Baba worm pretends to clean up PCs

By Dan Ilett, Special to ZDNet
21 January 2005 09:40 AM
Tags: worm, virus, exploit, fix, baba, evidence, cleaner, sopho
The latest version of the Baba worm claims to clean porn off PCs, but it's just a 'dirty trick', say antivirus experts.

Antivirus companies have found a mass-mailing worm that tries to spread by fooling users into believing that they have pornographic content on their PCs.

The Baba-C worm travels by email and includes the message "Windows Evidence Checker has found XXX material on your computer", but does not actually look for porn. The email claims that a user can clear their PC of this material by running a program called "Evidence Cleaner", attached to the mail. When activated, this program runs malicious code that allows hackers access to their data.

"Many people are worried about the adult material that inhabits areas of the Internet, and don't want it to reach their PC," said Graham Cluley, senior technology consultant for Sophos. "It's also clear that the Internet is widely used for accessing hardcore sexual material. Either way, many people want to ensure that their PC contains no evidence of pornographic content, and may be tempted to follow this email's instructions if they receive this worm. The Baba-C worm uses a dirty trick."

Sophos said that the email carrying the worm has the following characteristics:

"Subject: Important! XXX sites found on your computer!

Message body:

Windows Evidence Checker has found XXX content on your computer.

You can hide your activities with Evidence Cleaner service. To run Evidence Cleaner click to quick shortcut attached.

Warning! Your copy of Evidence Cleaner will be expired after 7 days. Today you can register for FREE. Please check attached instructions for more details."

By Thursday morning, Sophos had seen only a small number of copies of Baba-C.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured