Results 1 to 7 of 7

Thread: New w32.novarg.@worm

  1. #1
    wms
    wms is online now
    Moderator wms's Avatar
    Join Date
    Mar 2003
    Location
    United States
    Posts
    898
    Downloads
    0
    Uploads
    0

    Angry New w32.novarg.@worm

    Guys,

    A New Worm was discovered today called "W32. Novarg".

    It shows up in your e-mail box with a"spoofed" e-mail from your Ip, mine was spoofed with a name of a friend on the same Ip. So it looked legit. And it showed as a txt file, safe right. NOT

    It contains a file called "Text.txt" or similar.

    If you don't have todays (1/26/04) latest virus definitions it won't show up as a virus, then when you open it , it writes to the REG and installs some .dll files to your system.

    It is a DOD and mass e-mail worm.

    It's a real pain to remove, reg edits and rescans. Even then some of the files can't be removed, just quarantined.


    So be careful and download the latest definitions from your virus provider.

    Symantec has removal info if you need to remove it.
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)


  2. #2
    Gold Member
    Join Date
    Apr 2003
    Location
    Ohio, USA
    Posts
    1744
    Downloads
    1
    Uploads
    0
    Thanks Ward, I just did that two days ago and sure enough there was a rather large "New Virus Definitions" tonight.


    I don't play Russian roulette, so I never ever open attachments that I am not previously made aware of or included in a reply that I am aware of.


  3. #3
    wms
    wms is online now
    Moderator wms's Avatar
    Join Date
    Mar 2003
    Location
    United States
    Posts
    898
    Downloads
    0
    Uploads
    0
    Good policy Ken.

    I always scan even then as to try and make sure.

    I just go caught by this one.(dark)
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)


  4. #4
    Registered
    Join Date
    May 2003
    Location
    USA
    Posts
    109
    Downloads
    0
    Uploads
    0
    Since I just got done doing 4 hours of firewall changes for my company, so I will relay a bit of information,

    The payload looks to be a Denial of services attach against www.sco.com, so if you internet access becomes very very slow you might want to virus scan your systems.

    It also installs a back door trojan that uses port 3127, so if you have a firewall that can block in and out bound traffic I suggest you block TCP 3127


  • #5
    wms
    wms is online now
    Moderator wms's Avatar
    Join Date
    Mar 2003
    Location
    United States
    Posts
    898
    Downloads
    0
    Uploads
    0
    Thanks Bcromwell,


    Symantec now says it is using ports Tcp3127 thru Tcp3198.
    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)


  • #6
    Site Owner CNCadmin's Avatar
    Join Date
    Mar 2003
    Location
    United States
    Posts
    6424
    Downloads
    2
    Uploads
    3
    Just got 20 emails with the virus.
    Thank You,
    Paul G
    Site Owner-Webmaster-
    Administrator
    www.rfqwork.com
    www.cnczone.com
    www.welderzone.com


  • #7
    Registered HomeCNC's Avatar
    Join Date
    Mar 2003
    Location
    United States
    Posts
    779
    Downloads
    0
    Uploads
    0
    SCO is messing with the free open source of LINUX and pissed off some programmer people.
    Thanks

    Jeff Davis (HomeCNC)
    http://www.homecnc.info


    (Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)


  • Posting Permissions



    About CNCzone.com

      We are the largest and most active discussion forum from DIY CNC Machines to the Cad/Cam software to run them. The site is 100% free to join and use, so join today!

    Follow us on

    Facebook Dribbble RSS Feed


    Search Engine Friendly URLs by vBSEO ©2011, Crawlability, Inc.