dragon300zx
Feb-02-2006, 07:39 AM
Before reading this little document I put together. GO BACKUP YOUR FREAKIN DATA ALREADY.
New Virus Alert.<o:p></o:p>
<o:p> </o:p>
<st1:place w:st="on">Kama</st1:place> Sutra, My Wife, Blackworm, Nyxem.E, CME-24, ETC.<o:p></o:p>
<o:p> </o:p>
“Some antivirus software can eliminate the virus. Users should make sure their antivirus and antispyware software is up to date and to scan their computers for malicious programs that may have been surreptitiously installed on their machines.
<o:p></o:p>
However, not all antivirus programs are effective. Problems running antivirus software may be one sign your computer has been infected. Joe Stewart of LURHQ says like many recent worms, <st1:place w:st="on">Kama</st1:place> Sutra attempts to disable antivirus software when it is attacking a machine. “
<o:p></o:p>
This nasty little virus, will spread itself through email, it will activate and launch it’s kill attacks beginning Friday February 3<sup>rd</sup>, and on the 3<sup>rd</sup> of every month thereafter. Although it self duplicates, and attempts to neutralize your antivirus software, it’s kill attack is much worse.
“Experts say Windows Office documents, Word documents, Excel spread sheets, and PDFs (portable document format) are among the files that will be "overwritten." That means the data will be changed and corrupted, and the original information will no longer be accessible. Zip files will also be included in this damage.”
<o:p></o:p>
There is no patch from Microsoft that can stop this worm.<o:p></o:p>
<o:p> </o:p>
It is spread through email as attachments, and they are typically emails revolving around <st1:place w:st="on">kama</st1:place> sutra, porn, sex, etc. <o:p></o:p>
<o:p> </o:p>
Do not open emails that you do not know who they are from or what their contents are. Do not open any attachments that you are not sure are safe. This little worm even includes it’s own picture file that shows up in emails claiming that norton’s antivirus has determined the file is not infected. <o:p></o:p>
<o:p> </o:p>
The worm, which also goes by the names Blackworm, Blackmal, and Nyxem, has been spreading since January 16. It is capable of infecting Windows XP, Windows 2000, Windows 98 and Windows ME operating systems.
<o:p> </o:p>
"This is a really damaging worm. This is not one of those worms that is interested in having access to your machine for purposes later on. This worm will really damage your machine," Georgia Tech's Furst said.
<o:p></o:p>
"Unfortunately, there is no way to patch user ignorance, and the way this virus propagates is through user ignorance," he said. (quote from John Stewart of LURHQ Computer Information Security Firm)
Sergile also says home users need to be aggressive about questioning e-mail messages and attachments, even if it appears they are coming from colleagues, friends, or relatives. Many e-mail viruses spread by forwarding themselves to everyone in a user's e-mail address book.
<o:p></o:p>
"So while you might think it is coming from cousin Alice, most likely cousin Alice is not going to send you something that says 'Hey look at these pictures with naked people.' So that should be your first clue that a virus is propagating and you'd be well served to call cousin Alice to let her know that she is [unknowingly] sending out this type of e-mail," Sergile said.
<o:p></o:p>
This is all in all a nasty little bugger that can easily be prevented as long as you use precaution and don’t download emails you shouldn’t be.
As always you should make sure your antivirus software is up to date. This virus has spread mainly to home user’s so you have to check your computers at home or risk loosing all of your data. Even if your antivirus software is up to date thought it may not catch this worm. However there is a free download utility that will. Simply go to:
http://www.f-secure.com/v-descs/nyxem_e.shtml
and download the F-Force Utility and is LATEST.ZIP definitions file.
http://www.f-secure.com/tools/f-force.zip
http://download.f-secure.com/latest/latest.zip (http://download.f-secure.com/latest/latest.zip)<o:p></o:p>
Unzip the F-Force utility into it’s own folder and copy and paste the LATEST.ZIP file into that folder without un-zipping it. Run the f-force.exe file and follow the prompts.<o:p></o:p>
<o:p></o:p>
ALTHOUGH THIS VIRUS IS SET TO RUN ON THE THIRD OF EVERY MONTH IF YOUR COMPUTER’S CLOCK/CALENDAR IS NOT SET PROPERLY OR OFF BY A DAY OR TWO OR MORE THEN THE WORM WILL RUN ON THE DAY IT THINK’S IS THE THIRD.
