PDA

Click to See Complete Forum and Search --> : Zafi worm hitting hard


SirDice
June 14th, 2004, 01:18 PM
Heads up people. There's a new virus on the block.
It seems to spread pretty fast and is pounding our servers damn hard (about 700 in the past half hour).

http://vil.nai.com/vil/content/v_126242.htm

Tedob1
June 14th, 2004, 04:34 PM
thanks SirDice!

its really nice to know whats happening before i get in to work. walk in ... boss says "new virus out" i tell'em "Yup! nai calls it zafi...blah, blah, blah" and im a friggen guru. saves so much time in the morning. hit f5 to refresh last nights page and everything you need to know...

MURACU
June 14th, 2004, 04:52 PM
Thanks for the head up.

madjag291
June 14th, 2004, 07:17 PM
heh.. i think i should install an AV now-a-days with all the worms and virii running loose.. but it feels sooo nice having my resources unused =P

adiz
June 14th, 2004, 08:03 PM
boss says "new virus out" i tell'em "Yup! nai calls it zafi...blah, blah, blah" and im a friggen guru. saves so much time in the morning.

Exactly my thoughts. Haha it is awesome.


- Adiz

jonathans_daddy
June 14th, 2004, 08:18 PM
Hmm... not much of a problem here. I've received a grand total of 3. Must have something to do with my content filtering rule that blacklists any IP addresses that send me virii. :-)

CXGJarrod
June 14th, 2004, 08:25 PM
Got 200 emails from a mailserver that "claims" we sent them the virus from an alias account on our domain. If your out there admins turn the autoreply off.

dinowuff
June 14th, 2004, 08:49 PM
CXGJarrod-
I second, third and forth that motion - Please turn off the autoreply

Tiger Shark
June 14th, 2004, 08:56 PM
MEMO

TO: CXGJarrod

From: The admins

Date: Most of the Time
-------------------------------------------------------------------------------
Subject: Auto-reply

Mr. Jarrod

Most of us are out to lunch. Didn't you notice?

Signed

Duty Admin

Relyt
June 15th, 2004, 02:50 AM
Thanks SirDice,

madjag291,

heh.. i think i should install an AV now-a-days with all the worms and virii running loose.. but it feels sooo nice having my resources unused =P

:D At least if you use your resources you might have some control over what gets used and what for. If someone decides for you.....oh la la.....what fun they will have. :eek:

cheers

Soda_Popinsky
June 15th, 2004, 04:16 AM
I just had to install 2 more criticals for xp... 2 for directx... kinda weird, I didn't hear anything about them.

Relyt
June 15th, 2004, 04:28 AM
Soda_Popinsky,

Yeah, thanks for reminding me! :D Maybe if I stick my head under the pillow the need will just go away. Seems to becoming a never ending battle. Patch MS, Patch *nix, Patch MS, Patch *nix........

working on the fix for the 2.6.xxx kernal, then off to MS for the criticals... :)

cheers

The Grunt
June 15th, 2004, 06:18 PM
Can't wait till we have AI's doing the OS programming for us, no more vulns! haha...

SirDice
June 16th, 2004, 11:52 AM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=258712#post758065) by The Grunt
Can't wait till we have AI's doing the OS programming for us, no more vulns! haha...

Unless the AI was written by a human ;)

The only vulnerability this one abuses is the one inside the lusers head (Oh, look, how nice, an ecard, click-click). Still haven't figured out how to format, reinstall and patch a luser :D

the_JinX
June 16th, 2004, 01:34 PM
Yeah, have been getting over 1500 of these today (about 1200 yesterday..)

Also them damn "you sent me a virus" auto messages suck..
I have sent some of the admins of such sites a mail along the lines of.

You sir, are not a part of the sollution,
you are a part of the problem !
Turn them *insert strong language* automatic warning mails of !!

SirDice
June 16th, 2004, 01:51 PM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=258712#post758470) by the_JinX
Yeah, have been getting over 1500 of these today (about 1200 yesterday..)

Also them damn "you sent me a virus" auto messages suck..
I have sent some of the admins of such sites a mail along the lines of.
[/B]

It's getting close to 7-8000 a day here :(

The auto-replies suck indeed. If it's a Dutch company I will call them directly. You won't believe what total n00bs I get on the phone claiming to be responsible for the email of their company :rolleyes:

You could also email this link to them:
http://www.virusalert.nl/?show=nieuws&id=559
(Dutch anti-virus site)

the_JinX
June 16th, 2004, 02:19 PM
Good idea..
I used to call local companies too, but it was not good for my blood pressure, and faith in humanity as a whole ;)

You'd think that with all the media coverage nowadays most admins would be aware..
But on the other hand, you'd expect people to stop opening non-requested attachments too !!

Cope57
June 19th, 2004, 12:28 AM
Even though I have not used M$ for almost a year, I do recall the AV program I did use. I would recommend it to anyone.

AVG Free Edition Anti-Virus (http://www.grisoft.com/us/us_dwnl_free.php)

They have received the VB100% in the test of Virus Bulletin in June 2004 on Windows XP platform.
Also...
100% detection rate of AVG Anti-Virus System is continuously certified by independent ICSA laboratories.

You use what you want, but use something! and keep it up to date!

Have a good day.