Feeds

Kama Sutra: the final countdown

Da-da-da-da, da-da-da-da-daaaa...

The Power of One eBook: Top reasons to choose HP BladeSystem

The destructive Kama Sutra worm has begun thrashing files on infected machines with incorrectly set system clocks.

Even though the worm is programmed to first delete files on infected machines on Friday (February 3), its deadline is based on the clock of infected Windows PCs. Finnish anti-virus firm F-Secure says it has already received two reports from users who've had files on their system overwritten by the worm.

The Kama Sutra worm (AKA Nyxem-D or Blackworm) first appeared on January 18, posing as a email message offering a variety of salacious content. Subject lines used in the malicious emails include: The Best Videoclip Ever, Fw: SeX.mpg, Miss Lebanon 2006 and Fuckin Kama Sutra pics. The worm only affects Windows PCs.

Windows users who fall for this ruse wind up with an infected machine and disabled security software. Worse still, Nyxem-D is also programmed to overwrite files on Friday February 3, and the third day of every month thereafter. The worm overwrites DOC, XLS, MDB, MDE, PPT, PPS, ZIP, RAR, PDF, PSD and DMP files on all mounted drives.

This old-school "trash your Windows PC" worm has infected an estimated 600,000 machines, with the US, India and Peru having the greatest number of infected machines, Security Focus reports. One US firm alone is responsible for around 75,000 infection hits, according to an analysis by security firm LURHQ.

Windows users are advised to run scans for infection using up-to-date anti-virus signatures. The worm attempts to disable most anti-virus products, so if you hit trouble on this score it's a good idea to either reinstall software or run web-based anti-virus scanners, such as Trend Micro's free House Call service. Symantec, among other security vendors, has published a free disinfection tool (available here). ®

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.