• On CBS.com: Six show girls attacked

January 30, 2006 10:32 AM PST

ISP sends alert to Kama Sutra victims

A British Internet service provider is notifying customers whose systems it believes may be infected with the Kama Sutra virus.

When a computer is infected by the worm, which also goes by Nyxem.E and other names, it visits an online Web counter that tallies up how many PCs have been infected. U.K.-based Easynet said it is monitoring traffic to this Web counter and sending a virus alert to every person who visits it.

ISPs have come under criticism for failing to responsibly monitor the data they pipe to home users and to share the responsibility for the ever-growing burden of virus and spam that is falling on businesses and consumers.

"ISPs do the equivalent of pumping out raw sewage into your home. You wouldn't expect to have to filter your own water, so why do home users have to filter their own data?" Paul Wood, a senior analyst at hosted e-mail and Web security company MessageLabs, said in November.

In May, the Federal Trade Commission, in tandem with some counterparts worldwide, said it planned to ask ISPs to help crack down on "zombie" networks of computers that send out spam.

F-Secure applauded Easynet's move in its blog, encouraging other ISPs to get in contact with customers who may be affected by an attack.

"We think it's a good idea that ISPs warn people about viruses in general, and I think it's a great idea that Easynet proactively took this step," F-Secure security expert Patrik Runald said. "Obviously, with 300 or 400 viruses being detected every day, ISPs can't warn their customers about all of them. But in this type of case, it's a really good idea."

The security company encouraged other ISPs to notify any customers whose systems may have been infected by the Kama Sutra worm before Feb. 3, when the virus is due to deliver its payload.

"We thought this was an excellent idea and wanted to promote it! We encourage other ISPs to do the same, as it will help users disinfect their machines before the 3rd of February," F-Secure wrote on its blog.

The payload is programmed to delete all Microsoft Word, Excel and PowerPoint file types, as well as Adobe Systems PDF files, from a compromised PC. The multifaceted malicious software will also attempt to propagate itself, both through e-mail and as a network worm, which can be particularly damaging on closed networks.

"Nyxem is certainly malicious. It can be delivered via e-mail, but also as a network worm. It probes other PCs on a closed network to compromise them and send itself to the other computers, to infect as many hosts as possible," Jason Steer, a technical consultant at security company Ironport, said on Thursday.

The malicious software hides in attachment types not typically blocked by attachment filters.

Companies are unlikely to be directly affected by Kama Sutra if they are running up-to-date antivirus software, Ironport said, because the major antivirus vendors have now released patches. But the company warned on Thursday that businesses could experience secondary effects as the virus tries to propagate itself by harvesting e-mail addresses on an infected machine.

"The knock-on effects will come as compromised PCs try to communicate with businesses. This will cause additional e-mail and network traffic, and possible slow down e-mail response time," Steer said Thursday.

Tom Espiner of ZDNet UK reported from London.

See more CNET content tagged:
Easynet, Internet Service Provider, Nyxem, F-Secure Corp., Ironport Systems Inc.

Add a Comment (Log in or register) 4 comments
Wrong, wrong, wrong.
by thenet411 January 30, 2006 11:41 AM PST
ISPs are NOT responsible for monitoring the data that is transported to their systems. The analogy of comparing Internet access to water pipes is so wrong. I quote:
"ISPs do the equivalent of pumping out raw sewage into your home. You wouldn't expect to have to filter your own water, so why do home users have to filter their own data?"
The analogy that should have been used is the telephone network. The phone company provides you, the end user, with a clear phone line that can be used to talk to anyone or anything that also interfaces with that network. Saying ISPs are responsible for the content that users download is ridiculous! That would be like holding the telephone companies responsible for a little old lady that falls victim to a telephone scam. It is the USER'S responsibility to obtain antivirus software, keep it up to date, and use a little common sense when going through their inbox!
As I have said before, ignorance of this "new digital age" is no excuse for not taking the slightest interest in protecting yourself. The information about how to protect yourself against viruses and phishing is out there. All you need to do is a little reading.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from CNET News sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right