Windows users need to check this out fast.

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 02-01-2006
IrishEyes's Avatar
Reminiscing

Join Date: Apr 2004
Location: watching the snow melt...
Posts: 2,690
IrishEyes has a spectacular aura aboutIrishEyes has a spectacular aura aboutIrishEyes has a spectacular aura about
Windows users need to check this out fast.

nemo just sent me this link and I wanted to make sure that it got posted here. Basically if you're running Windows (and I know that a few of you still are), make sure - no, i mean REALLY make sure - that your AV software is up to date. This looks pretty nasty.

http://isc.sans.org/diary.php?storyid=1067
__________________
"Lucky in love, well maybe so. there's still a lot of things you'll never know...
like why each time the sky begins to snow - you cry..."
- Dan Fogelberg
Reply With Quote
  #2 (permalink)  
Old 02-01-2006
C1ay's Avatar
¿42?
Hypography Staff Member
Administrator
Senior Editor
Editor

Join Date: Feb 2005
Location: 33.78N 84.66W
Posts: 5,756
C1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant futureC1ay has a brilliant future
Re: Windows users need to check this out fast.

Would you believe that I don't have any AV software and never have on any of my machines and I've not had one virus? Sure, I've received 100's via email over the years but I've never executed any of them. I've had a hardware firewall for years now and I see nary a worm. I do think I'm the exception though, all other windows users should keep some kind of AV software running. I get a lot of calls from friends to help them clean their box from the latest bug.
__________________
Clay

Editor and Forum Administrator
stego anyone?
Add yourself to Hypography's Frappr.
"There are only 10 kinds of people in the world --
.....Those who understand binary, and those who don't."
"Draw no conclusions before their time."
Reply With Quote
  #3 (permalink)  
Old 02-01-2006
IrishEyes's Avatar
Reminiscing

Join Date: Apr 2004
Location: watching the snow melt...
Posts: 2,690
IrishEyes has a spectacular aura aboutIrishEyes has a spectacular aura aboutIrishEyes has a spectacular aura about
Blackworm (CME-24)

This one looks pretty bad. An excerpt from the SANS site (where the link leads) says the following:

Quote:
About BlackWorm
Over the last week, "Blackworm" infected about 300,000 systems based on analysis of logs from the counter web site used by the worm to track itself. This worm is different and more serious than other worms for a number of reasons. In particular, it will overwrite a user's files on February 3rd.

At this point, the worm will be detected by up to date anti virus signatures. In order to protect yourself from data loss on February 3rd, you should use current (Jan 23rd or later) anti virus signatures. Note, however, that the malware attempts to disable/remove any anti-virus software on the system (and does this every hour while the system is up), so if the machine was infected before signatures were deployed, obviously, that anti-virus software can't be expected to clean up the infection for you.

The following file types will be overwritten by the virus: DOC, XLS, MDE, MDB, PPT, PPS, RAR, PDF, PSD, DMP, ZIP. The files are overwritten with an error message( 'DATA Error [47 0F 94 93 F4 K5]').
It just sounds yucky. I'm glad I'm not subjected to the Evil Empire any longer.
__________________
"Lucky in love, well maybe so. there's still a lot of things you'll never know...
like why each time the sky begins to snow - you cry..."
- Dan Fogelberg
Reply With Quote
  #4 (permalink)  
Old 02-01-2006
GAHD's Avatar
Creating
Hypography Staff Member
Administrator

Join Date: Dec 2003
Location: Winterpeg, Manitoba
Posts: 1,903
GAHD is a name known to allGAHD is a name known to allGAHD is a name known to allGAHD is a name known to allGAHD is a name known to allGAHD is a name known to allGAHD is a name known to allGAHD is a name known to all
Send a message via ICQ to GAHD Send a message via AIM to GAHD Send a message via MSN to GAHD Send a message via Yahoo to GAHD
Re: Blackworm (CME-24)

It's stuff like this that makes me keep backups.
__________________
Sometimes a Hypography Forum Administrator



"With a big enough engine, even a brick will fly." -Law of Aerospace
Reply With Quote
  #5 (permalink)  
Old 02-02-2006
Drip Curl Magic's Avatar
ong RA guru dev RA

Join Date: Nov 2005
Location: Earth
Posts: 1,134
Drip Curl Magic is a glorious beacon of lightDrip Curl Magic is a glorious beacon of lightDrip Curl Magic is a glorious beacon of lightDrip Curl Magic is a glorious beacon of lightDrip Curl Magic is a glorious beacon of lightDrip Curl Magic is a glorious beacon of light
Send a message via AIM to Drip Curl Magic Send a message via MSN to Drip Curl Magic
Re: Windows users need to check this out fast.

hmmm... I use the free version of AVG and AVG updates itself daily automatically. Is this program enough to protect me? I was told one time that there is a better free anti-virus program- but I forgot the name of it. Anyone know of any really good AV programs (preferably free)?
__________________
Rofl waffles
Reply With Quote
  #6 (permalink)  
Old 02-02-2006
Jay-qu's Avatar
Ancora Imparo
Hypography Staff Member
Moderator
Editor
Gallery Curator
Basic Subscription
Sponsor
Re: Windows users need to check this out fast.

Avast, AntiVir - I have both running on different machines and havent ever had any problems. Good Adware/spyware/malware software is also helpful, they can do some nasty things to.
__________________
Jay-qu
::Hypography Moderator of..
Chemistry, Physics & Mathematics, Astronomy & Cosmology, Space and Technology & gadgets Forums

Einstein said that if quantum mechanics is right, then the world is crazy. Well, Einstein was right. The world is crazy.
-Daniel Greenberger

Physics Guides - Physics Resources and help
Reply With Quote
  #7 (permalink)  
Old 02-02-2006
Mercury's Avatar
Thinking

Join Date: Oct 2005
Location: Malaysia
Posts: 42
Mercury is on a distinguished road
Exclamation Re: Windows users need to check this out fast.

I received an e-mail two days ago which contained a virus... it might be this one. This is very, very bad. It's in several local newspapers and everyone is worried about it.
__________________
Silence is the element in which great things fashion themselves. - Carlyle, Sartar Resartus

Last edited by Mercury; 02-02-2006 at 03:06 AM.
Reply With Quote
  #8 (permalink)  
Old 02-02-2006
alexander's Avatar
Resident USSRian
Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member
Re: Windows users need to check this out fast.

lol guys, i run viruses in wine to see what they effect on people's computers

well, it took the good news a few days to get here, this was on digg like 2 days ago...

here is some more info on the worm:
http://securityresponse.symantec.com...kmal.e@mm.html
__________________
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Vista geokker Computer Science 4 09-17-2005
Is windows just another virus? dirty.deeds Computer Science 4 08-28-2005
Windows better than Linux research alexander Computer Science 38 05-04-2005
Cell Architecture alexander Computer Science 4 04-07-2005
Information/Complexity: bacterium vs. Windows OS TeleMad Computer Science 21 09-22-2004

» Current Poll
Favorite James Bond?
Sean Connery - 63.64%
7 Votes
George Lazenby - 0%
0 Votes
David Niven - 9.09%
1 Vote
Roger Moore - 9.09%
1 Vote
Timothy Dalton - 9.09%
1 Vote
Pierce Brosnan - 0%
0 Votes
Daniel Craig - 9.09%
1 Vote
Hate 'em all - 0%
0 Votes
Who's James Bond? - 0%
0 Votes
Total Votes: 11
You may not vote on this poll.

All times are GMT -8. The time now is 12:52 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2000-2008 Hypography
Part of the Hypography - Science for Everyone Network