Page 5 of 9 FirstFirst ... 34567 ... LastLast
Results 41 to 50 of 83

Thread: Virus Alert: Novarg / MiMail / MyDoom

  1. #41
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    Originally posted here by thadbme
    How much traffic is everyone seeing from this thing?
    Since midnight last night to right now, I have quarantined or block just under 2000 copies, not all that many when I compare it to Klez when it first started.

    Cheers:
    DjM

  2. #42
    Yes, that's my CC number! 576869746568617's Avatar
    Join Date
    Dec 2003
    Location
    Earth
    Posts
    397
    It's a virus, so it's in all likelyhood extremely buggy. Therefore, I'd say yes to your question.

    As for how much traffic, well...I have an OC3 line and out of 44mbps I have around 6mbps available, most of the used bandwidth is VPN and e-commerce traffic (28.7mbps), but the rest is because the mailserver is being hammered. You can draw your own conclusions from that.

  3. #43
    Senior Member
    Join Date
    Aug 2003
    Posts
    119
    That makes me not feel so bad about my, estimated 50 or so copies of it. Wow, you my friend are getting hammered by this thing

    Anyways good info and thanks for the response. When Sobig F came out I received around 3000 hits a day from it, pailing in comparison to this thing, atleast for now, and I'm hoping it will stay that way.

  4. #44
    Senior Member cwk9's Avatar
    Join Date
    Feb 2002
    Posts
    1,207
    SCO has now issued a bounty for MyDoom creator. Sounds like a good deal, virus writer goes to jail, some one gets $250K and SCO will be one setup closer to bankruptcy.
    Its not software piracy. I’m just making multiple off site backups.

  5. #45
    WAS Sent To me In my Email So thought i would post it:::::

    The W32.Novarg.A@mm virus is a mass-mailing worm that is very active on the Internet. While we are currently taking measures to protect our Email users, you can protect yourself by identifying and deleting emails with Novarg characteristics. Please do not report these emails as Spam.
    Note: Your computer should not be infected by this virus unless you open a corrupted attachment.

    What to look for:
    Emails infected with the Novarg virus have, thus far, been approximately 30-35KB in size and have exhibited the following characteristics:

    Subject line:

    Hello
    Hi
    Test
    Status
    From line:
    Contains spoofed addresses - which means that the name that appears in the "From" field is probably not the real sender.

    Body:

    Tends to be unreadable; gibberish. You may also see the following message: "The message contains Unicode characters and has been sent as a binary attachment".
    Attachment file extensions:

    .zip (most common)
    .bat
    .cmd
    .exe
    .pif
    .scr
    Known attachment file names:

    body (.zip, .bat, etc.)
    readme
    file
    message
    text
    jasrjx
    dajtl
    document
    What you can do:
    Delete messages with the above characteristics and be sure to delete them from your Trash Folder. Knowing some of the above characteristics about this virus, you may wish to set up custom filters and route most of these virus emails directly to your Trash or Bulk Folder. This way, you can keep your inbox free of most of these messages. Just be sure to check your Trash or Bulk Folder and empty them on a regular basis in order to free up space in your email account.

  6. #46
    Senior Member
    Join Date
    Jan 2004
    Posts
    124
    I got one I got one I got one

    Unfortunately my NAV deleted the attachment before I could run it... damn one more infection that I didn't catch

    now for serious, my company got e-mail stating that one infected e-mail was sent from us (it is a small company so we use just one e-mail). I am scaning all computers in our LAN but there is no any trace of virus. Does anyone know if this virus is spoofing From: field in e-mail header? I have doublecheck it, none of my bosses didn't open our e-mail from home.
    Ikalo
    ------
    Make your knowledge your deadliest weapon.

  7. #47
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Yes, it is spoofing the from. A large number of my users have received "your email has been rejected because of the MyDoom.A virus" when I know for a fact that they don't have it.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  8. #48
    Yes, that's my CC number! 576869746568617's Avatar
    Join Date
    Dec 2003
    Location
    Earth
    Posts
    397
    Not to doubt you, TigerShark, but how do you know for a fact? (runnung linux or something)
    Just curious. I knew my users didn't have it, but my mail server....it was ate up!

    Guess that's what I get for using a win server for mail......I use UNIX for everything else so I figured I'd use one Windows server, that won't hurt so bad...I can use it for mail. Didn't think about the fact that most viri are for Windows!

  9. #49
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    57: It's really rather easy.....

    If you are a virus carrying your own SMTP engine you might get into my network prior to a protective definition being downloaded but I'm afraid you aren't getting back out again.

    All incoming mail to the several domains I host is funnelled through a Windows 2000 server in my DMZ. This server runs GFI Mail Essentials and MailSecurity. MailEssentials removes the Spam and MailSecurity scans for viruses and updates the definitions hourly. Acceptable mail is then passed inbound to the trusted network to Microsoft Exchange Servers that run NAV for Exchange across them just for a giggle..... So you have a maximum of 1 hour's window to get in after a virus def has been published.

    Then comes the easy part.... Sucker one of my users into clocking on you.... Bingo - You are in business..... Not.....

    You see, when you start sending out all your emails you are going to get a shock..... You can't make a connection to any mailserver in the world..... Darned shame really..... You got so far.... But my firewall won't let any machine within my network send out SMTP/IMAP except the Mail Servers themselves. What's more, when a machine does try to send outbound email the Firewall sticks a popup on my screen informing me of the attempt.....

    So, you see, I know for a fact that users within my network _cannot_ send out email willy-nilly. So when they receive a message saying their mail was blocked because of an infection I can rest easy - and if I want to get paranoid I can check the firewall logs for "Deny Out SMTP"......

    ..... And it's all done with Windows servers and a firewall...... Amazing huh?
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  10. #50
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    Originally posted here by 576869746568617
    Not to doubt you, TigerShark, but how do you know for a fact?
    Just to add to what Tiger said, this quote is from the Symantec site.

    The email will have the following characteristics:

    From: May be a spoofed from address
    Now while it does say "may be spoofed", history teaches us that the new crop of viruses making the rounds use this technique. As well, the messages I am seeing also lead me to the same conclusion, specifically, e-mails coming from accounts I know have been deleted for more than a year.

    Cheers:
    DjM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •