Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

High-Outbreak Alert W32/Mydoom@MM

Thread Tools
 
Search this Thread
 
Old 26 January 2004, 09:44 PM
  #1  
Nicks VR4
Scooby Regular
Thread Starter
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Post

http://vil.nai.com/vil/content/v_100983.htm

McAfee are still currently analyzing this the threat
Old 27 January 2004, 12:32 AM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

It's big, get ready for fun in the morning.
Old 27 January 2004, 03:16 AM
  #3  
ScottyScoob
Scooby Regular
 
ScottyScoob's Avatar
 
Join Date: Apr 2002
Location: living in the Pans !!!
Posts: 1,008
Likes: 0
Received 0 Likes on 0 Posts
Post

Thought I was going to have a quiet night but not now, office in Holland is now disconnected from the network aswell as office in Melbourne grrrrrrrr

Old 27 January 2004, 09:33 AM
  #4  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Post

Mailbox being flooded with it now, but ISP is dealing with it, so its not getting through, but is damned annoying [img]images/smilies/mad.gif[/img]
Old 27 January 2004, 10:09 AM
  #6  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Post

Only 3 so far, probably from someone on SN...

All Dat'd up ( ) so bring it on
Old 27 January 2004, 11:18 AM
  #7  
Avi
Scooby Regular
 
Avi's Avatar
 
Join Date: Apr 2001
Location: Manchester
Posts: 5,084
Likes: 0
Received 0 Likes on 0 Posts
Post

W32.Novarg.A@mm

WWe've blocked thousands of these this morning, same thing [img]images/smilies/mad.gif[/img]

[Edited by Avi - 1/27/2004 11:20:37 AM]
Old 27 January 2004, 12:00 PM
  #8  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

McAfee Stinger has been updated to deal with this threat and can be downloaded free from here http://vil.nai.com/vil/stinger/
Old 27 January 2004, 04:52 PM
  #9  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

A plea to Sys Admins...

Please turn off sending AV notifications to the external sender.

I'm not infected, I didn't e-mail your user, it was wasn't me.

Gawd knows how much extra traffic the AV alerts generate and it's all pointless with spoofed From: fields.
Old 27 January 2004, 05:01 PM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Chris

Same problem here.....makes a nice DoS .....
Old 27 January 2004, 05:20 PM
  #11  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Post

Chris, think that is what my problem in my other thread is, some sysadmin is sending me out, so far 200 plus, notifications. mmm, nice, pity I'm on a mac which won't be effected by this (though I think I can still spread it).
Old 27 January 2004, 05:23 PM
  #12  
Hobo_Jojo
Scooby Regular
 
Hobo_Jojo's Avatar
 
Join Date: Aug 2003
Posts: 1,981
Likes: 0
Received 0 Likes on 0 Posts
Post

not had this yet, tho i never seem to get any of these virus out breaks coming through to me - as yet to ever get a virus (touch wood)
Old 27 January 2004, 05:29 PM
  #13  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Not as big as the DOS SCO's going to get on Feb 1st. Author's an obvious Linux lover.
Old 27 January 2004, 05:30 PM
  #14  
Avi
Scooby Regular
 
Avi's Avatar
 
Join Date: Apr 2001
Location: Manchester
Posts: 5,084
Likes: 0
Received 0 Likes on 0 Posts
Post

Please turn off sending AV notifications to the external sender.
Here Here.. try explaining to a secretary that someone has sfoofed their address, makes more trouble than it's worth.
Old 27 January 2004, 06:17 PM
  #15  
ChristianR
Scooby Regular
iTrader: (1)
 
ChristianR's Avatar
 
Join Date: May 2001
Location: Europe
Posts: 6,329
Likes: 0
Received 1 Like on 1 Post
Post

so what has sco done then, which wants the creator of the virus to attack it? guess it makes a change from a microsoft domain!
Old 27 January 2004, 06:37 PM
  #16  
Monkeh
Scooby Regular
 
Monkeh's Avatar
 
Join Date: Jun 2003
Location: A Shanty Town near you !
Posts: 547
Likes: 0
Received 0 Likes on 0 Posts
Post

Hehe
I love Norton Corporate AV it updates all the clients automatically
only 1 user out of 250 in my office has had it so far
Old 27 January 2004, 07:53 PM
  #17  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Post

had 4 of these today
all .zip files
Old 27 January 2004, 10:38 PM
  #18  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Christian, take a look on SCO.com, might have something to do with them asking Linux users for a licence fee.
Old 28 January 2004, 08:48 AM
  #19  
ChristianR
Scooby Regular
iTrader: (1)
 
ChristianR's Avatar
 
Join Date: May 2001
Location: Europe
Posts: 6,329
Likes: 0
Received 1 Like on 1 Post
Post

cheers, just seen this on the sophos website, which explains it well (http://www.sophos.com/virusinfo/articles/linuxwars.html) :

MyDoom worm: the latest weapon in the Linux wars? Sophos comments
Virus researchers at Sophos are suggesting that the W32/MyDoom-A worm, currently spreading widely across the internet, may have been deliberately constructed as a weapon in the current round of "Linux wars". The worm launches a distributed denial of service attack against the website of SCO, who have recently courted controversy in the Linux community. Such an attack could potentially knock SCO's website off the internet.

