January 27, 2004
The Latest Virus
Venomous Kate over at Electric Venom has got a pretty timely warning out about the MyDoom/Novarg virus that has been out spamming in full force for the last couple of days.
The only thing that I will mention is that MyDoom/Novarg is a spoofing virus. In other words, it will pull an email address out of your adress book and make it appear that the emails that it sends out are actually coming from someone else. Helps to keep the infected owner from catching on.
I know that it is a spoofing virus because apparently a spammer on the comcast network got infected. I know it has to have been a spammer, as the email that it is being claimed was used to send the two emails is one that I haven't really used in a couple of years (not since I got my own domain) except for getting emails from a very few select people - along with a ton of spam. Yet the return message I got from a computer in the .si domain informed me that the email that I sent using that address over the comcast system contained a virus. I just happened to have updated my virus definitions and did a full system scan last night AND I went in to check the registry for any signs of the virus, but none were to be found.
Take Kate's advice: update your definitions, do a system scan and then use of the online scanners to just double check. Then use both Spybot and AdAware religiously to keep the spyware programs from doing as much damage to your computer as the viruses. One of the reasons I did the full system scan was because in the span of 24 hours I had over 140 new registry entries, spyware files and folders installed on the computer (AOL and Yahoo! chat rooms seem to be where they are coming from the most. The pains of having a teenager. At least the chat rooms are "normal" ones.).
Also, if one of the programs returns an oddlooking file name, don't be afraid to google it. In doing so a few weeks ago I found a small program called HijackThis! which will produce a log that some of the more tech savvy users of sites like Computer Cops can decipher to help you in your quest to eliminate spyware, malware, and viruses from your system.
Posted by Chris at January 27, 2004 05:38 PM | TrackBack | Linked by:world @ haydur linked with Not.MyDoom.*
This is pretty interesting. I thought these worms were still following the basic techniques from the love bug days, when they used a plain socket connection and used Outlook/OE server settings to forward themselves. This thing even has it's own SMTP engine... wow, talk about hating corporations!
Posted by: Haydur at January 29, 2004 04:22 PMComments have been closed on this entry in an effort to conserve disk space. If you have feedback on this entry, please email me at blog - at - cbnoble.com.


