Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Speedy Worm Invades Email Inboxes

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
CShine Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 04:59 AM
Original message
Speedy Worm Invades Email Inboxes
A rapidly spreading e-mail worm on Monday afternoon shut down e-mail systems at several large corporations and is causing problems for computer users connected to the Internet, security experts said.

Known as "MyDoom," it is the fastest spreading e-mail worm ever, according to Network Associates, the Santa Clara, Calif.-based maker of McAfee Antivirus software. The company classified it as a "high alert," its most severe status level.

Mydoom is wreaking havoc with businesses and home computer users, said Steven Sundermeier, product manager for Central Command, an anti-virus company in Medina, Ohio. Sundermeier said the worm is spreading fastest in the United States and Europe.

The virus spreads in an e-mail message that looks like it was garbled during its journey to the recipient's in-box. The body text urges recipients to click on the attached file if the contents of the message are damaged or unreadable. The virus launches when the attachment is opened.

http://www.washingtonpost.com/wp-dyn/articles/A50582-2004Jan26.html?nav=hptop_tb
Printer Friendly | Permalink |  | Top
JCMach1 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 05:28 AM
Response to Original message
1. go to the lounge---WORM_MIMAIL.R
Printer Friendly | Permalink |  | Top
 
ConcernedCanuk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 05:32 AM
Response to Reply #1
3. JC - - !! - Ya beat me by 60 seconds !!
.
.
oh well

:toast:
Printer Friendly | Permalink |  | Top
 
JCMach1 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 06:07 AM
Response to Reply #3
4. MYDOOM also seems to be propagating like a MOFO
I run CLEAN systems, but my ISP is getting smacked.

THERE WILL BE SOME DOWNTIME TOMORROW for systems that can't handle the stress...
Printer Friendly | Permalink |  | Top
 
Mari333 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 11:34 AM
Response to Reply #1
11. THANK YOU
I just used the freescan and it found one worm already in my PC and removed it...I dont need my computer guy to come to my house again, and pay him money to put on yet another patch..I swear ! I already got whaked by the goddamn Blaster worm once , twice, and dont need anymore crap
a fine time to Knight Bill Gates...SIR WORM
Printer Friendly | Permalink |  | Top
 
ConcernedCanuk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 12:37 PM
Response to Reply #1
13. It's the Number One Virus in North America right now,
.
.

and # 3 in Asia

JUst hover over the wee map and watch the specs in the list to the right

http://www.trendmicro.com/map/
Printer Friendly | Permalink |  | Top
 
ConcernedCanuk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 05:29 AM
Response to Original message
2. Aliases: W32/Mydoom@MM, Mydoom, Win32.Mydoom.A, W32.Novarg.A@mm
.
.

"Aliases: W32/Mydoom@MM, Mydoom, Win32.Mydoom.A, W32.Novarg.A@mm"

Description:

A new variant of the MIMAIL worm has been found in the wild. As of January 26, 2004 1:47 PM (US Pacific Time), TrendLabs has declared a yellow alert to control the spread of WORM_MIMAIL.R.

This mass-mailing worm selects from a list of email subjects, message bodies, and attachment file names for its email messages. It spoofs the sender name of its messages so that they appear to have been sent by different users instead of the actual users on infected machines.

It can also propagate using the Kazaa peer-to-peer file sharing network.

It performs a denial of service (DoS) attack against the software business site www.sco.com. It attacks the site if the system date is February 1, 2004 or later. It ceases attacking the site and running most of its routines on February 12, 2004.

It runs a backdoor component, which it drops as the file SHIMGAPI.DLL. The backdoor component opens port 3127 to allow remote users to access and manipulate infected systems. Note that it allows remote access even after February 12, 2004.

This worm runs on Windows 98, ME, NT, 2000, and XP.


MORE on this, solutions and links at:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MIMAIL.R

Printer Friendly | Permalink |  | Top
 
JCMach1 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 06:08 AM
Response to Original message
5. Trend Micro Officescan and my ISP
are holding fast at the moment!
Printer Friendly | Permalink |  | Top
 
papau Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 06:42 AM
Response to Reply #5
6. Avast did an overnight upgrade/fix
:-)
Printer Friendly | Permalink |  | Top
 
jukes Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 09:19 AM
Response to Original message
7. W32.Novarg.A@mm.
I'm att'ing a quote from an email warning distributed in my sigoth's office. Could be a variant or a different creature alltogether:

"A new virus began spreading yesterday afternoon, and it's currently being called W32.Novarg.A@mm. It's another mass-mailing worm that attempts to perform a denial of service attack on a website. This time the victim is www.sco.com and the worm will try this on February 1st, and the worm is scheduled to stop spreading after February 12th. Along with the DoS attack, W32.Novarg.A@mm also allows for remote control of an infected system.

The Subject will be one of the following: test, hi, hello, Mail Delivery System, Mail Transaction Failed, Server Report, Status, Error
The Message will contain one of the following: Mail transaction failed.,The message contains Unicode characters and has been sent as a binary attachment.,or The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
The Attachment will be either a .htm,.txt.or .doc file. Please do not open this under any circumstances."
Printer Friendly | Permalink |  | Top
 
sendero Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 09:28 AM
Response to Original message
8. Of course.....
... my poor wife's job as a help desk manager will be hell today. This thing hit her office yesterday afternoon.

NEVER OPEN AN ATTACHMENT UNLESS YOU KNOW WHAT IT IS AND EXPECTED IT.

The fact that so many people still fall for these ridiculous ruses is kinda sad. At my wifes employer, they have training after training session explaining this simple fact, but there is always a dim bulb who does it anyway. They better hope she doesn't figure out they did it :)
Printer Friendly | Permalink |  | Top
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 09:53 AM
Response to Reply #8
9. It's not always a matter of falling for it
MonkeySoft's Exploder, at least in previous versions, automatically opens e-mail attachments. For that very reason I refuse to use it and persuade every one in my family to avoid it. Unless they are militant about their virus definitions and are willing to fork out decent cash for the latest versions, they become suseptible to every new attachment virus.

Instead, my friends and relatives get Netscape or another browser/mail box of their choosing and a list of files to never open - EVER.

Printer Friendly | Permalink |  | Top
 
yellowcanine Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 11:08 AM
Response to Original message
10. I just erased 3 email messages generated by this worm
The subject line said "Maid Delivery System" - very clever, huh? I knew it was fake because I hadn't sent any messages for a while.
Printer Friendly | Permalink |  | Top
 
central scrutinizer Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 12:09 PM
Response to Original message
12. 12 copies and counting
All successfully deleted by our anti-virus software. I use a Mac at home so no problem there.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 26th 2024, 11:40 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC