Worm tricks users with fake porn warning

Article

Worm tricks users with fake porn warning

Bill Brenner, News Writer

If you get an e-mail about a pornographic ghost in your machine, don't click the attachment. It's really a fake warning designed to infect computers with the latest Baba worm.

Lynnfield, Mass.-based antivirus firm Sophos offered that warning in an advisory this week. The firm said W32.Baba-C tries to fool users into believing their PC is infested with adult content. It then offers to run a program that will hide it. In reality, there is no X-rated content on the computer, and clicking on the attachment will unleash the worm.

Baba-C will then attempt to forward itself to other e-mail addresses and open a backdoor that attackers could use to access the system.

"This arrives in an e-mail disguised as a warning that 'Windows Evidence Checker' has found pornographic content on your computer," said Graham Cluley, senior technology consultant for Sophos. "Users are then told the adult material can be hidden by running a program called 'Evidence Cleaner.' So far this doesn't look like anything widespread, but it's another example of why people should be very leery of unfamiliar attachments."

For enterprises, Cluley said, "the danger is that people will see the message, panic and click the attachment to clean up their computers so they don't get in trouble at work. People might click before they think."

His advice: "Don't panic when you see a message that pornographic material has been found on your

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

computer. And, as I said, be very wary of unfamiliar attachments."

What it looks like
If you get an e-mail with Baba-C attached, you'll see the following characteristics:

  • Subject: Important! XXX sites found on your computer!
  • Message body: Windows Evidence Checker has found XXX content on your computer. You can hide your activities with Evidence Cleaner service. To run Evidence Cleaner click to quick shortcut attached. Warning! Your copy of Evidence Cleaner will be expired after 7 days. Today you can register for FREE. Please check attached instructions for more details.

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.