Novarg virus
Author
Discussion

simpo two

Original Poster:

89,683 posts

282 months

Tuesday 27th January 2004
quotequote all
Just had three Novargs turn up at my front door.

I googled for W32.Novarg.A@mm and was a bit alarmed to find NO results! But then I found more info at:
www.f-secure.com/v-descs/novarg.shtml

So keep your AV stuff up to date chaps!

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
It's an alias for the W32/Mydoom@MM virus.

See here - http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100983&cid=9539

SoftwareSorcerer

437 posts

266 months

Tuesday 27th January 2004
quotequote all
My servers have blocked 148 of these today.

Not looking forward to the traffic they will generate in a few days time.

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
we've stopped over half a million of them so far, and they're piling in at one hell of a rate -- currently just over 50,000 per hour

>> Edited by TheHobbit on Tuesday 27th January 13:01

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
One of our senior lot has just opened it, having binned the "do not open this file" warning...

Bloody snotmail...

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
Podie said:
One of our senior lot has just opened it, having binned the "do not open this file" warning...

Bloody snotmail...


Ooops.

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
TheHobbit said:

Podie said:
One of our senior lot has just opened it, having binned the "do not open this file" warning...

Bloody snotmail...



Ooops.


more like...

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
Podie said:
more like...




We're not allowed to use Hotmail or any webmail for that matter from within the companies network.....

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
TheHobbit said:

Podie said:
more like...





We're not allowed to use Hotmail or any webmail for that matter from within the companies network.....


nor are we..!!!

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
Podie said:
nor are we..!!!


Ah..... that would be even more frustrating then...

mondeoman

11,430 posts

283 months

Tuesday 27th January 2004
quotequote all
I'm picking up a load of these today .... "W32.Dumaru.Y@mm"

Same thing?

meeja

8,290 posts

265 months

Tuesday 27th January 2004
quotequote all
mondeoman said:
I'm picking up a load of these today .... "W32.Dumaru.Y@mm"

Same thing?


http://securityresponse.symantec.com/avcenter/venc/data/w32.dumaru.y@mm.html

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
we have now stopped over 1.2 million copies of MyDoom, with virus infection running at 1 in every 12 emails processed

MyDoom is now officially worse than SoBig.

simpo two

Original Poster:

89,683 posts

282 months

Tuesday 27th January 2004
quotequote all
You have to ask - what's the ing point of it all?

Still, any nasties that turn up here get flushed straight down the bog, so I'm doing my bit to clean up the world!

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
simpo two said:
You have to ask - what's the ing point of it all?


Someone trying to plot the downfall of MS or some vain attempt at getting themselves noticed... or maybe even a form of terrorism to try and bring down the Western world...?!!?

FourWheelDrift

91,220 posts

301 months

Tuesday 27th January 2004
quotequote all
TheHobbit said:
we have now stopped over 1.2 million copies of MyDoom, with virus infection running at 1 in every 12 emails processed

MyDoom is now officially worse than SoBig.


Bloody Hell, where do you work, the Microsoft Support centre?

I've only received 5 today all "from" spoofed alias's of my mailserver. But all stopped and disinfected by Norton.

Podie

46,646 posts

292 months

Tuesday 27th January 2004
quotequote all
FourWheelDrift said:

TheHobbit said:
we have now stopped over 1.2 million copies of MyDoom, with virus infection running at 1 in every 12 emails processed

MyDoom is now officially worse than SoBig.



Bloody Hell, where do you work, the Microsoft Support centre?

I've only received 5 today all "from" spoofed alias's of my mailserver. But all stopped and disinfected by Norton.


No real problems... except users who access webmail!

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
FourWheelDrift said:
Bloody Hell, where do you work, the Microsoft Support centre?

I've only received 5 today all "from" spoofed alias's of my mailserver. But all stopped and disinfected by Norton.


Erm.... shameless plug coming up... MessageLabs. We scan over 25 million e-mails per day and rising for e-mail security threats including viruses, spam, porn and other dangerous content.

I wasn't posting in order to plug, just thought as the thread had been started, people might be interested in how it was developing......

mondeoman

11,430 posts

283 months

Tuesday 27th January 2004
quotequote all
seems to be a lot from the netherlands.....

TheHobbit

1,189 posts

268 months

Tuesday 27th January 2004
quotequote all
mondeoman said:
seems to be a lot from the netherlands.....

we saw our first copy from Russia at 13:00 yesterday. most (of ours, so far) have come from the US.....