Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
W32.Novarg.A@mm / W32/Mydoom@MM on the loose
Posted on 27-Jan-2004 11:54 | Filed under: News



Security firms are currently investigating a new mass-mailing worm. Initial submissions have been received with file extensions of .exe, .pif, .scr, and .zip. This virus tries to spread via email and by copying itself to the shared directory for Kazaa clients if they are present. The body of the message may contain the following variations:

  • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
  • The message contains Unicode characters and has been sent as a binary attachment.
  • Mail transaction failed. Partial message is available.

    The worm itself is encrypted, and security firms are still working on this. Some companies call it W32/Mydoom@MM and others W32.Novarg.A@mm.

    When this file is run it copies itself to the local system with the following filenames:

    c:\Program Files\KaZaA\My Shared Folder\activation_crack.scr
    %SysDir%\taskmon.exe
    (Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)

    It also uses a DLL that it creates in the Windows System directory:

    %SysDir%\shimgapi.dll (4,096 bytes)

    It creates the following registry entry to hook Windows startup:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
    CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe


    When the machine gets infected, the worm will set up a backdoor into the system by opening TCP ports 3127 thru 3198. This will potentially allow a hacker to connect to the machine and utilize it as a proxy to gain access to it's network resources. In addition, the backdoor has the ability to download and execute arbitrary files. The worm will perform a DoS starting on 1 February 2004.


  • More information: http://securityresponse.symantec.com/avcenter...







    Twitter and LinkedIn »



    Follow us to receive Twitter updates when new discussions are posted in our forums:



    Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



    Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:



    Trending now »

    Hot discussions in our forums right now:

    Why I'm not buying Sonos again
    Created by dafman, last reply by Dunnersfella on 24-Jan-2020 16:30 (70 replies)
    Pages... 3 4 5


    Poor VDSL speeds and poor chat experience
    Created by MidnightRider, last reply by MidnightRider on 23-Jan-2020 22:42 (19 replies)
    Pages... 2


    Transferwise - painless and cheap FX and overseas purchases
    Created by landcruiserguy, last reply by openmedia on 21-Jan-2020 14:52 (35 replies)
    Pages... 2 3


    NZNOG Conference in Christchurch next week
    Created by NickMack, last reply by toejam316 on 21-Jan-2020 18:32 (16 replies)
    Pages... 2


    What do electricians charge these days
    Created by clive100, last reply by traderstu on 24-Jan-2020 17:41 (13 replies)

    New Orbi Mesh System
    Created by JayWehi33, last reply by Jiriteach on 24-Jan-2020 17:10 (13 replies)

    Issues streaming at peak times on 2degrees UFB / Wi-Fi
    Created by Mahon, last reply by Delphinus on 23-Jan-2020 23:45 (13 replies)

    Is this FnP Fridge the best bang for buck?
    Created by TeaLeaf, last reply by TeaLeaf on 23-Jan-2020 18:26 (27 replies)
    Pages... 2