Advertisement
Promo

Security threats Toolkit

Baba worm pretends to clean up PCs

Dan Ilet ZDNet.co.uk

Published: 20 Jan 2005 12:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus companies have found a mass-mailing worm that tries to spread by fooling users into believing that they have pornographic content on their PCs.

The Baba-C worm travels by email and includes the message "Windows Evidence Checker has found XXX material on your computer", but does not actually look for porn. The email claims that a user can clear their PC of this material by running a program called "Evidence Cleaner", attached to the mail. When activated, this program runs malicious code that allows hackers access to their data.

"Many people are worried about the adult material that inhabits areas of the Internet, and don't want it to reach their PC," said Graham Cluley, senior technology consultant for Sophos. "It's also clear that the Internet is widely used for accessing hardcore sexual material. Either way, many people want to ensure that their PC contains no evidence of pornographic content, and may be tempted to follow this email's instructions if they receive this worm. The Baba-C worm uses a dirty trick."

Sophos said that the email carrying the worm has the following characteristics:

"Subject: Important! XXX sites found on your computer!

Message body:

Windows Evidence Checker has found XXX content on your computer.
You can hide your activities with Evidence Cleaner service. To run Evidence Cleaner click to quick shortcut attached.
Warning! Your copy of Evidence Cleaner will be expired after 7 days. Today you can register for FREE. Please check attached instructions for more details."

By Thursday morning, Sophos had seen only a small number of copies of Baba-C.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
59 out of 111 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

Post a comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters