Results 1 to 7 of 7

Thread: New Virus Alert!

  1. #1
    newcster68's Avatar Taxicab Co. Owner
    Join Date
    Jan 2003
    Location
    Greensboro, NC
    Age
    56
    Posts
    970


    New virus infects PCs, whacks SCO

    update A mass-mailing virus that quickly spread through the Internet on Monday planted a file that will instruct infected computers to attack the SCO Group's Web server with a flood of data on Feb. 1.

    The virus--known as MyDoom, Novarg and as a variant of the Mimail virus by different antivirus companies--arrives in an in-box with one of several different random subject lines, such as "Mail Delivery System," "Test" or "Mail Transaction Failed." The body of the e-mail contains an executable file and a statement such as: "The message contains Unicode characters and has been sent as a binary attachment."

    "It's huge," said Vincent Gullotto, vice president of security software maker Network Associates' antivirus emergency response team. "We have it as a high-risk outbreak."
    In one hour, Network Associates itself received 19,500 e-mails bearing the virus from 3,400 unique Internet addresses, Gullotto said. One large telecommunications company has already shut down its e-mail gateway to stop the virus.

    Once the virus infects a Windows-running PC, it installs a program that allows the computer to be controlled remotely. The program primes the PC to send data to the SCO Group's Web server, starting Feb. 1, a virus researcher said on the condition of anonymity.

    The SCO Group has incurred the wrath of the Linux community for its claims that important pieces of the open-source operating system are covered by SCO's Unix copyrights. IBM, Novell and other Linux backers strongly dispute the claims.

    The company's Web site was slow to load on Monday afternoon, a SCO spokesperson acknowledged, but the site was still accessible from the World Wide Web.

    SCO's Web site was taken offline by denial-of-service attacks a handful of times in the last year, none of which had been initiated by a virus. In the past, the company has blamed Linux sympathizers for at least one of the attacks.

    Antivirus companies were scrambling on Monday afternoon to learn more about the virus, which started spreading at about noon PST. The virus affects computers running Windows versions 95, 98, ME, NT, 2000 and XP.

    "A lot of the information is encrypted, so we have to decrypt it," said Sharon Ruckman, a senior director of antivirus software maker Symantec's security response center. Symantec has had about 40 reports of the virus in the first hour, a high rate of submission, Ruckman said.

    The virus installs a Windows program that opens up a "back door" in the system, allowing an attacker to upload additional programs onto the compromised device. The back door also enables an intruder to route his connection through the infected computer to hide the source of an attack.

    The virus also copies itself to the Kazaa download directory on PCs, on which the file-sharing program is loaded. The virus camouflages itself, using one of seven file names, including Winamp5, RootkitXP, Officecrack and Nuke2004. Variations in the body text include: "The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment."

    Early data indicated an epidemic several times the size of the Sobig.F virus, which caused widespread infections last summer, said Scott Petry, a vice president of engineering at e-mail service provider Postini.

    "At its current run rate, we will trap almost 8 million in a day," Petry said. The company quarantined only 1,400 copies of Sobig.F in its first day and 3.5 million copies of the virus during that epidemic's peak 24-hour period.

    Mail systems that remove executable files from e-mails can stop the program from spreading.

  2. The Drawing Room   -   #2
    Lick My Lovepump
    Join Date
    May 2003
    Age
    21
    Posts
    2,657
    Shouldn't this be in Software ?

    EDIT: Ooh yes, 'tis a very nasty virus also.

  3. The Drawing Room   -   #3
    newcster68's Avatar Taxicab Co. Owner
    Join Date
    Jan 2003
    Location
    Greensboro, NC
    Age
    56
    Posts
    970
    Originally posted by Mad Cat@27 January 2004 - 14:54
    Shouldn't this be in Software ?

    EDIT: Ooh yes, 'tis a very nasty virus also.
    Well, let's see. uum this is a choosy subject to say where it goes. Since this is news and it does affect everybody around the world, I'd say it goes here. But, that's just me. I don't see why it should go in software cause it has nothing to do with a software issue. Maybe it might belong in Internetworld though.

  4. The Drawing Room   -   #4
    you know 99% of the time virus (and other forms of malware) spread because the user is eather too ignorant/stupid/don't care or just are unaware of what can harm their computer.

  5. The Drawing Room   -   #5
    Poster
    Join Date
    Jun 2003
    Location
    Yet to be determined
    Posts
    993
    b00! :

    Users are too gullable in this date and time.. Common sense should tell you not to download and open attachments.

  6. The Drawing Room   -   #6
    MagicNakor's Avatar On the Peripheral
    Join Date
    Nov 2002
    Posts
    5,202
    I got that attachment today. Antivirus caught it. Of course, you'd have to be pretty stupid to open an attachment from (in my case) a server in Peru that you've never dealt with...

    things are quiet until hitler decides he'd like to invade russia
    so, he does
    the russians are like "OMG WTF D00DZ, STOP TKING"
    and the germans are still like "omg ph34r n00bz"
    the russians fall back, all the way to moscow
    and then they all begin h4xing, which brings on the russian winter
    the germans are like "wtf, h4x"
    -- WW2 for the l33t

  7. The Drawing Room   -   #7
    Poster
    Join Date
    Jun 2003
    Location
    Yet to be determined
    Posts
    993
    This virus actually hit my school's network and the e-mail server is down.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •