View Full Version : New High-Distribution Virus Alert
SM-Bot
27 Jan 2004, 7:19am
Symantec calls it W32.Novarg.A@mm, McAffee calls it W32/Mydoom@MM, We just call it another pain in the a**
Symantec Security Response
McAfee VirusInfo
Submitted by Dexter & profd
Dexter
27 Jan 2004, 7:33am
Apparently, this virus is also designed to run a DoS attack on www.sco.com, probably as retaliation for SCO's efforts to force users of certain Linux distributions to purhcase a license from them, as SCO claims intellectual property over part of these distributions.
http://www.news.com.au/common/story_page/0,4057,8507028%255E15306,00.html
Dexter...
Black Hawk
27 Jan 2004, 7:35am
Bah.
SCO = owned.
the reply with quote thing that's on the side of the button doesn't actually work
Shorty
27 Jan 2004, 7:37am
Does work, you need to tick the "Quote message in reply" :p
This is just another nasty virus. Haven't these guys got better things to do?!
Black Hawk
27 Jan 2004, 7:42am
Meh. It should've done it automatically...
Shorty
27 Jan 2004, 7:58am
Meh. It should've done it automatically...
The click is for when you want to reply at the top of a long page.. as it scrolls straight to the bottom for you ;)
You still have to tick the box :)
profdlp
27 Jan 2004, 8:37am
Bah.
...the reply with quote thing that's on the side of the button doesn't actually work...
Could you be confusing these two - they do different things; both work for me. :beer:
Black Hawk
27 Jan 2004, 8:42am
Uhh...I meant the "Quick reply to this message".
Well this went off topic... ;D
profdlp
27 Jan 2004, 8:51am
Well this went off topic... ;D
I blame it on that new virus. Sneaky little fellers... :vimp:
Kwitko
27 Jan 2004, 12:33pm
I got 6 of these yesterday. They all came disguised as bounced emails.
//EDIT: Just got another one.
Enverex
27 Jan 2004, 12:55pm
I have been getting these for the last 5 months and have had over 3000+ in total. SpamAssassin now automatically picks them all up and bins them.
This is a mass-mailing and peer-to-peer file-sharing worm that arrives in an email message as follows:
From: (spoofed email sender)
Subject: (Varies, such as)
* Error
* Status
* Server Report
* Mail Transaction Failed
* Mail Delivery System
* hello
I've gotten 9 in the last few days.
Is the virus delivered upon opening, or if the attachment is opened? If the former is true, I'm pwned.
Aranyic
27 Jan 2004, 1:14pm
From what I can tell you have to manually open the attachment to become infected.
panzerkw
27 Jan 2004, 1:27pm
Had nine infected emails in my box when I woke up this morning. Between these and the porn/free meds/penis enlargement spam, my email box is starting to be a real hassle.
I added message rules to outlook that automatically deletes any email with the keywords this virus uses in the subject line. I haven't had one since.
TheLostSwede
27 Jan 2004, 2:13pm
Stupid Outlook. I made a rule to delete all mess with Penis, Viagra, Microsoft, Enlargement etc and putted it on. I then sent a mail to myself with all the words in the mail and the subject line. No dice. I still had the word penis in the fontsize 200 on teh screen. =\
Aranyic
27 Jan 2004, 2:59pm
;) this virus is spreading like wildfire, messagelabs users have reported 575,000+ emails with it, 1 in every 41 of the emails or there abouts infects the user.
http://messagelabs.com/viruseye/info/default.asp?frompage=top+ten&fromURL=%2Fviruseye%2Fthreats%2F&virusname=W32%2FMyDoom%2EA%2Dmm
EyesOnly
27 Jan 2004, 3:39pm
But so far i haven't gotten it. Hope it stays that way.
Straight_Man
27 Jan 2004, 3:49pm
Symantec calls it W32.Novarg.A@mm, McAffee calls it W32/Mydoom@MM, We just call it another pain in the a**
Symantec Security Response
McAfee VirusInfo
Submitted by Dexter & profd
Kaspersky Link here:
http://www.viruslist.com/eng/viruslist.html?id=841769
John-- who is seeing a lot of construction kit style plus addons Trojan+Internet Worm hybrids right now. BTW, Kaspersky AND NAV can be run on same XP box, if I end up with (legal OEM) XP on the Intel box after motherboard upgrade will license and run both together.
