A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me A pic of me
***Dave Does the Blog

The Post

« Previous  •  FRONT PAGE  •  Next »

Tuesday, 27 January 2004, 9:05 AM
Infectious

In case you've been under a rock, there's a new computer virus in town, the MyDoom or Novarg virus.

The virus--known as MyDoom, Novarg and as a variant of the Mimail virus by different antivirus companies--arrives in an in-box with one of several different random subject lines, such as "Mail Delivery System," "Test" or "Mail Transaction Failed." The body of the e-mail contains an executable file and a statement such as: "The message contains Unicode characters and has been sent as a binary attachment."
"It's huge," said Vincent Gullotto, vice president of security software maker Network Associates' antivirus emergency response team. "We have it as a high-risk outbreak."
In one hour, Network Associates itself received 19,500 e-mails bearing the virus from 3,400 unique Internet addresses, Gullotto said. One large telecommunications company has already shut down its e-mail gateway to stop the virus.
Once the virus infects a Windows-running PC, it installs a program that allows the computer to be controlled remotely. The program primes the PC to send data to the SCO Group's Web server, starting Feb. 1, a virus researcher said on the condition of anonymity.

As always, update your AV software; if it hasn't been automatically updated yet, then manually go out and grab the current signature file and engine. Etc.

UPDATE: The following is from the NAI AV site:

This is a mass-mailing and peer-to-peer file-sharing worm that arrives in an email message as follows:
From: (spoofed email sender) Subject: (Varies, such as)
- The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. - The message contains Unicode characters and has been sent as a binary attachment. - Mail transaction failed. Partial message is available. - Error - Status - Server Report - Mail Transaction Failed - Mail Delivery System - hello - hi

More info is also available at Symantec's site.


Filed under :: Spam
Link · Print · Edit · TR/G


« Previous  •  FRONT PAGE  •  Next »


Pings?

Trackback ping address: http://www.hill-kleerup.org/blog/mt4/080510t.cgi/4401
Stupid Evil Bastard (27-Jan-04 11:21 AM): Fun with the W32/MyDoom virus.
***Dave talked about it so I figured I'd toss up something about it as well. Goodness knows it's certainly got the anti-virus group at my company all up in arms today having received four urgent pages on the issue already. There seems to be some confus... ...

Comments?

Tuesday, 27 January 2004, 9:44 AM
Quoth Pascale Soleil ...

Or, you could get a Mac!

:D

Somebody had to say it.

Tuesday, 27 January 2004, 10:23 AM
Quoth Les ...

I'd love to have a Mac except for two things: 1) They're still too damned expensive for what you get and 2) I'd have to wait another year on average before I got to play any of the hot game titles that come out for the PC. If I weren't a gamer I'd consider a Mac, or at least switching to Linux. I think OS X is da bomb, but I'm not giving up Call of Duty to use it.

Back on topic for a moment, I've been getting bounced mails from my email address being spoofed hourly for the last day or so. Awful lot of unprotected machines out there.

Tuesday, 27 January 2004, 11:25 AM
Quoth *** Dave ...

Yeah, I noticed a lot of spoofed mail from me bouncing "back" last night, too.

As far as Macs go -- take whatever comfort there may be in being a smaller target. I'm not that huge of a Microsoft fan, but if Apple had 90% of the desktop share, sure as shootin' there'd be more viruses written for OS X.


Speak!

Note: This comment space is for discussion of the above topic, and not for unsolicited commercial links. I use SpamLookup, optional TypeKey registration, and mandatory TinyTuring text CAPTCHA to filter out comment spam. If you have technical problems with these measures, please . With or without TypeKey, you'll need to specify an e-mail address, which will not be published or otherwise abused.




Remember you next time?

Subscribe to this post (e-mail when updated)?





Creative Commons License
Original material on this weblog is available under a Creative Commons License from
The views expressed by me on this website/weblog are mine alone and do not necessarily reflect the views of
my employer, my church, my party, my candidate, my community, my wife, my friends, or, on occasion, myself.
Views expressed by others are, well, theirs.