View Full Version : New Email Virus - Beware
LisaM
01-26-2004, 10:14 PM
FYI - there is a new email virus which is running rampant. Since our webmaster address was affected before, I want to make everyone aware of the following just in case:
Please do not open any attachments which appear to have been sent from webmaster@birdsofpreyonline.com We NEVER send out email messages with attachments.
According to news reports:
"The worm, called ``Mydoom'' or ``Novarg'' by antivirus companies, usually appears to be an e-mail error message. A small file is attached that, when launched on computers running Microsoft Corp.'s Windows operating systems, can send out 100 infected e-mail messages in 30 seconds to e-mail addresses stored in the computer's address book and other documents
Subject lines also vary. The attachments have ``.exe,'' ``.scr,'' ``.cmd'' or ``.pif'' extensions, and may be compressed as a Zip file.
One of its messages reads: ``The message contains Unicode characters and has been sent as a binary attachment.''
jaguarin
01-28-2004, 11:14 PM
Okay this virus is so dangerous that the FBI is looking for the one that create it. Is te mpst dangerous in many years. From 1-5. Is danger number 4.
Name: Mydoom, Novarg, Shimg, and Mimail
Win32.Mydoom.A
Alias: W32.Novarg.A@mm (Symantec) ,
W32/Mydoom@MM (McAfee) ,
Win32/Shimg.Worm ,
Win32/Shimg.zip.Worm,
ZIP.Mydoom.A
Category: Win32
Type: Worm
Published Date: 1/26/2004
Last Modified: 1/28/2004
Wild: HIGH
Destructiveness: HIGH
Pervasiveness: HIGH
CHARACTERISTICS
Cleaning Utility Available: To download clnmydoom.zip - a utility that cleans a local machine affected by Win32.Mydoom.A and its variants, please click here.
This utility may be especially useful for those who either do not use CA Antivirus solutions, or who may be using products based on older technology that does not support system cleaning. Please view the Removal Instructions for your CA Antivirus Solution (below) to ascertain whether you require the cleaning utility.
Warning: Before running ClnMydoom.com, please ensure that you carefully review the ReadMe.txt instruction file that accompanies this utility.
--------------------
Win32.Mydoom.A is a worm spreading via e-mail and the Kazaa P2P file sharing network. The worm has been distributed as 22,528-byte, UPX-packed Win32 executable and may be included in a ZIP archive.
Method of Distribution
Via E-mail
The worm arrives attached to an e-mail with a variable Subject and message body. The attachment also uses a variable name and extension. The From address is 'spoofed'.
The Subject may be selected from a long list carried by the worm, or may consist of randomly-generated characters. Examples of possible Subjects include:
Error
hello
HELLO
hi
Hi
Mail Delivery System
Mail Transaction Failed
Server Report
Status
The Message Body may be selected from a list carried by the worm, empty, or consist of randomly-generated, illegible garbage. An example of a Message Body used by the worm:
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
The Attachment name is chosen from a list carried by the worm, or may consist of randomly-generated characters. Examples of attachment names used by the worm:
Data
Readme
Message
Body
Text
file
doc
document
Attachments also use a variable extension. Extensions used by the worm for its attachment include .bat, .cmd, .pif, .exe, and .scr. The worm may also send itself as a .ZIP arch
Go to Mac Affe if you are infected:
http://us.mcafee.com/virusInfo/default.asp?id=mydoom
jaguarin
01-28-2004, 11:17 PM
BE CAREFUL THIS VIRUS WOULD BE DOWNLOAD BY KAAZA TOO:
http://www3.ca.com/virusinfo/virus.aspx?ID=38102
Read at the end
Jesse321
02-05-2004, 05:50 PM
This particular virus is VERY sneaky .. it can be piggy backed on picture file formats like jpg and gif as well as MP3 files .. if you have virus software keep it up to date almost daily !!
the panther
02-06-2004, 02:51 PM
Yes, beware! I get these up to six times daily! Don't open the attachment, just delete the message and make sure it's gone!
I've seen this particular one come from Easter Seals and random AOL accounts also.
Frostbite
02-06-2004, 03:27 PM
What exactly does this virus do? What makes it harmful to the computer?
LisaM
02-06-2004, 03:57 PM
I think it goes into your address book and sends virus-ridden spam emails to all of the people in your address book - thus making you into an unwitting spammer.
the panther
02-06-2004, 07:52 PM
I think they can also wreck your hard drive. Some can delete files and such. Key words: I think.
LisaM
03-03-2004, 03:22 PM
Yet another email virus is making the rounds. If you receive the following email message supposedly coming from "Birdsofpreyonline" DO NOT OPEN THE ATTACHMENT!
The subject heading is: "Important notify about your email account"
"Dear user of Birdsofpreyonline.com,
We warn you about some attacks on your e-mail account. Your computer may contain viruses, in order to keep your computer and e-mail account safe, please, follow the instructions.
Please, read the attach for further details.
Have a good day,
The Birdsofpreyonline.com team http://www.birdsofpreyonline.com
Of course, we DID NOT send it. The attachment contains a virus.
In addition, I have seen variations on this message all purporting to be notification to you of a virus on your computer and urging you to open the attachment.
cateyes
03-11-2004, 10:19 AM
any particular reason why they are using this site to put it out?
VOXMAN41
03-17-2004, 02:10 PM
Thanks for the heads up. My comp has been infected twice in the last month and I'm a little bit pissed about it.
Sxygrrl Huntress
03-18-2004, 09:09 AM
If you don't want your computer to get a virus, it's pretty much mandatory that you get Anti-virus software. There's no way around it.
VOXMAN41
03-18-2004, 09:58 AM
we have norton, but sometimes it seems like you're still vulnarble
jaguarin
03-18-2004, 10:22 AM
pc cillin 9 is the best
SevenSlave
03-18-2004, 10:32 AM
I use AVG:
http://www.grisoft.com/us/us_dwnl_free.php
It's free ... and it's obscure enough to be missed by most hackers (Rule of Thumb: If it's known to you, odds are it's also known to a hacker. :( )
vBulletin v3.0.3, Copyright ©2000-2012, Jelsoft Enterprises Ltd.