Forum Home
Press F1
 
Thread ID: 42327 2004-02-08 02:29:00 Does this sound like the MyDoom virus? stu140103 (137) Press F1
Post ID Timestamp Content User
213611 2004-02-08 11:45:00 > Wtf,your miles away,what stu has posted is very close
> to the email i recieved loaded with the virus.
>

If you look again, the message has been bounced as tagged spam by spam assassin, not antivirus software.

You'll also find that the subject line does not match the list of subjects used by MyDoom.A or MyDoom.B.

It is true that MyDoom used Mailer Daemon style messages as a way of disguising itself, however they were extremely distinct. the above-posted ones do not match the criteria for MyDoom.
whiskeytangofoxtrot (438)
213612 2004-02-08 20:12:00 The range of subject lines used by MyDoom has increased significantly WTF and that is no longer an indicator. If in doubt I rely on Norton to ID the virus, but nothing new or different has turned up. After intercepting around 1600 at the last count I think I have a feel for the variations.

Viagra ads and other typical spam info turn up quite regularly as low-life smarties try to forward the virus with a new disguise.

Mutation is the name of the game, and there are as many mutanrt senders out there as there are mutant viruses.

Cheers

Billy 8-{) :(
Billy T (70)
213613 2004-02-08 23:48:00 > 1 . Nice job of blurring your address with
> asterisks, of course you've left it in further down
> the track as well . . .

Where are the mod"s when you what them?!? ?:| :D
stu140103 (137)
213614 2004-02-09 00:52:00 Email Bruce Stu

Cheers

Billy 8-{)
Billy T (70)
213615 2004-02-09 01:20:00 > Email Bruce Stu

I have, did you not see the message

"Mods: check your e-mails" ;)
stu140103 (137)
213616 2004-02-09 02:12:00 Bouncing hasn't reduced the number of viruses you receive, Billy. Correlation is not causation. The number has reduced because ISPs are trying harder to shoot the damn things. They don't like that traffic. It costs them money. Graham L (2)
213617 2004-02-09 05:23:00 > The number has reduced because ISPs are
> trying harder to shoot the damn things.

*cough*

So who are all these ISPs who are trying to shoot them down Graham? Apart from Xtra and a couple of ther NZ ISPs, who else is seriously stripping viruses from the traffic? I'm sure that more than a few Netizens would like to know who to switch to for virus screening protection.

I've seen what I estimate to be upward of 1000 ISPs (allowing for some duplications) who are cheerfully forwarding MyDoom and its siblings.

Cheers

Billy 8-{) :|
Billy T (70)
1 2