Thursday, February 02, 2006

VIRUS ALERT: BlackWorm (MyWife.d)

AT-RISK SYSTEMS:
PRIORITY: URGENT/SEVERE

BlackWorm is an email worm that uses its own SMTP engine to spread through e-mail and open network shares. Blackworm is also known as BlackWorm/Nyxem/Blackmal/Blueworm/Grew. This vulnerability has been classified as "High Risk." Computer users should take appropriate action to be protected against this worm.

Using its own SMTP engine, BlackWorm spreads using different subjects, email bodies and attachments. The attachments sent by the worm may contain the following extensions: pif, scr, mim, uue, hqx, bhx, b64, and uu.

On February 3rd , tomorrow, computers that are infected with BlackWorm will have the following file types overwritten by the worm: DOC (MS Word), XLS (MS Excel), MDE, MDB (MS Access), PPT (MS PowerPoint), PPS (MS PowerPoint), RAR, PDF (Adobe Reader), PSD (Adobe Photoshop), DMP, ZIP (Compressed Archive). The files are overwritten with an error message ('DATA Error [47 0F 94 93 F4 K5]'). It has already infected more than 300,000 computers worldwide.

I strongly suggest backing up important files and updating your anti-virus software as soon as possible to keep from losing your files. Contingency plans and more information available from LURHQ Security.

No comments: