585,748 active members*
3,668 visitors online*
Register for free
Login
Results 1 to 7 of 7
  1. #1
    Join Date
    Mar 2003
    Posts
    927

    Angry New w32.novarg.@worm

    Guys,

    A New Worm was discovered today called "W32. Novarg".

    It shows up in your e-mail box with a"spoofed" e-mail from your Ip, mine was spoofed with a name of a friend on the same Ip. So it looked legit. And it showed as a txt file, safe right. NOT

    It contains a file called "Text.txt" or similar.

    If you don't have todays (1/26/04) latest virus definitions it won't show up as a virus, then when you open it , it writes to the REG and installs some .dll files to your system.

    It is a DOD and mass e-mail worm.

    It's a real pain to remove, reg edits and rescans. Even then some of the files can't be removed, just quarantined.


    So be careful and download the latest definitions from your virus provider.

    Symantec has removal info if you need to remove it.
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)

  2. #2
    Join Date
    Apr 2003
    Posts
    1873
    Thanks Ward, I just did that two days ago and sure enough there was a rather large "New Virus Definitions" tonight.


    I don't play Russian roulette, so I never ever open attachments that I am not previously made aware of or included in a reply that I am aware of.

  3. #3
    Join Date
    Mar 2003
    Posts
    927
    Good policy Ken.

    I always scan even then as to try and make sure.

    I just go caught by this one.(dark)
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)

  4. #4
    Join Date
    May 2003
    Posts
    109
    Since I just got done doing 4 hours of firewall changes for my company, so I will relay a bit of information,

    The payload looks to be a Denial of services attach against www.sco.com, so if you internet access becomes very very slow you might want to virus scan your systems.

    It also installs a back door trojan that uses port 3127, so if you have a firewall that can block in and out bound traffic I suggest you block TCP 3127

  5. #5
    Join Date
    Mar 2003
    Posts
    927
    Thanks Bcromwell,


    Symantec now says it is using ports Tcp3127 thru Tcp3198.
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)

  6. #6
    Join Date
    Mar 2003
    Posts
    6855
    Just got 20 emails with the virus.

  7. #7
    Join Date
    Mar 2003
    Posts
    779
    SCO is messing with the free open source of LINUX and pissed off some programmer people.
    Thanks

    Jeff Davis (HomeCNC)
    http://www.homecnc.info


    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •