»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-27-2004, 10:11 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Portland, Or
Posts: 3,110
NeoStarO1 is on a distinguished road
Send a message via ICQ to NeoStarO1 Send a message via AIM to NeoStarO1 Send a message via Yahoo to NeoStarO1
Outdoors W32.Novarg.A@mm On the loose

Now im getting ticked. I rarely get viruses. Yesterday got a email from the school district and I thought it was in relation to something I been inquiring about with the school district so dummy me opened it up and NIS went crazy! Nope. it was a frickin' virus.

I cleaned everything up last night and all was smooth as heck again. This morning check my email and again 7 emails! all full of this same virus.

Symantec has this notice on thier front home page. Here are the details

Short of not checking my email how can I stoop this thing? Its all coming through my business email accounts. We are not opening them. This mornign we did not open anything. I do not have preview panes on or anything.

Any advise or do i need to sit this out for the next 12 days? Read the article to knwo what im talking about.

NeoStarO1 is offline   Reply With Quote
Old 01-27-2004, 10:15 AM   #2 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
Old news.

Rob's got it on the news page also.

If it's coming into your biz account, then most likely someone you do biz with has it. All you can do is wait till they clean their system. It is a mass mailer worm after all.

Last edited by nomaxim; 01-27-2004 at 10:19 AM.
nomaxim is offline   Reply With Quote
Old 01-27-2004, 10:35 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Portland, Or
Posts: 3,110
NeoStarO1 is on a distinguished road
Send a message via ICQ to NeoStarO1 Send a message via AIM to NeoStarO1 Send a message via Yahoo to NeoStarO1
Didn't relize it was old news. According to symantec it was only discovered yesterday. Perhaps thier website is wrong.

So only thing I can do is t wait till they clean there computer?

Well that doesn't bode well for me cuz i do regular specials every week and newsletters every first of the month. I have over 300 email addresses.

Do you think I should put something up on our website asking our clients to clean thier computer? I don't wanna be sending out any more coupons or newsletters till this stops. I am afraid i may inadvertaly send someone something.

I also want to format my comptuer as well as I need more patitions and im thinking i should wait till this blows over.

I'm really frustereated right now. I have set more tighter securities on my email right now as 30 more come in. Damm blast it!!!
NeoStarO1 is offline   Reply With Quote
Old 01-27-2004, 10:54 AM   #4 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
CNN , At present 1 outta 12 emails is infected in some networks. It should peak out in the next 12-36 hours as more people become aware of it.

Be glad your Norton caught it or your system may have been sending it to all your customers!

It could also be that only one of your customers has it. Last year duing Klez I got like 50-60 over a two week period before it stopped.

EDIT: Old news meant loosly, I've been dealing with it all last night. Work 3rd shift.

Last edited by nomaxim; 01-27-2004 at 10:57 AM.
nomaxim is offline   Reply With Quote
Old 01-27-2004, 10:55 AM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
also see http://www.techimo.com/forum/t97654.html

and http://isc.sans.org/diary.html

Last edited by DVNT1; 01-27-2004 at 11:01 AM.
DVNT1 is offline   Reply With Quote
Old 01-27-2004, 10:58 AM   #6 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
...and for a graph of infected email rate :

http://isc.sans.org/images/virus2.png (novearg email messages per hour)

and http://isc.sans.org/images/virus.png (novearg email messages per 10 minutes)
DVNT1 is offline   Reply With Quote
Old 01-27-2004, 11:04 AM   #7 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
NeoStar, Run another scan. Maybe try HouseCall or something else too just to be sure.
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
-George Carlin
nomaxim is offline   Reply With Quote
Old 01-27-2004, 11:06 AM   #8 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
The virus also spoofs sender's address so it could easily be someone which has your email address in thier address book. Then thier computer sends out the virus email using your email address as the claimed source.
DVNT1 is offline   Reply With Quote
Old 01-27-2004, 11:08 AM   #9 (permalink)
Registered User
 
golfcart's Avatar
 
Join Date: Oct 2001
Location: Michigan
Posts: 1,680
golfcart is on a distinguished road
Thanks for the links DVNT1. Those are neat graphs
golfcart is offline   Reply With Quote
Old 01-27-2004, 11:15 AM   #10 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Portland, Or
Posts: 3,110
NeoStarO1 is on a distinguished road
Send a message via ICQ to NeoStarO1 Send a message via AIM to NeoStarO1 Send a message via Yahoo to NeoStarO1
Yes im considering disabling all accounts on the server for a few days. That way it gets bounced back to them or who ever sends it.

What do you suggest?
NeoStarO1 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:16 PM.