NEWS The appearance and spread of viruses throughout the tech-enabled world is rapidly becoming par for the course for home and corporate users. However, occasionally, a virus contains a more interesting wrinkle than being named after a tennis player or teen-punk idol. For example, tech security companies are warning of a new virus designed to attack a version of the already-existing Yaha virus. Trouble is, the new virus may also crash your computer. The W32.Sahay.A@mm virus arrives as an attachment called "mathmagic.scr", with the subject "Fw: Sit back and be surprised..." It attempts to attach itself to all the .exe file in the Windows and C:\Program Files\Mirc\download folders, but due to bugs in the software may crash the computer or corrupt files in these folders. The Sahay virus also checks the computer for characteristics of the W32.Yaha family of worms, and if any are found attempts to remove them and then displays this message: Title: Exchange viruses? Message: Hi there.. it seems you were infected with Yaha.k. That worm however, written by an idiot who sPeLlS lIkE tHiS,abused my website and got me toreceive the complaints. Therefore, I have just disinfected you.Don't worry tho.. as I didn't wanna steal from you, I gave you this virus (Win32.HLLP.YahaSux) in return :) Greetz, Gigabyte [Metaphase VX Team] The worm then sends itself to all contacts in Outlook's Address book and restarts the computer. Clive Wainstein, pre-sales engineer at Trend Micro, told ZDNet Australia that in five years working in the antivirus field he had never seen a virus attempt to delete another one. "The hacker community on the whole is a very competitive, small-knit community," said Wainstein. "It doesn't surprise me that [the Sahay writer] has done this, he's trying to promote his handiwork." According to David Banes, regional manager for security company Symantec, Sahay is not the first virus designed to attack another virus, but it is the first one for quite a while. It is more usual to receive a hoax email claiming an existing, necessary file is a virus, such as the Jdbgmgr.exe hoax, which claims a file is a virus when it is really a debugger register for Java. Symantec has posted information about removing the virus on its website. "The idea of a virus that removes a virus has been tossed around for a while, but antivirus companies tend to frown on it," said Banes. "Either way you're running code on someone else's machine without them knowing about it."
Antivirus virus on the loose
These crazy virus writers...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
Defeating spam in enterprise email
Enterprises should expect the onslaught of spam to continue. Botnets aren't going away. Criminal syndicates won't...
-
DDoS attack protection: Five best practice tips
Cybercriminals are smarter, stealthier and more adaptive. Traditional defence methods are no longer able to match the...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




