PDA

View Full Version : New Virus



I.am
01-27-2004, 07:15 AM
I know most of you dont open attachments like me. But there are many who do.

-----------

A mass-mailing virus quickly spread through the Internet on Monday, compromising computers so that they attack the SCO Group's Web server with a flood of data on Feb. 1, according to antivirus companies.

The virus--known as MyDoom, Novarg and as a variant of the Mimail virus by different antivirus companies--arrives in an in-box with one of several different random subject lines, such as "Mail Delivery System," "Test" or "Mail Transaction Failed." The body of the e-mail contains an executable file and a statement such as: "The message contains Unicode characters and has been sent as a binary attachment." ...



... More Info & Source (http://news.com.com/2100-7349_3-5147605.html?tag=nefd_top)

shn
01-27-2004, 07:18 AM
It wont be infecting mine :lol:

I.am
01-27-2004, 07:19 AM
Originally posted by shn@27 January 2004 - 00:18
It wont be infecting mine :lol:
:lol: i know

shn
01-27-2004, 07:21 AM
SCO Group sucks anyway. Their the ones that want to charge for linux.

I hope they get dd0sed out of existance!

I.am
01-27-2004, 07:29 AM
The SCO Group has incurred the wrath of the Linux community for its claims that important pieces of the open-source operating system are covered by SCO's Unix copyrights. IBM, Novell and other Linux backers strongly dispute the claims.

--->


SCO's Web site was taken offline by denial-of-service attacks a handful of times in the last year, none of which had been initiated by a virus. In the past, the company has blamed Linux sympathizers for at least one of the attacks.

shn, what are you upto now :lol:

shn
01-27-2004, 07:35 AM
:o ;)

4play
01-27-2004, 08:54 AM
this will probably look bad on the linux community. who else would want to attacks sco.

apart from google, the bsd community, the australian goverment ,just about everyone that uses linux and all the people they sent bills to for $699 for using their intellectual property even though their court case looks about ready to collapse.

this virus requires you to unzip it and execute the binary payload. unless you are a complete muppet its gonna be quite hard to get infected. ;)

I.am
01-27-2004, 07:08 PM
Yup. But its in executable form as well. It also copies itself to kazaa's shared directory and renames itself as diff. software names.

shelly
01-27-2004, 07:52 PM
WHILE WILD BIRDS apparently are dropping stone dead from the sky in Thailand from influenza, the MyDoom worm continues to wreak havoc in the PC world.
According to Kaspersky Labs, the infection – also known as Novarg, likely was written in Russia.

The firm said that over a few hours the program infected around 300,000 computers worldwide. And, Kaspersky says, the sudden explosion of the worm means that the virus writers have prepared the attack carefully.

It said that when the worm infected a critical mass of computers in the network, a command was sent to mail MyDoom out – the same approach used by Sobig.F.

The worm has a random falsified sender address, eight possible message headers, 18 possible attachment names and five possible extensions to attached files, said Kaspersky.

It spreads not only by email but through the Kazaa network, said Kaspersky, and masquerades under different names such as winamp5 and icq2004-final.

If the attachments are clicked on, the worm opens a Notebook window with random characters, makes two files in the Windows folder – taskmon.exe and shimgapi.dll. These files enter the system registry auto run key.

The worm then scans the disk for email addresses and mails copies of itself all over the place. It also installs a proxy server on the infected computer so that a machine can be used to spam or mass mail new versions, said Kaspersky.

It also installs a backdoor letting the virus writer control PCs, remove or change data, and install third party programs.

It also includes a module to organise a denial of service attack on the SCO web site, to be activated between the 1st and the 12th of February.

This is Post from another forum, my thanks to Bluedevil

james_bond_rulez
01-27-2004, 08:01 PM
these guys know a thing or two about networking.....

very impressive...

open proxy.... wow

shn
01-27-2004, 08:01 PM
Next time post the source please. A link will do. :smilie4:

fkdup74
01-27-2004, 08:12 PM
Next time post the source please. A link will do.

been posted B)

http://filesharingtalk.com/index.php?showtopic=96389

maybe i shoulda bumped this one?

shn
01-27-2004, 08:24 PM
Originally posted by FKDUP74@27 January 2004 - 14:12

Next time post the source please. A link will do.

been posted B)

http://filesharingtalk.com/index.php?showtopic=96389

maybe i shoulda bumped this one?
Sorry but I was referring to shelly's post.

fkdup74
01-27-2004, 08:34 PM
oh, oops :P B)

shelly
01-27-2004, 08:47 PM
Originally posted by shn@27 January 2004 - 20:01
Next time post the source please.  A link will do. :smilie4:
sorry my bad.
www.kaspersky.com/news (http://www.kaspersky.com/news.html?id=3629137)

footballmad
01-27-2004, 08:59 PM
I received this email earlier today but the only attachment was a .txt file.

I have AVG installed and it didn't alert me to anything.

I checked my system folder for the executable and .dll just in case and didn't find anything.

I wonder what DVDPIRATE thinks as he seems to be quite knowledgeable about this.

Lite
01-27-2004, 09:30 PM
New Virus, infects PC

What else do software based virus's infect? :unsure: :lol: ;)

Thanks for the info though ;)

I.am
01-27-2004, 09:49 PM
Originally posted by Lite@27 January 2004 - 14:30

New Virus, infects PC

What else do software based virus's infect? :unsure: :lol: ;)

Thanks for the info though ;)
:lol: i know.

But if you click on the link then you will find that to be the title of the news. I took part of the "Title" while posting here.