The Strike Point
Custom Search
   


The Strike Point Archive 01

Recent Virus going around - Info / Help

Starting a couple of days ago I got copies of this worm from people on TCB and the Strike BB. It contains an attachment as described below. I got six more copies this morning, not for the email addresses I use here.

Someone on each of our BBs has the virus! So that means others will get infected. Here's what it does and how to remove it.

W32.Novarg.A@mm

Information and removal tool.

http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html

W32.Novarg.A@mm is a mass-mailing worm that arrives as an attachment with the file extension .bat, .cmd, .exe, .pif, .scr, or .zip.

When a computer is infected, the worm will set up a backdoor into the system by opening TCP ports 3127 through 3198, which can potentially allow an attacker to connect to the computer and use it as a proxy to gain access to its network resources.

In addition, the backdoor can download and execute arbitrary files.

The worm will perform a Denial of Service (DoS) starting on February 1, 2004. It also has a trigger date to stop spreading on February 12, 2004. These two events will only occur if the worm is run between or after those dates. While the worm will stop spreading on February 12, 2004, the backdoor component will continue to function after this date.

If you have a sudden denial of service on Feb 1st, remember this link and how to remove the virus.

Messages In This Thread

Recent Virus going around - Info / Help
Re: Recent Virus going around - Info / Help
Re: Recent Virus going around - Info / Help
Re: Recent Virus going around - Info / Help
Re: Recent Virus going around - Info / Help
Re: Recent Virus going around - Info / Help

Copyright 2022 David Spragg