th January 2006 15:40 GMT

Windows users are been urged to make sure their systems are clean from an email worm which is programmed to overwrite user's files on 3 February. Blackworm (AKA Nyxem, MyWife or Tearec) has infected more than 300,000 systems worldwide, based on analysis of logs from counter web sites used by the worm.

Blackworm arrives as the infectious payload of email messages with spoofed sender addresses claiming to offer obscene pictures or pornographic movie clips. Subject lines used in the malicious emails include: The Best Videoclip Ever, Fw: SeX.mpg, Miss Lebanon 2006 and f***in Kama Sutra pics. The worm only affects Windows PCs.

If activated, Blackworm tries to disable security software. It also tries to harvest email addresses from infected PCs in a routine designed to draw up a hit list of targets for infection. Blackworm is programmed to download updates of its code onto infected PCs.

Its behaviour is little different from standard email worms apart from the fact it is programmed to overwrite DOC, XLS, MDB, MDE, PPT, PPS, ZIP, RAR, PDF, PSD and DMP on 3 February. The worm creates and opens a ZIP archive in the Windows system directory, potentially giving away its presence on infected systems but don't rely on this.

Windows users are advised to run scans for infected using up-to-date anti-virus signatures. The worm attempts to disable most anti-virus products so if you hit trouble on this score it's a good idea to either reinstall software or run web-based anti-virus scanners, such as Trend Micro's free House Call service. ®

http://www.theregister.co.uk/2006/01/27/blackworm_warning/


Show unread posts since last visit.
Sponsor for PC Pals Forum