Welcome | Sign In
TechNewsWorld.com
Security

Porn Worm Set to Execute Nasty Payload on Friday

Print Version
E-Mail Article
Reprints
Porn Worm Set to Execute Nasty Payload on Friday

There is concern surrounding the W32/Nyxem worm because of reports that have surfaced indicating that it can disable a keyboard and mouse and force a restart function immediately after infection. During this process, it creates several Windows registry key values to cause an included OCX file to be trusted.


Be especially wary of unsolicited e-mails claiming to contain obscene pictures and sex movies this week. The W32/Nyxem worm is set to trigger its data-destroying payload on February 3.

The W32/Nyxem-D worm -- also known as "Email-Worm.Win32.VB.bi," "Blackworm," "W32.Blackmal.E@mm," or "Grew." -- can spread via e-mail using a variety of pornographic disguises in an attempt to disable security software.

When launched, it tries to disable a number of anti-virus and firewall products, and attempts to harvest other e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse addresses from the infected computer in an effort to spread itself further.

"Companies should educate their users to practice safe computing," said Graham Cluley, senior technology consultant for Sophos.

"That includes never opening unsolicited e-mail attachments and discouraging the sending and receiving of joke files, pornography and funny photographs and screensavers," he added. "This worm feeds on people's willingness to receive salacious content on their desktop computer, but they could be putting their entire company's data at risk."

Nasty Subject Lines

The subject lines used in the malicious e-mails include "*Hot Movie*," "Arab sex DSC-00465.jpg," "Fwd: Crazy illegal Sex!" and various other suggestive phrases. If the subject lines are offensive, the payloads are even more so.

The payload will destroy DOC, XLS, MDB, MDE, PPT, PPS, ZIP, RAR, PDF, PSD and DMP files by replacing their contents with the string: "DATA Error [47 0F 94 93 F4 K5]."

The Feb. 3 payload does work and is set to strike on any infected computer, based on the infected machine's local date and time, according to Ken Dunham, a senior engineer with VeriSign (Nasdaq: VRSN) iDefense.

Fact Versus Fiction

The worm may not be nearly as damaging as some fear, however. That's because the counter it installs can be easily discovered by anyone investigating the worm, Dunham told TechNewsWorld.

"The worm counter may not have started at zero. It records each hit or page view, rather than unique IP addresses, and could be manipulated," Dunham said. "Data to date shows that this worm is not a massive epidemic but that it is temporarily more successful than long-term persistent threats such as NetSky and Zafi variants."

The worm does reportedly send out copies of itself as a PDF, such as eBook.PDF. However, if such a file is executed, Adobe (Nasdaq: ADBE) Acrobat will not be able to execute the MZ header executable, Dunham said. These types of attachments are not significant threats at this time, in his view.

Working Against Researchers

Still, there is concern surrounding the worm, because of reports that it can disable a keyboard and mouse, and forcing a restart of the computer immediately after infection. During this process, it creates several Windows registry key values to cause an included OCX file to be trusted. This avoids any dialog boxes that may otherwise occur. It also attempts to delete files in the Program Files directory related to anti-virus software. Those are scary possibilities, but Dunham said the perpetrators are ultimately working against security researchers.

"Slowly evolving threats like Grew.A often lead to increased fear, uncertainty and doubt without the help of an intelligence provider," Dunham said. "It makes it almost impossible for some to get qualified research data on a worm when there is so much misinformation, aliases, and other data available on the Internet."


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network