Jump to content


Photo
- - - - -

W32.Novarg.A@mm


  • Please log in to reply
4 replies to this topic

#1 AibelNET

AibelNET

    CS v Women CS always win..

  • Elites
  • 215 posts

Posted 27 January 2004 - 10:03 AM

<img style="float: right" src="http://www.winmatrix...c_windows.gif">DO NOT OPEN ANY ENAILS WITH THE FOLLOWING...
From:
may be a spoofed from address
Subject:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Message:
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
Attachment:
document
readme
doc
text
file
data
test
message
body
With one of the following suffixes:
.pif
.scr
.exe
.cmd
.bat
.zip
REAL NASTY WORM
W32.Novarg.A@mm is a mass-mailing worm. The worm will arrive as an attachment with a file extension of .bat, .cmd, .exe, .pif, .scr, or .zip.
When the machine gets infected, the worm will set up a backdoor into the system by opening TCP ports 3127 thru 3198. This will potentially allow a hacker to connect to the machine and utilize it as a proxy to gain access to it's network resources. In addition, the backdoor has the ability to download and execute arbitrary files.
The worm will perform a DoS starting on February 1, 2004. On February 12, 2004 the worm has a trigger date to stop spreading.
Posted ImageRead: W32.Novarg.A@mm

Edited by Jatin, 27 January 2004 - 07:58 PM.


#2 AquaS

AquaS

    AquaS

  • Member
  • 437 posts

Posted 27 January 2004 - 11:05 AM

Anubis thanks for the information.

#3 Jatin

Jatin

    Administrator

  • Admin
  • 4,867 posts

Posted 27 January 2004 - 05:45 PM

Thanks Anubis

#4 ReynoldsM

ReynoldsM

    Reynolds Medila

  • Elites
  • 2,147 posts

Posted 27 January 2004 - 08:23 PM

I got some of these in my inbox :/

#5 Jatin

Jatin

    Administrator

  • Admin
  • 4,867 posts

Posted 28 January 2004 - 08:28 PM

W32.Novarg.A@mm RemovalTool (Thanks to AquaS)

Want to comment?

Register or Sign In to go completely ad-free!