Aranyic
27 Jan 2004, 4:15pm
Just got this in an email:
Updated at 14.20 GMT/09.20 New York/01.20 Sydney
MessageLabs has now intercepted 1.2 million copies of W32/Mydoom.A-mm. The company is processing between 50,000 and 60,000 copies of the worm an hour. To date, the worm's peak infection rate is 1 in 12 of all email scanned be MessageLabs. So far, the worm has been seen in 168 countries.
W32/Mydoom.A has exceeded the infamous SoBig.F virus in terms of copies intercepted, and the number continues to rise
Dexter
27 Jan 2004, 5:49pm
Stupid Outlook. I made a rule to delete all mess with Penis, Viagra, Microsoft, Enlargement etc and putted it on. I then sent a mail to myself with all the words in the mail and the subject line. No dice. I still had the word penis in the fontsize 200 on teh screen. =\
Ya, I deleted all my Outlook filters a while back after it started filtering out legitimate e-mails form clients, even though there were no matches to my keywords in their subject lines.
Stupid Outlook.
Dexter...
Spinner
27 Jan 2004, 5:53pm
I got 6 of these yesterday. They all came disguised as bounced emails.
//EDIT: Just got another one.
Yeah same here, I got four this morning.
TheLostSwede
27 Jan 2004, 6:14pm
I have never used a Antivirusproggy. Which one would you guys recommend? Money isn't an issue.
.... I still had the word penis in the fontsize 200 on teh screen. =\
Yeah maybe I am immature .... but for some reason that is hilarious. ;D
But back on topic ... here at work we get 100-300 spam emails a day mostly consisting of penis enlargement and viagra-like supplements. The rest are all worms. I have message rules set, but they are starting to spell words to get around the rules "enlagrement" "v|agra" etc.... how troublesome. SUPPOSEDLY the company who hosts our websites is supposed to setup a spam blocker on the server side .... but it hasn't happened yet ....
LawnMM
27 Jan 2004, 6:17pm
Norton
Spinner
27 Jan 2004, 6:48pm
Norton
I second that. Mack', I'm genuinely shocked you don't use an Antivirus program. Any specific reason why you haven't decided to up until now?
I second that. Mack', I'm genuinely shocked you don't use an Antivirus program. Any specific reason why you haven't decided to up until now?
I don't use them either. I haven't really had the need. As long as you don't open foreign emails/files and you are careful what/where you download, you shouldn't really ever get a virus. Lately though I have been using Norton AV 03. I just don't like how AV progs like to invade your system and use resources, and I have had bad experiences with bugged Norton installs destroying my system (well my windows install anyways).
But yeah, I would have to say Norton also.
Enverex
27 Jan 2004, 7:03pm
I don't use one either. Don't see the point in unnecessary slowdowns when I don't open random files from people and don't have any other things that would have dangerous files. The only time I may ever use one is if I think I may have to handle potentially dangerous files at some point.
Shorty
27 Jan 2004, 7:10pm
Im getting loads but the anti-virus is keeping them at bay :)
TheLostSwede
27 Jan 2004, 7:15pm
I second that. Mack', I'm genuinely shocked you don't use an Antivirus program. Any specific reason why you haven't decided to up until now?
I'm just lazy and always thought that running such program always messes things up more than it helps. Reason i wan't to try one is to se if i already have any virus on the system. If i don't, i'll uninstall it.
Templar
27 Jan 2004, 7:29pm
Still can't believe people still open these.. Attachment should = immediate red flag at least :\
I'm just lazy and always thought that running such program always messes things up more than it helps. Reason i wan't to try one is to se if i already have any virus on the system. If i don't, i'll uninstall it.
I second that.
Black Hawk
27 Jan 2004, 9:23pm
I use NAV2003 (2004 sucks) and I have yet to see a slow down. Uses less than 1mb. Checks for virus every friday night and checks incoming email. Other than it's not free it's really good. Older version really screwed up stuff like gaming but this one works like a charm. The thing about 2004 is that it checks every single file transfer even from within the hardrive. So if you transfer like 100 small files, it hogs down the system.
Aranyic
28 Jan 2004, 1:56pm
Update:
Updated at 13.20 GMT/08.20 New York/00.20 Sydney
MessageLabs has now intercepted around 2.2 million copies of W32/Mydoom.A-mm. The top three countries the company is seeing copies sent from are the US (40%), the UK (22%) and Australia (5%). So far, the virus has been active in 206 countries.
The infection ratio currently stands at around 1 copy of Mydoom per 17 emails scanned.
Enverex
28 Jan 2004, 2:02pm
Strange, now that this is happening, I don't seem to be getting any anymore.....
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.