A CNET FAQ on the Kama Sutra worm

By Robert Vamosi on 03 February 2006

Tags: faq | karma | security | sutra | virus | worm | antiviru | vendor | damage | cure

A There's a computer worm set to damage computer systems starting on February 3, 2006.

There has been a lot of confusion surrounding this worm, especially because media organisations and antivirus vendors haven't determined a common name. CNET has settled upon Kama Sutra; however, aliases include CME-24 (US-CERT), MyWife (McAfee), Tearec (Panda), Nyxem (Sophos), Blackmal (Symantec, Computer Associates, Vet), and GREW (Trend).

Infections: Security vendor LURHQ has metrics on the spread of Kama Sutra in specific countries through January 26, 2006. The data suggests that India, Peru, Italy, and Turkey are the most vulnerable to Kama Sutra; today, however, antivirus vendor F-Secure posted data suggesting that the United States and Europe may be equally vulnerable.

Who's at risk?: Kama Sutra affects all versions of Windows; it does not affect users of Mac OS, Linux, or Unix.

How does it infect?: Windows users who receive sexually suggestive e-mail and proceed to open the attached file may find themselves infected with Kama Sutra. Unlike some e-mail worms, Kama Sutra will not automatically spawn; you must open the file yourself.

Expected damage: Kama Sutra contains a dangerous payload. On the third day of the month all files with the extensions DOC, XLS, MDE, MDB, PPT, PPS, RAR, PDF, PSD, DMP, and ZIP will be overwritten with an error message "DATA Error [47 0F 94 93 F4 K5]." These files -- which include the default file formats for Microsoft Office and Adobe Acrobat applications -- cannot be restored once they are damaged.

CNET Virus Threat Meter: Despite the danger presented by Kama Sutra, infection rates remain relatively low worldwide. Therefore we are keeping the Threat Meter on Low for the time being.

Prevention and cure: Read our prevention and cure alert for links to specific antivirus vendors. For a more comprehensive analysis, see the page posted at Sans.org.

Like this article? Click below to send it to your mobile for free!

RA
04/02/2006 10:09 PM

can you help me on this virus? can the files be recovered by any means? i have lost my data in .doc, .ppt, .mdb and .xls.

Report offensive content

smaeer
29/02/2008 07:35 PM

I want anti virus software for my computer safty.

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Hacker talks fooling e-passport systems

  • Best free Windows Mobile software

  • Trend Micro PC-cillin Internet Security 2009

  • Norton Internet Security 2009: Photos

  • Trend Micro Internet Security 2009 Pro: Photos

  • 101 software tips, tweaks and tricks

  • Don't buy stand-alone antivirus: Trend Micro

  • Norton Internet Security 2009

  • Spyware Terminator

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Trend Micro PC-cillin Internet Security 2009

      Trend Micro PC-cillin Internet Security 2009

      You can't beat the price. For a good, basic internet security suite, we recommend Trend Micro Internet Security 2009.

    • Norton Internet Security 2009

      Norton Internet Security 2009

      Norton Internet Security 2009 hits all the right security notes and its superior protection technologies might even win back some jaded anti-Symantec folks, though the lack of adequate technical support may continue to frustrate.

    • Spyware Terminator

      Spyware Terminator

      This spyware scanner and removal tool does the job, but enabling some functions may cause slight slowdowns and it has a few bugs in Vista.

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    More reviews »

    Membership benefits

    Contact community members

    Contact community members

    Add friends or tech gurus to you contacts and send them messages. Sign up for a free CNET.com.au membership now!