Jump to content

Recommended Posts

Posted

Malware researchers from Panda Security warn of a new worm, which locks all documents, presentations or emails found on infected computers with a password.

 

Dubbed Clippo.A, the worm copies itself as PICTURE.EXE and SOUND.EXE to all folders on the system, as well as to removable drives or network shares where it has write permissions.

 

Its payload involves dropping a file called FILE.EXE in the root of the C: drive and adding a "load=c:\film.exe" startup registry entry under HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows.

 

Most importantly, the worm it sets a 721709031350 password to any Word document, PowerPoint presentation or Outlook email it finds.

 

Malicious programs, that block access to important files or operating system features usually ask for money in order to restore normal functionality.

 

Such programs are collectively known as ransomware,but this doesn't appear to be the case with this threat.

 

"[…] The purpose of this worm is not to obtain financial gains but just to annoy users," the Panda Security researchers note.

 

Clippo stands to show that even though it is a rare occurrence these days, file damaging malware is not extinct.

 

Clippo affects Windows 2003 and XP, as well as previous versions of the operating system that are no longer actively supported by Microsoft.

 

It can be rendered inactive by manually removing the registry entry and deleting the c:\file.exe file, but a full system scan with a capable and up-to-date antivirus program is highly recommended.

 

The network shares accessible from an infected computer and all removable storage devices plugged into it should also be scanned.

 

 

Source:

New Worm Locks Documents with Password - Softpedia

Member of:

UNITE

  • 2 weeks later...
  • Replies 1
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted
Anti-Executable will kill these .EXE-files immediately in my winXP-system, while my reboot will undo any change on my partition-C and that will be the end of this miserable Clippo-worm and I won't even notice it.

ErikAlbert - "Simplicity is always brilliant" - "Every software sucks, some softwares suck more than others."

Security : FirstDefense-ISR + Anti-Executable + Sandboxie + ShadowProtect - no scanners, no cleaners.

My security doesn't recognize malware like scanners, malware is removed because it changed something. :cool:

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...