Technology Blog

W32/Hairy-A Worm Targeting The Fans Of Harry Potter

harry potter virus

Sophos the world leader in IT security and control solutions had recently announced the computer worm W32/Hairy-A that is taking advantage of the worldwide Harry Potter fans to infect PCs around the globe.


The W32/Hairy-A worm is spreading itself as a copy of the eagerly-anticipated novel Harry Potter and the Deathly Hallows, which releases worldwide on July 21.


Once this virus is in the user's system, it copies itself onto attached USB memory drives so it can spread to any other PCs it is connected to.
A file called 'HarryPotter-TheDeathlyHallows.doc' can be found on infected PCs and once opened the only words inside are: Harry Potter is dead.


These are the few symptons of this deadly virus:

  • It creates a number of new Windows users on the computer which are named after the main characters in JK Rowling's popular books including Harry Potter, Hermione Grainger and Ron Weasley.
  • Logging in to any of these new users a message will sounds like it appeared from the evil Lord Voldemort himself can be seen: "Read and repent, the end is near, repent from your evil ways O Ye folks lest you burn in hell . . . JK Rowling especially".
  • Whenever infected users open Internet Explorer they will find their home page has been re-directed to an Amazon.com web page selling the spoof book Harry Putter and the Chamber of Cheesecakes.

The W32/Hairy-A worm does not spread via email. It infects you when you attach an already-infected USB drive and allow it to auto-run. Some media are claiming the email element, but there is no mention of that on the Sophos website.

Sunday, July 01, 2007 written by