August 3, 2001
ISEC
●This is the summary of Computer Virus Incident Reports of July 2001 complied by IPA:
Information-technology Promotion Agency.
1,738 reports (1,335 reports in June) were submitted to IPA in July.
It is about 2.5 times more than the number, which is 700,in July 2000.
Virus that destroys data such as W32/Magistr that increased in June and W32/Sircam
that appeared in middle of July were recognized as the major effective virus. The
percentage of actual harm was 19.8% in total reports in July, which counted 8.3% up
compared with the number in June. It hasn’t seemed that the number increased compare to
each previous month since February.
Top ranks of reported virus that destroys data
| Number of reports (Rate of actual harm) |
Effects
such as eradication |
||
| June | July | ||
| W32/Sircam | ――― | 520(*1) (23%) |
Erase all files in C drive (October 16) Filling free area in hard disks up with data to make it impossible to use. |
| W32/Magistr | 253 (9%) |
202 (16.3%) |
Destroy the data of BIOS and CMOS. (One month after it infects.) |
| VBS/Haptime(*2) | 21 (10%) |
35 (20%) |
Erase files of which suffix is EXE., DLL.. (It happens when the total number of month and day becomes 13.For example, August 5.) |
(*1) (The total number of reports from 21st to 31st of July 2001)
(*2) It infects even if you open emails. Measure: Setting up Internet Explore properly. Refer to "Information on Haptime." http://www.ipa.go.jp/security/topics/newvirus/haptime/html (Japanese)
Huge damage from new virus"W32/Sircam
When this virus sends emails the name of its subject and attached file will sound just normal so that users open it without any suspicious then they get infection. Below there will be shown the detail. Do not open the attached file no matter when you get the following email. The percentage of its actual harm was over 20%, which is very serious. The number of reports was 520,which is the biggest number of reports for new virus ever since we started correcting. (cf. We got 437 reports for Navidad in November 2000.) It has severe infection ability. Virus sends infected emails to the following address. *Every registered address that belongs to Outlook and Outlook Express. *Address that is on the Web page that you have been. Flowing out personal information: This virus will send emails with the attachment file that they will have already altered the files of Word or Excel in my document.
PS,this is the case of using image of E-mail software under Japanese.
Warning for this month: Recommending to do back up often
―Destroyed data cannot be repaired by Anti-virus software. ―
Virus that destroys data such as W32/Sircam and W32/Magistr will alter a part of important files and registry etc on the system when you try to open the attachment 0file that infected by those viruses. Then destroy data. Anti-virus software cannot repair and there is no way of recovering the previous state except that you get data from back up. If you often take back up data and programs etc, you can avoid losing important data.
For questions, please contact:
IPA Security Center (IPA/ISEC)
(ISEC: Information-technology SEcurity Center)
Phone:03-5978-7508
E-mail: isec-info@ipa.go.jp
Virus Emergency Call:03-5978-7509
URL:http://www.ipa.go.jp/security/
Computer Virus Incident Reports for July, 2001(full report)
Copyright © 2001 Information-technology Promotion Agency, Japan. All rights reserved.