New Virus Alert.<o:p></o:p>
<o:p> </o:p>
<st1:place w:st="on">Kama</st1:place> Sutra, My Wife, Blackworm, Nyxem.E, CME-24, ETC.<o:p></o:p>
<o:p> </o:p>
“Some antivirus software can eliminate the virus. Users should make sure their antivirus and antispyware software is up to date and to scan their computers for malicious programs that may have been surreptitiously installed on their machines.
<o:p></o:p>
However, not all antivirus programs are effective. Problems running antivirus software may be one sign your computer has been infected. Joe Stewart of LURHQ says like many recent worms, <st1:place w:st="on">Kama</st1:place> Sutra attempts to disable antivirus software when it is attacking a machine. “
<o:p></o:p>
This nasty little virus, will spread itself through email, it will activate and launch it’s kill attacks beginning Friday February 3<sup>rd</sup>, and on the 3<sup>rd</sup> of every month thereafter. Although it self duplicates, and attempts to neutralize your antivirus software, it’s kill attack is much worse.
“Experts say Windows Office documents, Word documents, Excel spread sheets, and PDFs (portable document format) are among the files that will be "overwritten." That means the data will be changed and corrupted, and the original information will no longer be accessible. Zip files will also be included in this damage.”
<o:p></o:p>
There is no patch from Microsoft that can stop this worm.<o:p></o:p>
<o:p> </o:p>
It is spread through email as attachments, and they are typically emails revolving around <st1:place w:st="on">kama</st1:place> sutra, porn, sex, etc. <o:p></o:p>
<o:p> </o:p>
Do not open emails that you do not know who they are from or what their contents are. Do not open any attachments that you are not sure are safe. This little worm even includes it’s own picture file that shows up in emails claiming that norton’s antivirus has determined the file is not infected. <o:p></o:p>
<o:p> </o:p>
The worm, which also goes by the names Blackworm, Blackmal, and Nyxem, has been spreading since January 16. It is capable of infecting Windows XP, Windows 2000, Windows 98 and Windows ME operating systems.
<o:p> </o:p>
"This is a really damaging worm. This is not one of those worms that is interested in having access to your machine for purposes later on. This worm will really damage your machine," Georgia Tech's Furst said.
<o:p></o:p>
"Unfortunately, there is no way to patch user ignorance, and the way this virus propagates is through user ignorance," he said. (quote from John Stewart of LURHQ Computer Information Security Firm)
Sergile also says home users need to be aggressive about questioning e-mail messages and attachments, even if it appears they are coming from colleagues, friends, or relatives. Many e-mail viruses spread by forwarding themselves to everyone in a user's e-mail address book.
<o:p></o:p>
"So while you might think it is coming from cousin Alice, most likely cousin Alice is not going to send you something that says 'Hey look at these pictures with naked people.' So that should be your first clue that a virus is propagating and you'd be well served to call cousin Alice to let her know that she is [unknowingly] sending out this type of e-mail," Sergile said.
<o:p></o:p>
This is all in all a nasty little bugger that can easily be prevented as long as you use precaution and don’t download emails you shouldn’t be.
As always you should make sure your antivirus software is up to date. This virus has spread mainly to home user’s so you have to check your computers at home or risk loosing all of your data. Even if your antivirus software is up to date thought it may not catch this worm. However there is a free download utility that will. Simply go to:
http://www.f-secure.com/v-descs/nyxem_e.shtml
and download the F-Force Utility and is LATEST.ZIP definitions file.
http://www.f-secure.com/tools/f-force.zip
http://download.f-secure.com/latest/latest.zip (http://download.f-secure.com/latest/latest.zip)<o:p></o:p>
Unzip the F-Force utility into it’s own folder and copy and paste the LATEST.ZIP file into that folder without un-zipping it. Run the f-force.exe file and follow the prompts.<o:p></o:p>
<o:p></o:p>
ALTHOUGH THIS VIRUS IS SET TO RUN ON THE THIRD OF EVERY MONTH IF YOUR COMPUTER’S CLOCK/CALENDAR IS NOT SET PROPERLY OR OFF BY A DAY OR TWO OR MORE THEN THE WORM WILL RUN ON THE DAY IT THINK’S IS THE THIRD.