 |
|
Symantec would like to assist you
regarding the W32.Novarg.A@mm worm that just classified as a Category
4. Below, Symantec provides you with tools and resources aimed at
combating W32.Novarg.A@mm.
W32.Novarg.A@mm
Also known as "W32/Mydoom@MM".
Arrives as an attachment with a file extension of .bat, .cmd, .exe,
.pif, .scr, or .zip. The worm also contains functionality to perform as
a proxy server. It listens on all TCP ports in the range 3127-3198. It
will perform a DoS attack starting on February 1, 2004 and on February
12, 2004 the worm has a trigger date to stop spreading.
This worm spreads faster than the usual
mass-mailing virus because it uses a better social engineering technique,
making users more tempted to open the attached file. Subject includes:
Mail Delivery System, Mail Transaction Failed, Server Report, Status, and
Error Messages including: Mail transaction failed.
For more information and removal instructions,
please visit Symantec Security Response: http://securityresponse.symantec.com/avcenter/venc/data/w32.novarg.a@mm.html
This worm re-emphasizes the basic
practice that corporations need to take:
Download
and deploy the most up-to-date virus definitions
Turn
off and remove unneeded services
Check
vendor Web sites for patches and updates
Block
or remove email that contains suspect file attachments
Isolate
infected machines from the network
Train
users not to open attachments unless they are expecting them
Research
information about the virus
Trace
the path of introduction
Symantec can provide customers support
against this worm in several ways:
Symantec
AntiVirus solution provide definition file to protect users in multiple
levels, including gateway, mail server and client.
Norton
AntiVirus prevents infected file to be spread out to other users by using
worm-blocking technology.
DeepSight
Alert Services and Threat Management System sends a notification when a
worm is detected with updates on how to mitigate the risk, information
on multiple antivirus vendor updates.
Symantec
IDS solutions will have signatures to be able to detect this new worm.
|
|
|
 |