Here We Go Again: Worm Novarg.A

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
This is just a reminder to everyone that you need to be on the lookout for a new worm, and update your virus definitions accordingly as they become availible. Symantec is tracking a new worm, W32.Novarg.A@mm, a mass-mailing worm that's currently a Cat4 on Symantec's scale. It's commonly arriving as an attachment called "text.zip", which has an executable inside of it(cmd extension, a Windows NT command script, oddly enough). I've already recieved 3 copies in 30 minutes and more are likely on their way.
 

conjur

No Lifer
Jun 7, 2001
58,686
3
0
rolleye.gif


Why people open .ZIP files from unknown senders is just beyond me.
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
It's not the unknown senders that get people, it's the known senders. The first one I got a copy from had my editor's email address on it.:eek:
 

Night201

Diamond Member
Apr 23, 2001
3,697
0
76
Within the past hour, I've received 3 emails with a 22kb .zip file. Is this it?
 

MrDudeMan

Lifer
Jan 15, 2001
15,069
92
91
Originally posted by: conjur
rolleye.gif


Why people open .ZIP files from unknown senders is just beyond me.

dude, you need to understand what it does before you start
rolleye.gif


 

thirtythree

Diamond Member
Aug 7, 2001
8,680
3
0
I keep seeing these threads but I haven't gotten a single one on my e-mail :( where's the sign up?
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
Originally posted by: Night201
Within the past hour, I've received 3 emails with a 22kb .zip file. Is this it?
Yes. It comes out to 22,528 bytes.
 

conjur

No Lifer
Jun 7, 2001
58,686
3
0
Originally posted by: ViRGE
It's not the unknown senders that get people, it's the known senders. The first one I got a copy from had my editor's email address on it.:eek:

But it had to start somewhere, eh?

:)
 

Jzero

Lifer
Oct 10, 1999
18,834
1
0
Initial submissions have been received with file extensions of .exe, .pif, .scr, and .zip.
Not .cmd, though.
If you find documentation that says .cmd is one, please post here! Need to update my filter!!!

It's good practice to never open UNEXPECTED attachments no matter who sent them. If you know the sender, it's easy enough to ask them if they meant to send the file....
 

CraigRT

Lifer
Jun 16, 2000
31,440
5
0
Originally posted by: conjur
rolleye.gif


Why people open .ZIP files from unknown senders is just beyond me.

i hear you, but the same dumbasses will ask.. "but how would i know?"

i mean honestly... LOL..... just don't open anything!!!!!! :p
 

konichiwa

Lifer
Oct 9, 1999
15,077
2
0
Originally posted by: conjur
rolleye.gif


Why people open .ZIP files from unknown senders is just beyond me.

Opening ZIP files can't do anything, it's running the .cmd, .bat, .exe, etc files inside that baffles me!
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
Originally posted by: Jzero
Initial submissions have been received with file extensions of .exe, .pif, .scr, and .zip.
Not .cmd, though.
If you find documentation that says .cmd is one, please post here! Need to update my filter!!!

It's good practice to never open UNEXPECTED attachments no matter who sent them. If you know the sender, it's easy enough to ask them if they meant to send the file....
I've got a copy with .cmd in my inbox, it's inside of a .zip though.
 

Jzero

Lifer
Oct 10, 1999
18,834
1
0
Originally posted by: ViRGE
Originally posted by: Jzero
Initial submissions have been received with file extensions of .exe, .pif, .scr, and .zip.
Not .cmd, though.
If you find documentation that says .cmd is one, please post here! Need to update my filter!!!

It's good practice to never open UNEXPECTED attachments no matter who sent them. If you know the sender, it's easy enough to ask them if they meant to send the file....
I've got a copy with .cmd in my inbox, it's inside of a .zip though.

Can't block .zip b/c we need to receive those, but my filter is smart enough to search IN zips (and other archives!). I'll add .cmd to my list....
 

RossMAN

Grand Nagus
Feb 24, 2000
78,794
266
116
I've only received a few e-mails from co-workers and I deleted them all.

This is going to wreak havoc on corporate, educational and government e-mail infrastructures.
 

PlatinumGold

Lifer
Aug 11, 2000
23,168
0
71
i got an email from someone i know, and i was EXPECTING to get an attachment. :(

i didn't even open the attachment i only previewed it. :(

god i hate these virus people.
 

OZEE

Senior member
Feb 23, 2001
985
0
0
Sorry about the repost --

Never saw it -- there are so many stickies that I just skip over them...
 

SagaLore

Elite Member
Dec 18, 2001
24,037
21
81
Originally posted by: MrDudeMan
Originally posted by: conjur
rolleye.gif


Why people open .ZIP files from unknown senders is just beyond me.

dude, you need to understand what it does before you start
rolleye.gif

Are you saying Conjur doesn't know how this virus works, or are you making a joke about people who open attachments?
 

Vic

Elite Member
Jun 12, 2001
50,415
14,305
136
Our office got hit with this one this afternoon and (of course) some people opened the attachment and even the files inside
rolleye.gif


Luckily though, we're pretty well secured here (our head IT guy is very good -- I don't work in IT), so I don't think this will be much more than just an annoyance for us.