Overclockers Australia!
Make us your homepage. Add us to your bookmarks  
Major Sponsors:


News
Current
News Archive

Site
Articles & Reviews
Forums
Wiki
Image Hosting
Search
Contact

Misc
OCAU Sponsors
OCAU IRC
Online Vendors
Motorcycle Club


Hosted by Micron21!
OCAU News
Nyxem.E (9 Comments) (link)
 Friday, 3-February-2006  11:27:19 (GMT +10) - by Agg

There's a nasty virus doing the rounds - unfortunately we only heard about it just now and today is the day it goes mental deleting things. -=N0N@ME420=- sent word that it's being covered on F-Secure's Blog and they have a free tool to help disinfect your machine.

The worm has a dangerous payload. If the date is equal to 3 (3rd of February, 3rd of March, etc) and the worm's UPDATE.EXE file is run, it destroys files with those extensions on all available drives:

*.doc
*.xls
*.mdb
*.mde
*.ppt
*.pps
*.zip
*.rar
*.pdf
*.psd
*.dmp

The files' contents get replaced with a text string "DATA Error [47 0F 94 93 F4 K5]". The payload is activated 30 minutes after the worm's file UPDATE.EXE is loaded into memory (basically 30 minutes after logon). We can confirm that the payload works at least on Windows XP. When the payload is activated, the worm enumerates all logical drives and damages files on them in a loop.


Virus writers: get a life.



Return to OCAU's News Page

All original content copyright James Rolfe. All rights reserved. No reproduction allowed without written permission.