Virus Alert

Desert Orchid

Senior Jockey
Joined
Aug 2, 2005
Messages
25,043
I got this message at work today. They seem to be taking it very seriously.
A serious Virus is about to strike computer on Friday 3rd February. To help avoid problems both here and at home do not open any zip files unless you know exactly where they are from. Do not be tempted to open any naughty sounding e mails or zip files. Current Virus signature files will deal with this worm but if your machine was infected before a current virus signature was installed your machine will crash on Friday. The only way to get your machine running again is to do a complete reinstall.
About BlackWorm:-
Over the last week "Blackworm" infected about 300,000 systems based on analysis of logs from the counter web site used by the worm to track itself. This worm is different and more serious than other worms for a number of reasons. In particular, it will overwrite a users files on February 3rd.
How would I get infected?:-
The worm spreads via e-mail attachments or file shares. Once a system in your network is infected, it will try to infect all shared file systems it has access to. You may see a new "zip file" icon on your desktop.
What will BlackWorm do to my system?:-
It will disable most anti virus products and delete them. The worm will e-mail itself using a variety of extensions and file names. It will add itself to the list of auto-start programs in your registry.
Files which may be deleted by the malware include files ending with he extension of COD, XLS, MDE, MDB, PPT, PPS, RAR, PDF, PSD, DMP, ZIP
Another factor that potentially makes this virus particularly noteworthy is that it has seen broad distribution with the estimated infected machines in hundreds and thousands.
Make sure your machine at home is up to date with Microsoft Patches and security updates.
Make sure your virus signature file is up to date.

Does anyone know if it's real or a hoax?
 
Virus: Kama Sutra (aka Nyxem.E, Grew.A, Blackmal.E, MyWife.D)

Status: Real.

Example: [Collected via e-mail, 2006]

Blackmal.E, a new Windows worm (which is like a virus), was discovered on January 20. It spreads as an e-mail attachment and will activate on February 3 and on the third day of every month thereafter.

Once activated, Blackmal.E will erase all Word, Excel, Access, PowerPoint, and Acrobat (PDF) documents, in addition to other file types. It is possible you are infected and do not know it yet, especially if the antivirus software on your computer has not been updated recently.

Keep in mind the worm will activate on Friday, February 3, and on the third day of every month thereafter. It is important, therefore, ALL computer users update their virus protection quickly and often — especially on home computers.

Origins: The
Kama Sutra worm (so named because the messages it sends to replicate itself contain phrases such as "Fuckin Kama Sutra pics," sent under subject lines such as "Crazy illegal Sex!" and "Sex Video") is a fast-spreading e-mail worm designed to destroy Microsoft Office documents (Word, Excel, Access and PowerPoint) as well as Adobe Acrobat and Photoshop files on all hard drives connected to infected PCs.

When a recipient opens a message generated by the worm (also known as Nyxem.E, Grew.A, MyWife.D, or Blackmal.E), a program is launched that disables anti-virus protection on the target PC. The infected PC then begins to replicate the worm by sending copies of similarly infected messages to e-mail addresses found on the victim's hard drive.

The Kama Sutra worm does not seem intended to plant back doors on infected PCs or to steal passwords or other personal information, but simply to destroy documents. It implants a program that erases common work files from all data-storage devices connected to infected PCs on the third day of every month, with the first wave of destruction to be launched on 3 February 2006.

As usual, the defense is to make sure your PC has anti-virus software installed with up-to-date definitions, or — if your PC has already been infected — to reinstall and run an anti-virus program updated to protect against the worm.
 
I heard about this elsewhere in the last couple of days - not the best!

Additionally, there may be a virus doing the rounds via MSN Messeger. Last year our office was infected by a virus after someone clicked on a link that was sent to them by one of their Messenger contacts. This activated a virus that sent the same link to everyone on his Messenger list. A couple of days ago a similar thing happened when a friend sent me a message saying something like "Did you know that you can find out who has blocked you? Click on this link to see who has blocked you". Luckily he noticed it & typed straightaway that he didn't type or send it.
 
Back
Top