Nasty Virus
Posted: 1/28/2004, 12:19 am
just warning you guys...i got this email from my roomate and my computer was being a turd and so i downloaded norton antivirus. it found both "taskmon" and "novarg" on my computer so watch out.
The "next big one" may have been released yesterday. It hit both corporations as well as home users hard yesterday and is still growing. The formal title is Mydoom, it is also known as Novarg and WORM_MIMAIL.R. This one is hard to pin down characteristics as it has a random Subject line generator as well as a random Body generator. It is an address stealing worm so the From address will be someone you know. If you are a KaZaa user, you are particularly susceptible to this attack.
Some of the Subject lines that have been seen:
"Error
Status
Server Report
Mail Transaction Failed
Mail Delivery System
hello
hi"
Some of the Body text that has been observed:
"The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available."
It delivers its payload as an attachment which also has a variety of names. You should delete the email immediately and not open the attachment. We have updated the JNL systems, but you should ensure you have the latest anti-virus protection on your home computers. If you think there is a chance that you were hit by this worm, look for the file "taskmon.exe" on your PC; if you have this file, you should unplug from the web and clean your PC. Note that you may not have noticed the impact of the worm yet, but if it is resident on your PC, a secondary payload will activate on Feb 1 and start a Denial of Attack Service. As always, use good sense when opening emails from the web.