PDA

View Full Version : Mydoom virus


ciaran
27-01-2004, 13:34
I've got it sent to me once already today so I thought I'd mention it, from here (http://news.bbc.co.uk/2/hi/technology/3432639.stm) (and many other places)


A malicious computer virus spread via e-mail is clogging networks and may allow unauthorised access to personal computers, experts have warned.
The worm, Mydoom or Novarg, is carried as an e-mail attachment in a text file and sends itself out to other e-mail addresses once opened by the recipient.

The virus may also open a "back door" to the computer to give hackers access.

It is also spread through file-sharing networks and experts think it could be worse than last summer's Sobig worm.

...

Unlike many of its predecessors, Mydoom does not entice the recipient to open the attachment by promising nude pictures or personal messages.

Instead, the e-mail carrying the virus often bears the subject "Test" or "Status". The message inside may read: "The message contains Unicode characters and has been sent as a binary attachment".

It also "spoofs" the sender's e-mail address, in an attempt to fool the recipient into opening the e-mail. Some examples of spoofed addresses which have been received by BBC News Online have included aol.com, oxfam.org.uk, and usc.edu.

...

Users are advised to delete or ignore the e-mail attachment - which usually ends .exe, .scr, .zip, .cmd or .pif - to avoid damage.

brid
27-01-2004, 17:32
damnit, didn't open the mail with the virus but someone sent me a rather irrate message because i supposedly sent it to them. So beware of bris.ac.uk addresses too.

happy joy joy
28-01-2004, 00:57
i had 3 in my email 2day. but hers what my email providers told me to do

_________________________________________________________________________
Important News about the Novarg virus


Virus Alert
The W32.Novarg.A@mm virus is a mass-mailing worm that is very active on the Internet. While we are currently taking measures to protect our Email users, you can protect yourself by identifying and deleting emails with Novarg characteristics. Please do not report these emails as Spam.
Note: Your computer should not be infected by this virus unless you open a corrupted attachment.

What to look for:
Emails infected with the Novarg virus have, thus far, been approximately 30-35KB in size and have exhibited the following characteristics:

Subject line:

Hello
Hi
Test
Status
From line:
Contains spoofed addresses - which means that the name that appears in the "From" field is probably not the real sender.

Body:

Tends to be unreadable; gibberish. You may also see the following message: "The message contains Unicode characters and has been sent as a binary attachment".
Attachment file extensions:

.zip (most common)
.bat
.cmd
.exe
.pif
.scr
Known attachment file names:

body (.zip, .bat, etc.)
readme
file
message
text
jasrjx
dajtl
document
What you can do:
Delete messages with the above characteristics and be sure to delete them from your Trash Folder. Knowing some of the above characteristics about this virus, you may wish to set up custom filters and route most of these virus emails directly to your Trash or Bulk Folder. This way, you can keep your inbox free of most of these messages. Just be sure to check your Trash or Bulk Folder and empty them on a regular basis in order to free up space in your email account.

For more information: Symantec Novarg Recommendations

- The Excite Team

pablo
28-01-2004, 11:28
http://www.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html for more info .


There are even mails out there pretending to be from eirjobs.com addresses : more : http://feckthat.com/rant/showthread.php?t=3730