Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Weekly Brief
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Worms

Microsoft Warns of File-Trashing Worm

Security advisory issued, but experts think danger not as great as originally reported.

Robert McMillan, IDG News Service

Tuesday, January 31, 2006 1:00 PM PST
Recommend this story?

Microsoft has published a security advisory warning Windows users of a file-trashing worm that has been circulating via e-mail for several weeks. The worm, which is programmed to destroy a wide variety of files on the third day of every month, has been circulating since mid-January, and is estimated to have infected between 250,000 and 300,000 systems worldwide.

Security researchers have given the worm a variety of names. Microsoft calls it Win32/Mywife.E@mm, but it is also known as Nyxem, Blackdoom, W32.Blackmal.E@mm, Tearec, and Kama Sutra. And while there have been reports that the malicious software has infected millions of computers, Microsoft believes that the attack is "much more limited and is not in the range of millions at this time," according to the Microsoft security advisory, released Monday.

In fact, several security researchers believe that the Nyxem threat has been overstated. "There's been way more attention given it in the media than it deserves," said Russ Cooper, a senior information security analyst at Cybertrust in Herndon, Virginia. The dramatic nature of this worm's behavior, with its file-destroying instructions, and inflated reports of infections have helped fuel media interest, he said.

Watch Out for Feb. 3 If Infected

Between 250,000 and 300,000 PCs have been infected, estimates Johannes Ullrich, chief research officer for the SANS Institute. However, that number represents a very small number of total Internet users, Cooper said. "How many people do you think had their hard disks fail yesterday?" he asked. "Probably a number as significant as one eighth of 1 percent.... It had nothing to do with a worm or a virus. I'm not saying [300,000] is not large number, but it's not like it is everybody in the city of Columbus, Ohio."

For those who are infected, however, Friday, February 3, will be a long day. On that day the worm will overwrite a wide range of files, including Word documents, Excel spreadsheets, PowerPoint presentations, and .pdf files, replacing their contents with the phrase: "DATA Error [47 0F 94 93 F4 K5]," Microsoft said.

Microsoft's advisory tells customers to use up-to-date antivirus software, most of which can detect the Nyxem infection, and to use caution before opening unknown e-mail attachments.

How It Works

For a PC to become infected by Nyxem , a user must first click on a PIF (Program Information File) file attached to an e-mail, which is typically blocked by corporate antivirus software, according to Cooper. "If you're letting it through and you're a company, then you probably don't have antivirus. So you've already got a problem." PIFs are data files used to help programs written for Microsoft's pre-Windows DOS run in a Windows environment.

Nyxem does not rely on a Windows vulnerability, but instead uses "social engineering" techniques to spread, tricking users to click on files that promise racy content like "Miss Lebanon 2006" or "School girl fantasies gone bad," according to security researchers.

Ullrich agreed that the majority of users do not need to worry about Nyxem. "The story here is if you are hit, you do have other vulnerabilities than this problem," he said.


Recommend this story?

Comments
HP Ink Center
Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...
CDW Solution Center
Deliver speed and scalability in your storage systems. Find out how at the CDW Solution Center.
Asus Notebook Center
Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more at the Asus Resource Center.
Intel Processor Technology
Which Intel Processor is Right for You?Centrino, Core 2 Duo, Core 2 Quad, Core 2 Extreme? Check out the Intel Technology Center for more info...
Are you a gamer?Visit the Intel's Gaming section for the latest downloads, hottest gaming events and to learn about Intel & Gaming.
See what Intel can do for Vista...Discover how Windows Vista technology work in the benchmarks with Intel Centrino processor technology.
VoIP Web Demo
Join Altigen for a Live Web Demo and learn how VoIP technology can improve your business communications.
The Future Sales Force - A Consultative Approach
This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ.
Latest News
Samsung Electronics will unveil this weekend the first prototype of a new LCD (liquid crystal display) technology that won't... 16-May-2008
With all the time spent on the road, most drivers consider their cars to be their second homes. Reaching their primary home... 16-May-2008
Internet users in China have begun expressing solidarity with the victims of Monday's earthquake via their instant messaging... 15-May-2008
Sony has promoted a senior executive at its U.S. games studio to lead its global studios, it said Friday. 15-May-2008
Fujitsu has developed a prototype electronic paper screen that tackles one of the technology's biggest weaknesses: the amount... 15-May-2008
The One Laptop Per Child Project and Microsoft plan to make both Windows and Linux available on a version of the project's XO... 15-May-2008
Yahoo has responded to investor Carl Icahn's threat to take control of Yahoo's board and force it back to the negotiating... 15-May-2008
Billionaire investor Carl Icahn's proxy fight for Yahoo is aimed at reigniting merger talks between the Internet company and... 15-May-2008
When Apple ships its iPhone 2.0 update--and the accompanying App Store for distributing third-party software for the... 15-May-2008
Amit Singh thought something was missing from OS X. The Google engineer--and author of Mac OS X Internals--took a look at what... 15-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)