Subscribe: Subscribe to BigBlueBallRSSSubscribe to BigBlueBall by emailEmailSubscribe to BigBlueBallTwitter


Go Back   BigBlueBall Forums > Site News & Announcements
Forgot Password? Register
Connect with Facebook

Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 01-27-2004, 05:11 PM
Dr Kimble's Avatar
I Love Pancakes!
 

Join Date: Oct 2003
Location: CA, USA
Posts: 972
Dr Kimble has a spectacular aura about (100)Dr Kimble has a spectacular aura about (100)
Send a message via ICQ to Dr Kimble Send a message via AIM to Dr Kimble Send a message via MSN to Dr Kimble Send a message via Yahoo to Dr Kimble Send a message via Skype™ to Dr Kimble
Mail Worm

I was getting these weird emails and now I know why. I read this in the paper today. Beware:

NEW VIRUS: Mail Worm in One of Every 12 Messages
SAN JOSE, Calif. (Jan. 27) -- An e-mail worm that looks like a normal error message but actually contains a malicious program continued to snarl computers around the world on Tuesday.

MessageLabs Inc., which scans e-mail for viruses, said 1 in every 12 messages contained the worm, called ''Mydoom'' or ''Novarg.'' Security experts described it as the largest virus-like outbreak in months, one made more problematic by its timing.

The worm began spreading rapidly Monday during business hours in the United States, where the world's computers are concentrated. Many recent outbreaks began during Asian business hours - overnight in the United States - allowing anti-virus vendors to develop new defenses by the time U.S. companies opened up shop.

''Whenever a virus begins to start in the states, it usually becomes much bigger,'' said Vincent Gullotto, an anti-virus researcher at Network Associates Inc.

Some corporate networks were clogged with infected traffic within hours of its appearance, and operators of many systems voluntarily shut down their e-mail to keep the worm from spreading during the cleanup.

Mikko Hypponen, manager of anti-virus research at F-Secure Corp. in Finland, estimated that 200,000 to 300,000 computers were hit worldwide.

The worm infects computers using Microsoft Corp.'s Windows operating systems, though other computers were affected by network slowdowns and a flood of bogus messages.

Unlike other mass-mailing worms, Mydoom does not attempt to trick victims by promising nude pictures of celebrities or mimicking personal notes. Instead, one of its messages reads: ''The message contains Unicode characters and has been sent as a binary attachment.''

''Because that sounds like a technical thing, people may be more apt to think it's legitimate and click on it,'' said Steve Trilling, senior director of research at the computer security company Symantec.

Besides sending out tainted e-mail, the program appears to open up a backdoor so hackers can take over the computer later.

Hackers, for instance, could later install programs that log keystrokes on infected machines, collecting username and passwords of unsuspecting users and distributing them to strangers. Symantec, however, backed away from earlier statements that such a program was included with the worm.

The worm also places copies of itself in folders used for sharing files through the Kazaa file-sharing network. Remote users who download those files and run them could be infected. Security experts say the spread through Kazaa is minor compared with e-mail.

The worm was also programmed to flood the Web site of The SCO Group Inc. beginning on Feb. 1 with requests in an attempt to crash its. SCO's site has been targeted in other recent attacks because of its threats to sue users of the Linux operating system in an intellectual property dispute.

Microsoft offers a patch of its Outlook e-mail software to warn users before they open such attachments or prevent them from opening them altogether. Antivirus software also stops infection.

Christopher Budd, a security program manager with Microsoft, said the worm does not appear to take advantage of any Microsoft product vulnerability.

''This is entirely a case of what we would call social engineering - enticing users to take actions that are not in their best interest,'' he said.

Mydoom isn't the first mass-mailing virus of the year. Earlier this month, a worm called ''Bagle'' infected computers but seemed to die out quickly.

Reply With Quote
 

 
  #2 (permalink)  
Old 02-02-2004, 02:42 AM
Member
 

Join Date: Jun 2003
Location: India.
Posts: 87
deepthought is on a distinguished road (10)
For more info -> www.symantec.com

You can run the tool provided to remove the virus. Also use Liveupdate to update your virus definitions.
Reply With Quote
Reply


Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools


Similar Topics
Topic Topic Starter Forum Replies Last Post
MSN Messenger Hit by Double-Whammy Worm Jeff Windows Live Messenger News 0 02-03-2005 04:16 PM
PCWorld: New Worm Travels by IM Charles Online Privacy, Safety & Security 1 08-20-2004 09:51 PM
Trilllian Pro 1 Mail Sounds ? sporman10 Trillian 1 09-11-2003 05:05 AM
Symantec Says Worm Attacks E-Mail, Instant Messages BigBlueBall News General / Other IM News 0 04-09-2002 01:00 AM
SpotLife Announces Agreement with Yahoo! Mail BigBlueBall News General / Other IM News 0 11-26-2001 01:00 AM

 

All times are GMT -5. The time now is 03:31 AM.