Heads up--W32.Novarg.A@mm spreading rapidly

P

PA Bear

This one is nasty--beware.

W32.Novarg.A@mm
aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
Discovered on: January 26, 2004
Last Updated on: January 26, 2004 03:30:48 PM
Category 4 - Severe
Dangerous threat type, difficult to contain. The latest virus
definitions should be downloaded immediately and deployed.
-Wild: High
-Damage or Distribution: High

http://www.symantec.com/avcenter/venc/data/[email protected]
http://vil.nai.com/vil/content/v_100983.htm
http://www.f-secure.com/v-descs/novarg.shtml
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
 
C

Curt Christianson

AVG also has an update for this
www.grisoft.com
Curt
PA Bear said:
This one is nasty--beware.

W32.Novarg.A@mm
aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
Discovered on: January 26, 2004
Last Updated on: January 26, 2004 03:30:48 PM
Category 4 - Severe
Dangerous threat type, difficult to contain. The latest virus
definitions should be downloaded immediately and deployed.
-Wild: High
-Damage or Distribution: High

http://www.symantec.com/avcenter/venc/data/[email protected]
http://vil.nai.com/vil/content/v_100983.htm
http://www.f-secure.com/v-descs/novarg.shtml
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
 
G

Gary S. Terhune

Sigh... I'm always tempted to test my AV (after updating, of course.) Got a half
dozen of these in the last few hours (my open address here invites such.)

Yup, ETrust now caught this one--Message.Zip containing a PIF file, Document.Zip
containing SCR file, both infections identified as Win32.Mydoom.A worm

Hey, maybe I should be forwarding these emails directly to CA. Heck, I must get
them about as soon as they're released. Whaddya think, <bg>? Maybe just the ones
that I know are viruses but an updated ETrust doesn't identify as such?

Naw. Wouldn't get paid, and I do enough volunteer work as it is.
 
P

PA Bear

New virus infects PCs, whacks SCO (9:00 PM ET)
http://news.com.com/2100-7349_3-5147605.html?tag=nefd_top

</paste>
update: A mass-mailing virus quickly spread through the Internet on Monday,
compromising computers so that they attack the SCO Group's Web server with a
flood of data on Feb. 1, according to antivirus companies.

In one hour, Network Associates itself received 19,500 e-mails bearing the
virus from 3,400 unique Internet addresses, Gullotto said. One large
telecommunications company has already shut down its e-mail gateway to stop
the virus.

....The virus affects computers running Windows versions 95, 98, ME, NT, 2000
and XP.

The virus also copies itself to the Kazaa download directory on PCs, on
which the file-sharing program is loaded. The virus camouflages itself,
using one of seven file names, including Winamp5, RootkitXP, Officecrack and
Nuke2004. Variations in the body text include: "The message cannot be
represented in 7-bit ASCII encoding and has been sent as a binary
attachment."

Early data indicated an epidemic several times the size of the Sobig.F
virus... "At its current run rate, we will trap almost *8 million* in a
day," [said the vice president of engineering at e-mail service provider
Postini]. The company quarantined only 1,400 copies of Sobig.F in its first
day and 3.5 million copies of the virus during that epidemic's peak 24-hour
period.
</paste>

GAry said:
Sigh... I'm always tempted to test my AV (after updating, of course.) Got a half
dozen of these in the last few hours (my open address here invites such.)

Yup, ETrust now caught this one--Message.Zip containing a PIF file, Document.Zip
containing SCR file, both infections identified as Win32.Mydoom.A worm

Hey, maybe I should be forwarding these emails directly to CA. Heck, I must get
them about as soon as they're released. Whaddya think, <bg>? Maybe just the ones
that I know are viruses but an updated ETrust doesn't identify as such?

Naw. Wouldn't get paid, and I do enough volunteer work as it is.
This one is nasty--beware.

W32.Novarg.A@mm
aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
Discovered on: January 26, 2004
Last Updated on: January 26, 2004 03:30:48 PM
Category 4 - Severe
Dangerous threat type, difficult to contain. The latest virus
definitions should be downloaded immediately and deployed.
-Wild: High
-Damage or Distribution: High

http://www.symantec.com/avcenter/venc/data/[email protected]
http://vil.nai.com/vil/content/v_100983.htm
http://www.f-secure.com/v-descs/novarg.shtml
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
 
P

Papa

Thanks for the warning, PA Bear.

I received 1 of those in my Inbox yesterday and 2 today. All were deleted
immediately (without opening the attachment, of course).

Regards.
 
P

PCR

Thanks for the warning. Looks like I need to update. Saw one of those in
my Inbox recently.

--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
should things get worse after this,
PCR
(e-mail address removed)
| This one is nasty--beware.
|
| W32.Novarg.A@mm
| aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
| Discovered on: January 26, 2004
| Last Updated on: January 26, 2004 03:30:48 PM
| Category 4 - Severe
| Dangerous threat type, difficult to contain. The latest virus
| definitions should be downloaded immediately and deployed.
| -Wild: High
| -Damage or Distribution: High
|
| http://www.symantec.com/avcenter/venc/data/[email protected]
| http://vil.nai.com/vil/content/v_100983.htm
| http://www.f-secure.com/v-descs/novarg.shtml
| http://www3.ca.com/virusinfo/virus.aspx?ID=38102
|
| --
| ~Robear Dyer (PA Bear)
| MS MVP-Windows (IE/OE)
| AH-VSOP
|
 
P

PA Bear

*One*? Count yourself lucky (and check for AV updates).
--
~PA Bear

Dopeler effect: The tendency of stupid ideas
to seem smarter when they come at you rapidly..
http://bertc.com/sniglets.htm
Thanks for the warning. Looks like I need to update. Saw one of those in
my Inbox recently.
This one is nasty--beware.

W32.Novarg.A@mm
aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
Discovered on: January 26, 2004
Last Updated on: January 26, 2004 03:30:48 PM
Category 4 - Severe
Dangerous threat type, difficult to contain. The latest virus
definitions should be downloaded immediately and deployed.
-Wild: High
-Damage or Distribution: High

http://www.symantec.com/avcenter/venc/data/[email protected]
http://vil.nai.com/vil/content/v_100983.htm
http://www.f-secure.com/v-descs/novarg.shtml
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
 
P

PCR

Well, I don't take E-mails larger than 100 KB, by message rule. It might
have been at the NetZero "E-mail on the WEB" I saw it. I don't know why
I even go there to delete them, as they don't get here into IE.

Yes, I'm updating definitions now. Thanks.

--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
should things get worse after this,
PCR
(e-mail address removed)
| *One*? Count yourself lucky (and check for AV updates).
| --
| ~PA Bear
|
| Dopeler effect: The tendency of stupid ideas
| to seem smarter when they come at you rapidly..
| http://bertc.com/sniglets.htm
|
| PCR wrote:
| > Thanks for the warning. Looks like I need to update. Saw one of
those in
| > my Inbox recently.
| >
| >> This one is nasty--beware.
| >>
| >> W32.Novarg.A@mm
| >> aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
| >> Discovered on: January 26, 2004
| >> Last Updated on: January 26, 2004 03:30:48 PM
| >> Category 4 - Severe
| >> Dangerous threat type, difficult to contain. The latest virus
| >> definitions should be downloaded immediately and deployed.
| >> -Wild: High
| >> -Damage or Distribution: High
| >>
| >> http://www.symantec.com/avcenter/venc/data/[email protected]
| >> http://vil.nai.com/vil/content/v_100983.htm
| >> http://www.f-secure.com/v-descs/novarg.shtml
| >> http://www3.ca.com/virusinfo/virus.aspx?ID=38102
| >>
| >> --
| >> ~Robear Dyer (PA Bear)
| >> MS MVP-Windows (IE/OE)
| >> AH-VSOP
 
G

Gunilla

I never get one single infected email! Talk about luck! But anyway, I get
some other sh**!

Cheers!

PA Bear said:
*One*? Count yourself lucky (and check for AV updates).
--
~PA Bear

Dopeler effect: The tendency of stupid ideas
to seem smarter when they come at you rapidly..
http://bertc.com/sniglets.htm
Thanks for the warning. Looks like I need to update. Saw one of those in
my Inbox recently.
This one is nasty--beware.

W32.Novarg.A@mm
aka W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend]
Discovered on: January 26, 2004
Last Updated on: January 26, 2004 03:30:48 PM
Category 4 - Severe
Dangerous threat type, difficult to contain. The latest virus
definitions should be downloaded immediately and deployed.
-Wild: High
-Damage or Distribution: High

http://www.symantec.com/avcenter/venc/data/[email protected]
http://vil.nai.com/vil/content/v_100983.htm
http://www.f-secure.com/v-descs/novarg.shtml
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
 
B

Bill in Co.

PCR said:
Well, I don't take E-mails larger than 100 KB, by message rule....

Oh yeah? What happens to someone if they try to get one of your "Master
Posts" then?
 
P

PCR

LOL. I don't put those into E-mails.

--
Thanks or Good Luck,
There may be humor in this post, and,
Naturally, you will not sue,
should things get worse after this,
PCR
(e-mail address removed)
| PCR wrote:
| > Well, I don't take E-mails larger than 100 KB, by message rule....
|
| Oh yeah? What happens to someone if they try to get one of your
"Master
| Posts" then?
|
|
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top