In May 2003 US-based SCO claimed that versions of the Linux open source operating system use code owned by SCO. It has begun offering Linux users a licence to protect them against possible legal action. Leading Linux developers such as Linus Torvalds, the inventor of Linux, have denied that Linux source code contains any SCO intellectual property. SCO has also launched legal actions against IBM, Red Hat, and Novell.

"Rows between SCO and the open source community have been continuing for some months. The MyDoom worm takes the Linux Wars to a new intensity," said Graham Cluley, senior technology consultant for Sophos. "It appears that the author of MyDoom may have taken the war of words from the courtrooms and internet message boards to a new level by unleashing this worm which attacks SCO's website. If we ever get our hands on MyDoom's creator my guess is that he will be an open source sympathiser. Of course, it's the last kind of assistance the open source community would want at this time."

Once the MyDoom worm has infected a PC it attempts to spread via mass-emailing, and turns the computer into a "zombie" which can unwittingly launch the attack against SCO's website between 1 and 12 February.

"All computer users should ensure their computers are adequately protected against these kind of attacks with updated anti-virus and firewall software," continued Cluley.
Old 29 January 2004, 01:27 AM
  #20  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Post

5 today
Old 29 January 2004, 08:18 AM
  #21  
ChristianR
Scooby Regular
iTrader: (1)
 
ChristianR's Avatar
 
Join Date: May 2001
Location: Europe
Posts: 6,329
Likes: 0
Received 1 Like on 1 Post
Post

75 between 9pm a 8am..
Old 29 January 2004, 10:26 AM
  #22  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Doing my bit to ecourage the disabling of auto responders. http://news.zdnet.co.uk/internet/sec...9143774,00.htm

New variant out yesterday, this one attacks Microsoft. McAfee products detected it before it was composed.
Old 29 January 2004, 03:04 PM
  #23  
sasim
Used to work here!!
 
sasim's Avatar
 
Join Date: Jun 2000
Location: Peterhead, Scotland
Posts: 1,488
Likes: 0
Received 0 Likes on 0 Posts
Post

our IT boys tell me that the system has rejected 6000 e-mails in the least 1/2 of them were infected

They dindn't say why the other 3000 were rejected
Old 29 January 2004, 03:47 PM
  #24  
rogp
Scooby Regular
 
rogp's Avatar
 
Join Date: Mar 2003
Posts: 455
Likes: 0
Received 0 Likes on 0 Posts
Post

I've had a steady stream today, about 2 every 5 minutes.
Old 29 January 2004, 06:24 PM
  #25  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Post

Well, things are settling down here.

Funny thing is that the PC users have not reported that many alerts from Norton AV, neither have the other mac users, looks like it's me that has been hit the hardest then! lol

I've got a mac, so don't get infected, but recived (marked as junk though) 2000 messages, looking at them, 80 percent were, as per another post, an email virus notification from someone's mail server, of the remaining 20 percent, 5 percent were actually infected messages, the remaing 15 percent were 'mail delivery' errors, again, due to the virus.

Thankfully the email notifcation thing seems to have stopped, as it was getting very silly.
Old 29 January 2004, 06:45 PM
  #26  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Cool

Glad I'm not working atm
Old 29 January 2004, 10:03 PM
  #27  
ianmiller999
Scooby Regular
 
ianmiller999's Avatar
 
Join Date: Feb 2003
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
Post

Just had 3 so i am expecting a lovely full email box tomorrow. Speaking to my friend at fuzzmail now to see if he can stop the emails getting through to my web account.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
smunns
ScoobyNet General
286
01 October 2015 11:51 AM
smunns
Dealer and Third Party Supplier Queries
5
14 September 2015 08:08 PM
David_Wallis
Computer & Technology Related
7
13 June 2002 04:32 PM
BigGT3Fan
Computer & Technology Related
4
14 March 2002 11:11 AM



Quick Reply: High-Outbreak Alert W32/Mydoom@MM



All times are GMT +1. The time now is 05:03 AM.