News of Worms and Virus's topic - To help keep your PC's safe!!

  • Thread starter Thread starter Pebb
  • 11 comments
  • 552 views
Messages
16,737
England
Southampton, UK
Messages
Pebb--
Messages
Pebb
Source: Techspot

Four new Trojans on the loose

Four new Trojans are doing the rounds, one of which is directed at PCs, and the other three concerning mobile phones. Bootton.E, Pbstealer.D and Sendtool.A, the phone Trojans, have quite a low infection rate at present. Bootton.E restarts the mobile but also releases corrupted components that cause a reboot to fail, rendering the phone unusable. Pbstealer.D, on the other hand, sends an infected user's contact list, notepad and calendar to-do list to other nearby users via Bluetooth. How isn’t that potentially embarrassing? Sendtool.A sends malicious programs such as the Pbstealer Trojan to other devices via Bluetooth.

Fortunately, the worms are unlikely to spread very far. "They don't spread quickly because they're not purely autonomous," said Ollie Whitehause, a researcher with Symantec. Unlike worms on computers, the Trojan horses hitting cell phones spread as attachments that require users to download them.
Nyxem is the PC worm. Unlike the mobile phone malware, Nyxem is spreading rapidly and carries a potentially destructive set of instructions.

Also nicknamed the Kama Sutra worm, it is programmed to overwrite all of the files on computers it infects on 3 February, said Mikko Hypponen, chief research officer at F-Secure Corp.
 
Source: F-Secure

We have been co-operating with RCN, the company running the counter site that is used by the Nyxem.E worm. Last night we got the web access statistics, listing all the IP addresses that have accessed the Nyxem counter.

After filtering out the addresses of bots that have been hammering the counter lately, we used our WORLDMAP technology to map the addresses to a map. As a result we have a global view of the machines that will run into trouble unless they are disinfected before tomorrow:

http://www.f-secure.com/weblog/archives/NyxemLatLonBig.png

As we warned before, the payload of Nyxem.E worm will activate tomorrow, on February 3rd, 2006 on all infected computers that have their clock set correctly.

We made a few additional tests with the worm in our test network environment. When the payload is activated, the worm enumerates all logical drives and damages files on them in a loop. So it should damage files on all drives that have a drive letter, including network drives. That's the theory. In practice, however, the worm failed to do so on network drives, at least in our test environment. Files on local and removable drives (including USB memory) were damaged by the payload.
 
yeh the BBC have something on these worms too, they sound very nasty so everyone scan their pc's before tommorow, unless it is tommorow.
 
If you go onto F-Secure, they have a removal tool for Nyxem. I just started to download both F-Secures different virus scanners, for worms aswell.
 
Thanks TVR, just running that now. I did run nortan earlier and it said nothing was on the pc but better to be safe than sorry, i dont know what i would do without my Word documents.
 
No problem Sprite, trying to help as many people stay safe from this worm.
 
So... if you received the e-mail, and opened the attachment, you're dead meat, right? If you never opened the e-mail, and never opened the attachment, you're fine?
 
So... if you received the e-mail, and opened the attachment, you're dead meat, right? If you never opened the e-mail, and never opened the attachment, you're fine?

Im guessing so but you can never be too complaisant when it comes to things that can harm your pc. Plus alot of people read alot of e-mails per day, and if it can move from network to network then the spread will be rapid.
 
sprite
Im guessing so but you can never be too complaisant when it comes to things that can harm your pc. Plus alot of people read alot of e-mails per day, and if it can move from network to network then the spread will be rapid.
They were talking about app. 300000 computers reporting to the counter, so I wouldn't say an infection of proportional scale...

Annoying for those who DID get it and don't have a backup though....
 
As long as you do not get the email, which has the worm then you should be safe. But just do a scan just in case, glad my PC is free from this worm.
 
Back