new email virus in the wild (W32/Mydoom@MM)

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
There is a new email virus circulating the internet named W32/Mydoom@MM. It will come from a variety of senders, with a variety of subjects. The body message may look something like:

"The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment."
or
"The message contains Unicode characters and has been sent as a binary attachment."
or
"Mail transaction failed. Partial message is available."

It will include an attachment which will most likely be a .zip file named ?readme.zip?, containing a file named 'Document.scr'. THIS IS THE VIRUS ITSELF.

As always use a heavy dose of common sense whenever opening email attachments.

EDIT: Updated to include name in topic title
 

Twista

Diamond Member
Jun 19, 2003
9,646
1
0
ya its stickyed in General Hardware forum also, may be helpful to add the common names :D

[edit: Well its a requsted Sticky.]
 

RalfHutter

Diamond Member
Dec 29, 2000
3,202
0
76
I'll bump this to the top. I think it's as appropriate to be a sticky in the OS forum as the Gen hardware forum.
 

KGB

Diamond Member
May 11, 2000
3,042
0
0
The wife just got this in her inbox.

It's a good thing I saw this on CNN as I woke up today.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
I've now recieved this twice, fortunetly our anti-virus gateway blocks the attachment.

Most anti-virus vendors have updates available that address this, updating would probably be a good idea.
 

MysticLlama

Golden Member
Sep 19, 2000
1,003
0
0
I've been getting around 300ish per hour (40 mailboxes on the server)

Also, tons of backlash from bounced e-mail saying we have a virus, your mail could not be delivered, and numerous other things because it spoofs senders. It really sucks trying to explain to people that we don't have a problem when they get mail telling them they have a virus.
 

Twista

Diamond Member
Jun 19, 2003
9,646
1
0
just got 1 on yahoo account from some cable modem email addy. I think .RR or something and its spoofed i know. Title was ERROR but it had that text within the message.
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Originally posted by: MysticLlama
I've been getting around 300ish per hour (40 mailboxes on the server)

Also, tons of backlash from bounced e-mail saying we have a virus, your mail could not be delivered, and numerous other things because it spoofs senders. It really sucks trying to explain to people that we don't have a problem when they get mail telling them they have a virus.
Yup this happens all the time here as well, there's not much to be done except educate them on email....
 

ITJunkie

Platinum Member
Apr 17, 2003
2,512
0
76
www.techange.com
Originally posted by: spyordie007
Originally posted by: MysticLlama
I've been getting around 300ish per hour (40 mailboxes on the server)

Also, tons of backlash from bounced e-mail saying we have a virus, your mail could not be delivered, and numerous other things because it spoofs senders. It really sucks trying to explain to people that we don't have a problem when they get mail telling them they have a virus.
Yup this happens all the time here as well, there's not much to be done except educate them on email....

Little maggot script kiddies :|