High-risk virus fowards hard disk content, paralyses in-boxes
E-mail users face the possibility of going offline temporarily following a growing number of reports of a new, debilitating computer virus which was detected late last week.
National ICT Security and Emergency Response Centre (Niser) assistant director Azrina Raja Osman told malaysiakini today the first complaint on the virus, known as SirCam, was received on Saturday.
"Since then we have continually received complaints," said Azrina, who declined to provide detailed figures on the number of computers affected in the country.
SirCam, believed to have originated in Latin America, spread from Europe and the United States to Asia and comes in the form of an e-mail attachment.
Once the attachment is opened, the virus will run through the recipient's e-mail address book or the computer's temporary Internet cache and automatically forward itself to every name found.
Far more disastrous than the previous e-mail viruses, SirCam forwards itself to more victims together with whichever file it has randomly seized from the computer's 'My Documents' folder.
Many users hit by the virus claimed that their private and confidential material had been forwarded to total strangers because of the virus.
The virus changes its e-mail subject line and body text constantly but often starts with 'Hi! How are you?' and ends with 'See you later. Thanks'.
Top priority
Azrina said SirCam had been classified as a 'high-risk virus', adding that monitoring the virus is currently a top priority.
She said Niser had taken several measures to deal with the outbreak of the virus. These included sending alerts to Internet users on Niser's mailing list, and publishing advisories on their [#3] website[/#] and through the national media.
E-mail users are advised not to open attachments from an 'unknown and suspicious source' (or even familiar sources who may be innocent victims) and avoid opening any attachment ending with either a .bat, .com, .exe, .lnk, .pif or .vbs, she added.
However, she admitted that the virus may lurk for some time until the anti-virus systems in the market are capable of detecting it.
"SirCam will still be around until users' anti-virus software is upgraded. Many major anti-virus vendors will soon release their solutions," she said.
Worm's attacks
Meanwhile, on the computer worm Code Red which was detected last week, Azrina said the situation is under control now.
"We have observed a reduction in attacks by Code Red since yesterday. Before that it was quite severe," she said. Computer worms are a variant of computer viruses.
The New Straits Times daily on Sunday reported that the Malaysian Computer Emergency Response Team (Mycert) had spotted heavy scanning activities on many networks due to the worm's attacks.
According to the report, the Code Red worm resides in a computer's memory to find a vulnerability in the system which eventually grants its access to a main server.
The worm is capable of defacing websites and enables its perpetrator to create, remove and edit content.

