Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

FYI: ALERT- The BlackWorm virus- Act now to avoid infection

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 01:30 AM
Original message
FYI: ALERT- The BlackWorm virus- Act now to avoid infection
Threat Level: HIGH

PandaLabs has detected that all computers infected with BlackWorm will encounter widespread damage this Friday, Feburary 3. BlackWorm, also known as "Tearec.A", "Mywife.E" and "KamaSutra" will corrupt all Microsoft Word, Microsoft Excel or Microsoft PowerPoint files on infected computers.

Don't wait to check if your computer contains Blackworm.
Panda Software recommends running an online virus scan immediately.

INFORMATION:
BlackWorm (Tearec.A) spreads through e-mail attachments, peer-to-peer networks and network shares. It disables and ends several antivirus programs installed on the affected computer. It also attempts to delete files belonging to several antivirus programs, peer-to-peer file sharing programs (P2P) and other Internet applications, which would cause them to stop working.

Additionally, it monitors the network traffic of certain connections related with antivirus programs and email services to collect passwords.

FREE VIRUS SCAN:
Scan your computer for Blackworm.
http://www.ActiveScan.com

Note: Posted as a public service. The poster is not in any way associated with Panda Software, and makes no claims as to the actual urgency of this virus warning.
Printer Friendly | Permalink |  | Top
mike_c Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 01:41 AM
Response to Original message
1. OK-- I saw the Microsoft alert about this virus earlier, but...
Edited on Wed Feb-01-06 01:46 AM by mike_c
...I'm really uncomfortable about running a script like this-- it opened my computer up totally, bypassed my Symantic security wall, installed and ran executables that I know nothing about, etc. Since I don't know anything about PandaScan I feel like I've just violated the most basic security no-no. We shall see.

on edit-- with only about 1/5 of the scan finished it says it's detected 90 spyware 'bots that neither Spybot Search and Destroy or Adaware found in a recent scan. WTF?

Four viruses so far that a Symantic virus scan did not detect YESTERDAY! AGAIN, WTF?!
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 01:47 AM
Response to Reply #1
2. Panda Software is top of the line
I wouldn't have posted the link if I weren't confident it was safe. I say this as a computer repair professional who gets a large percentage of my income from cleaning computer virii off machines.
Printer Friendly | Permalink |  | Top
 
Stephanie Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 01:49 AM
Response to Reply #1
4. Panda is legit - no worries
And thanks for the heads up, I am running Symantec scan now just in case.
Printer Friendly | Permalink |  | Top
 
mike_c Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 02:00 AM
Response to Reply #4
5. damn, I just renewed my Symantic subscription about a month ago...
...so this really pisses me off!
Printer Friendly | Permalink |  | Top
 
Stephanie Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 02:27 AM
Response to Reply #5
6. Symantec is the best
You're in good shape.
Printer Friendly | Permalink |  | Top
 
Carla in Ca Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 02:35 AM
Response to Reply #4
8. Stephanie, I've got a question for you
Today I got a window saying my system had recovered from a fatal error and to send report to MS. That web page said to do a live update (Norton) but it said all files were current. What does that mean?

Thanks, Carla
Printer Friendly | Permalink |  | Top
 
Stephanie Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 02:37 AM
Response to Reply #8
9. a computer person will answer you
I have no clue
Printer Friendly | Permalink |  | Top
 
TaleWgnDg Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 01:49 AM
Response to Original message
3. www.commentwire.com . . . January 25, 2006
http://www.commentwire.com/article_news.asp?guid=20856A5C-3952-4F2C-913A-1E963F902D41

BlackWorm Preps to Wipe Drives
25th January 2006
By Staff Writer
Update your users' anti-virus signatures. An email worm known to have infected three quarters of a million computers will start deleting data on February 3.

Known as BlackWorm, the malcode has been spreading via email since the weekend. It generally arrives as a .pif or .scr attachment, masquerading as a porno picture.

Once installed, it waits until the 3rd of the month, then attempts to delete files that have extensions including .doc, .xls, .ppt, .pdf, .rar and .zip -- basically, the formats in which most Windows users have their most important data.

Antivirus companies have been able to track the spread of the worm because BlackWorm, once installed, attempts to connect to a counter at a publicly accessible web site. At the time of writing, the counter had clocked up over 700,000 hits.

According to the SANS Institute's Internet Storm Center, one way to discover whether a machine on your network has been infected is to check if any machine has connected to any URL at "webstats.web.rcn.net" without a referrer field in the HTTP header.

The worm is also known as Kama Sutra. All the major antivirus software vendors already offer signatures for this malcode.

http://www.commentwire.com/article_news.asp?guid=20856A5C-3952-4F2C-913A-1E963F902D41
.
Printer Friendly | Permalink |  | Top
 
Stephanie Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 10:02 AM
Response to Reply #3
10. How would you check that?
How do you find out if your machine has connected to that site?
Printer Friendly | Permalink |  | Top
 
Desertrose Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Feb-01-06 02:28 AM
Response to Original message
7. I love my Mac ..............n/t
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 16th 2024, 06:30 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (01/01/06 through 01/22/2007) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC