The newly discovered Reeezak worm is threatening computer systems around the world with reports of damage inflicted to computers in Europe and the US. The worm, which was first reported in the UK on Wednesday, enters a computer as an e-mail message in Microsoft's Outlook e-mail program with a subject line "Happy New Year" and with an attachment, "Christmas.exe," in order to fool potential victims into believing the program is an electronic Christmas card.
The worm has the ability to disable keyboards on the infected computers and can also delete all of the files found in the Windows System Directory, rendering the computer inoperable. Furthermore, like many such worms that have abounded in recent months, the malicious software spreads by re-mailing itself to all of the addresses in Outlook's address book and may attempt to redirect the PC to a Web page that will install the bug, explained John Mulholland, manager of information security and consulting services with Systemhouse Technology in Dublin.
Another consequence of the worm would change the name of infected computers to "Zaker," Mulholland explained. He went on to say that part of the danger of the worm is its holiday theme. "We thought that due to the time of year, it might be a bit more dangerous because people might let their guard down."
Ian Hameroff, director of antivirus solutions at Computer Associates, echoed Mulholland's advice, urging users to keep their guard up at all times. "Be on the lookout for suspicious messages -- they may be bearing gifts that you don't want," Hameroff added.
Despite the danger that the bug poses, McAfee.com has given it a low risk rating and Symantec rated the worm "level 2" (of 5). Meanwhile, Computer Associates International assigned a medium-to-high risk to the bug, which is also known as W32/Reeezak.A@mm, W32/Zacker.C@mm and W32.Maldal.C@mm.
With the first word misspelled, the message Reeezak carries in the e-mail body reads:
"Hii
I can't describe my feelings
But all i can say is
Happy New Year :)
bye"
For more information visit http://www.systemhouse.com/
|