Clusterheadaches.com Message Board (http://www.clusterheadaches.com/cgi-bin/yabb/YaBB.cgi)
New Message Board Archives >> 2006 General Board Posts >> Kama Sutra Worm, etc...
(Message started by: purpleydog on Feb 2nd, 2006, 2:42am)

Title: Kama Sutra Worm, etc...
Post by purpleydog on Feb 2nd, 2006, 2:42am
http://www.theregister.com/2006/02/01/january_virus_chart/




Kama Sutra worm crashes malware chart
The return of the 'trash your PC' virus
By John Leyden
Published Wednesday 1st February 2006 14:13 GMT


Virus authors were hard at work last month creating 2,312 new malware variants - a third higher than December, according to UK-based security firm Sophos. Most of these attacks were financially motivated and designed to steal sensitive information from compromised PCs.

But it was the return of an old-school "trash your Windows PC" worm that captured the most headlines. The Kama Sutra worm (AKA Nyxem-D or Blackworm) first appeared on 18 January posing as an email message offering a variety of salacious content. Users daft enough to fall for this ruse wind up with an infected machine and disabled security software. Worse still, Nyxem-D is also programmed to overwrite files on Friday 3 February.


According to SoftScan, a Scandinavian email filtering firm, levels of infection in the UK and the majority of Europe are very low. The largest number of infections by far is in India, it reports.

Even so Nyxem-D appears at number four in Sophos's chart. Sober-Z remains January's most frequently encountered virus but since the worm is programmed to stop spreading after 6 January it ought to drop off the radar completely in February even though it's doubtless numerous machines will remain infected. Sober-Z stopped spreading in the first week of January but still racked up almost 45 per cent of malware reported to Sophos last month, a stat that illustrates the potency of the attack it unleashed. Sophos reckons that 1.4 per cent or one in 70 emails was viral in January.

Malware laced with offers of smut, as used by the Kama Sutra worm, is a common trick. Another more sophisticated type of attack appeared last month. The Brepibot virus posed as a request for the recipient to check the article and photo for editorial content before it is used in a high profile publication such as the Guardian's Business section. The malware was spammed out with the UK in particular and the US, to a lesser extent, bearing the brunt of the assault, according to SoftScan.

January saw many variants of the Feebs worm emerging. Although none of them got anywhere near the prevalence of the Kama Sutra worm and the like, Feebs was technically sophisticated. Among other features (rootkit, P2P propagation, reporting via ICQ, on-the-fly injection into emails sent by the infected user), the worm uses Javascript to spread, according to an analysis by security appliance firm Fortinet. The worm lies in an encoded string of a Javascript embedded into an .hta document. Whenever run, the Javascript decrypts the worm body, and executes it. The .hta document is then regenerated and bulk mailed to potential victims. ®

January top ten virus chart, as compiled by Sophos:

  1. Sober-Z
  2. NetSky-P
  3. Zafi-B
  4. Nyxem-D
  5. Mytob-BE
  6. Mytob-FO
  7. NetSky-D
  8. Mytob-EX
  9. Mytob-C
 10. Mytob-AS



http://avast.com/

This is the best anti-viral software I've used. In fact, it caught a virus on my system tonight, and held it until I could do a boot scan and get rid of it. It updates daily, or even several times daily, depending on the current threat, and is easy to install. You'll never go back to Norton, and it's free. Try it. (Just remember, you can't run Norton and this at the same time.)


[smiley=smokin.gif]

Title: Re: Kama Sutra Worm, etc...
Post by Woobie on Feb 2nd, 2006, 7:40am
Dammit PD...........

I thought this thread was gonna be FUN! ;;D




Actually - it COULD have been - I just  cant understand it.  For all I know it IS about sex........

Maybe THAT"S my problem. :-/

Title: Re: Kama Sutra Worm, etc...
Post by JenniferD on Feb 2nd, 2006, 7:55am
Thanks for the heads-up. I'd almost welcome a pc-trashing virus at this point. This piece of crap I have is useless anyway.

Title: Morning!
Post by Richr8 on Feb 2nd, 2006, 8:47am
There is a great site out there called
http://www.techsupportforum.com/?source=overture
that has a lot of great free information and links about detrashing you computer of adware and spyware that make them run like c__p!  With all of the garbage (adware/spyware/keyloggers viruses ,etc.)  on the internet and that comes to us through e-mail, it's not long before even good PC is running like a snail.  These folks are very helpful at keeoping you pc tuned up and it's all free.  It's the only way I know to stay ahead of all the malicious stuff going on out there.

Title: Re: Kama Sutra Worm, etc...
Post by Melissa on Feb 2nd, 2006, 10:09am
You mean this ISN'T a sex thread?!?!

Well wtf?

Purps, you aren't living up to your name!!!

[smiley=laugh.gif] ;;D ;)

Title: Re: Kama Sutra Worm, etc...
Post by Drk^Angel on Feb 2nd, 2006, 10:58am
Avast! is great, but I learned a lesson about it recently.  I've been a long time user of Norton, and so was used to how Norton would catch a java or activeX (blah) exploit, but still allow the web page to be accessible (useful when you visit some of the sites I visit, and I'm not talkin' about just the porn sites either).  Well... Avast! don't seem to work in that way (or at least the way I currently have it configured doesn't), so like a newb, when Avast kept blockin' one site I was tryin' to access, I turned off Web Shield, thinkin' the Standard Shield would pick up the exploit when the browser downloaded it for execution.  Huge mistake!  OY!  Took me a whole half an hour to clean the crap out of the system.  Worse infection ever.  Oh well... Could've been even worse... It could've wiped my porn collection.  Then I really would've been pissed.

My theory on PC virii... If you're gonna run Winblows, ya gotta get infected at least once every 7 years.  It's sorta like a booster shot for tetanus or sumptin'... Keeps ya on your toes so that you're ready for the next booster, and lets you verify how well your protections work.

PFDAN................................... Drk^Angel

Title: Re: Kama Sutra Worm, etc...
Post by cootie on Feb 2nd, 2006, 11:13am
Thanks....I saved the site for the avast cuz my Norton is up in May so I have to decide if I want to update online via credit card and RISK what happen'd with McAfee or use sumthin else. I know McAfee is a good product but it wasn't compatable on my other new computer and crashed the brouser and had a heck of a time gettin it back to normal. Had to uninstall McAfee 5 times and then delete files left by hand. But........my bank said they will NOT block McAfee from billing me once a year........huh ? I am afraid to take this route with Norton. They will keep chargeing your card yearly.....I can NOT get rid of McAfee and have emailed and tried to call for over a year now. Been charged twice for a product I don't have and seems to be NOTHING I can do about it. I even filled out an official cancellation of there product off there site and emailed. Sum of this is a repeat to ya'll I know....but......it's just a warning to be CAREFUL with the updateing online cuz you may get stuck with that bill forever !!!! Seems sumone's always out to rain on my parade Pam

Title: Re: Kama Sutra Worm, etc...
Post by sandie99 on Feb 2nd, 2006, 2:27pm
Thanks for the info. :)

Sanna

Title: Re: Kama Sutra Worm, etc...
Post by pattik on Feb 2nd, 2006, 4:19pm

on 02/02/06 at 07:40:10, Woobie wrote:
Dammit PD...........

I thought this thread was gonna be FUN! ;;D


Kama Sutra=good

worms=bad



Clusterheadaches.com Message Board » Powered by YaBB 1 Gold - SP 1.3.1!
YaBB © 2000-2003. All Rights Reserved.