Sircam Worm: Crawling Fast but Easily Crushed
Curiosity could kill your computer, but quick deletion will spare your files and your correspondents.
Frank Thorsberg, PCWorld.com
Sircam is a tricky e-mail worm that's trying to wriggle its way into PCs all over the world, but you can kill the cyber beast with one keystroke before it can harm your system.
The Sircam worm, first detected in mid-July, is replicating at a rapid rate, say Internet security experts. It's likely you could have a version of it sitting in your e-mail box right now.
"It's not the worst, but it's one of the top ones," says Vincent Weafer, director of the Symantec Anti-Virus Research Center. "On a 1-5 scale, it's rated a 4. It's a global epidemic and it's certainly matching some of the things we've seen like the Love Bug and Melissa. It's a very virulent virus with global impact."
The Sircam worm arrives in an infected attachment to an e-mail message. The e-mail text message comes in several slight variations, but here's a typical example: "Hi how are you. I send this file in order to have your advice. See you later. Thanks."
Use your delete button to get rid of this message (and the attachment, which you shouldn't touch), the experts say. It's a good idea to delete any other suspicious e-mail from anyone you don't know, especially if there's an attachment.
If you don't, you're likely to send the worm squirming down another network path, and find hassles on your hard drive as well. When you open an attachment infected by Sircam, it worms its way into your Outlook address book. The worm chooses a file on your own hard drive to infect and send it as an attachment to its next correspondents. Then it trashes files on your hard drive, and slows down your PC.
Solutions Available
Antivirus vendors, of course, urge you to keep your virus definitions current. All the major vendors have updated their programs to identify and nullify the Sircam worm.
But if your PC is already infected, you can obtain a free tool to remove the virus from your system from several computer security companies. Symantec is providing a Sircam removal tool. Another tool is available from McAfee, at its Avert antivirus center. Panda Software also provides a Sircam extraction tool.
Every e-mail user has the power at their fingertips to stop Sircam and other worms that arrive in online mail--by simply hitting the "delete" key. But the originators of these worms are counting on e-mail recipients' curiosity to override their common sense.
Hooked By the Worm
Mary Huhn wishes she'd used her delete button sooner. Huhn writes the "Surfer gURL" technology column for the New York Post. She received a Sircam worm in an e-mail message a few days ago, and her PC soon began sending out infected e-mail messages to people in her address list.
"It's awful. It's bad news," Huhn says. "I've never been caught by virus before. I think that if I had one thing to say, it would be: 'If you are getting e-mail from someone you haven't heard from in a long time or someone you do not know, don't open any attachments.'"
The Sircam worm brings another threat--one of privacy invasion. PC World contributing editor Steve Bass received an infected message from Huhn. He didn't open the attachment, but he examined it closely enough to see that it contains a confidential document that included another newspaper employee's Social Security number. Another infected e-mail to Bass contained details of a confidential employment agreement.
This occurs because the Sircam worm takes an actual random file from the hard drive of its recipient and converts it to an infected executable file that will continue to spread the worm.
The e-mail messages "are from someone you may know and they are using subject lines based on the document itself," says Symantec's Weafer. "People have said they got confused over this and just clicked on it, to their own detriment."
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
The Best of PC World
Solve Tech Issues Fast
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Antivirus Software
Norton AntiVirus 2009 (Full Product)Price: $14.84
VirusScan Plus 2009 - 3-User (Full Product)Price: $4.00
Anti-Virus 2009 (Full Product)Price: $17.85
VirusScan Plus 2009 (Full Product)Price: $4.00
McAfee VirusScan Plus 2008 (Full Product)Price: $3.23
Mcafee McAfee 2009 VirusScan Plus- 1 User Download Version (VSF09E001RKA)Price: $12.27
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


