Welcome to BrightSite by bright.net Internet Services
Online Signup
Nitro Dial
Web Mail
MyMail

bright.net Anti-Virus Page
Navigation
Recent Entries
Links
Firefox
Virus News

Blackmal Destroys Personal Files on the 3rd of Each Month!
Blackmal Destroys Personal Files on the 3rd of Each Month!


How It Infects:
Blackmal spreads as an attachment to an infected email.

Read More on How To Avoid Infection:
Avoid emails with the following characteristics:

Subject: (One of the following subjects)

* *Hot Movie*
* A Great Video
* Fw:
* Fw: DSC-00465.jpg
* Fw: Funny :)
* Fw: Picturs
* Fw: Real show
* Fw: SeX.mpg
* Fw: Sexy
* Fwd: Crazy illegal Sex!
* Fwd: image.jpg
* Fwd: Photo
* give me a kiss
* Miss Lebanon 2006
* My photos
* Part 1 of 6 Video clipe
* Photos
* Re:
* School girl fantasies gone bad


Message: (One of the following messages)

* Note: forwarded message attached. You Must View This Videoclip!
* >> forwarded message
* Re: Sex Video
* i just any one see my photos.
* It's Free :)
* The Best Videoclip Ever
* Hot XXX Yahoo Groups
* F****n Kama Sutra pics
* ready to be F****D ;)
* forwarded message attached
* VIDEOS! FREE! (US$ 0,00)
* What?
* i send the file.
* Helloi attached the details.
* Thank you
* the file i send the details
* hello,
* Please see the file.
* how are you?
* i send the details.


Attachment: (One of the following attachments)
* 007.pif
* 392315089702606E-02,.scR
* 677.pif
* Adults_9,zip.sCR
* Arab sex DSC-00465.jpg
* ATT01.zip.sCR
* Attachments[001],B64.sCr
* Clipe,zip.sCr
* document.pif
* DSC-00465.Pif
* DSC-00465.pIf
* eBook.pdf
* eBook.PIF
* image04.pif
* New Video,zip
* New_Document_file.pif
* photo.pif
* Photos,zip.sCR
* School.pif
* SeX,zip.scR
* Sex.mim
* Video_part.mim
* WinZip,zip.scR
* WinZip.BHX
* WinZip.zip.sCR
* Word XP.zip.sCR
* Word.zip.sCR
* 04.pif
* DSC-00465.Pif
* DSC-00465.pIf
* image04.pif
* 3.92315089702606E02.UUE
* Attachments[001].B64
* Attachments00.HQX
* Attachments001.BHX
* eBook.Uu
* Original Message.B64
* Sex.mim
* SeX.mim
* Video_part.mim
* WinZip.BHX
* Word_Document.hqx
* Word_Document.uu




What It Does:
# Copies itself to your Windows system directory.

# Adds itself to your computer's registry so that the infection runs when Windows starts.

# Modifies your computer's registry to hide its presence.

# Disables security-related programs on your computer by:

* Deleting executable files in security-related folders.

* Closing windows that have names of security-related programs in the title bar.

* Deleting security-related keys from your registry.

# Harvests email addresses from your computer and spreads itself to those addresses.

# NEW UPDATE! Attempts to destroy personal files on your computer any time the date reads the third of the month (January 3rd, February 3rd, etc.). The worm targets files with the following extensions:


Vulnerable Operating Systems:
Windows 95/98/Me/NT/2000/XP

February 1st, 2006
bright.net does not support nor endorse these programs but have found some of them helpful. Many of the programs and links found on this page are for third-party applications and are to be used at your own risk. Should you encounter problems with the tools, you may need to consult a computer technician for further assistance.