also @ TechSpot: UK's SOCA seizes domain of popular music blog, rnbxclusive.com
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Harry Potter Worm

Thread Tools Search this Thread
  #1  
Old 07-03-2007
Fortify's Avatar
Newcomer, in training
 
Location: Sydney, Australia
Member since: Mar 2007, 28 posts
Harry Potter Worm

There has been a worm going around, disguised as HarryPotter-TheDeathlyHallows.doc. The news article from below was taken from The Australian Daily Telegraph 29 June 2007

Quote:
Harry Potter virus red alert
A NASTY computer worm is taking advantage of the worldwide Harry Potter mania to infect PCs around the globe.

With the release of the last ever Potter book and the premiere of the fifth movie in the franchise, the W32/Hairy-A worm is disguising itself as a copy of the eagerly-anticipated novel Harry Potter and the Deathly Hallows, which releases worldwide on July 21.

Once in the user's system, the worm copies itself onto attached USB memory drives so it can spread to any other PCs it is connected to.

A file called 'HarryPotter-TheDeathlyHallows.doc' can be found on infected PCs and once opened the only words inside are: Harry Potter is dead.

But it doesn't end there.

The worm also creates a number of new Windows users on the computer which are named after the main characters in JK Rowling's popular books including Harry Potter, Hermione Grainger and Ron Weasley.

Logging in to any of these new users and a message which sounds like it appeared from the evil Lord Voldemort himself can be seen: "Read and repent, the end is near, repent from your evil ways O Ye folks lest you burn in hell . . . JK Rowling especially".

In addition whenever infected users open Internet Explorer they will find their home page has been re-directed to an Amazon.com web page selling the spoof book Harry Putter and the Chamber of Cheesecakes.

"Much of the world is waiting with bated breath for the final Harry Potter novel, and the premiere of the new movie is looming too so there is a real danger that muggles will blindly allow their USB flash drives to auto-run and become infected by this worm," says Graham Cluley, senior technology consultant for internet security company Sophos.

"The fact that this worm has been inspired by the tales of a fictional schoolboy wizard doesn't make it a harmless prank.

"A worm like this which infects and tampers with users' computers without their permission is committing a criminal act.

"Someone needs to get a little more sunshine in their diet and put their energies into a more positive pursuit than writing malicious code like this."

Sophos has noticed an increasing global trend for malware authors to spread their destructive code via popular USB memory drives which are used to easily transport digital files.

Users are advised to check the root directory of their USB drives for the suspect Potter files before running their applications or using the drive on another computer.
Samson
  #2  
Old 07-03-2007
beef_jerky4104's Avatar
Banned
 
Location: The Basketball court...
Member since: Jan 2007, 1,094 posts
System specs
That's kind of weird.
  #3  
Old 07-17-2007
captaincranky's Avatar
TechSpot Evangelist
 
Member since: Oct 2006, 7,585 posts
Now, if someone would only...

write a worm that attacks the computers of NBC reality show viewers, particularly "Age of Love", we might be able to work past the outdated notion that two wrongs don't make a right.
  #4  
Old 07-18-2007
jobeard's Avatar
TechSpot Ambassador
 
Location: Southern Calif.
Member since: Apr 2005, 10,835 posts
details of exploit

see this description of the details
Closed Thread

Similar Topics
Topic Replies Forum
Harry Potter and the Half Blood Prince (PC) 8 Gaming
Recently Installed Harry Potter And Goblet Of Fire Game, Wont Play 19 Gaming
Harry Potter Goblet Fire Help!!!! 1 Gaming
Hairy Harry 0 Gaming

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 10:26 PM.