MyDoom / W32.Novarg Virus Information 22 Oct 2004
MyDoom Virus (AKA W32.Novarg.A@mm) is a mass-mailing worm that arrives as an attachment with the file extension .bat, .cmd, .exe, .pif, .scr, or .zip. Be very careful of any attachments you recieve.

Apon infection in your computer the virus sets up a backdoor program which can allow an attacker to access your computer remotely. In addition to this the worm/virus is set to perform a Denial of Service (DoS) attack beginning February 1 2004. If the virus is installed on your computer during this period you will find your internet connection slow as your computer is involved performing the attack. This may cause network congestion around the world during this period. Simply take the steps suggested below to remove the virus.

Users with AntiVirus tools should update there definitions immediatly.

ALSO NOTE: to minimise the spread accross our network we have introduced some blocks for outbound messages containing any Microsoft executable files which are common to the virus. (which includes .exe files)

Removal of the Virus To remove the virus you can use a removal tool, full in-depth instructions on the tool and its download are available < HERE >

Here is an excerpt from that page, Note: if you have issues using this tool, consult the website link above or contact your Anti Virus software vendor for assistance.

1. Download the FxNovarg.exe file from: http://securityresponse.symantec.com/avcenter/FxNovarg.exe
2. Save the file to a convenient location, such as your downloads folder or the Windows desktop, or removable media known to be uninfected.
3. To check the authenticity of the digital signature, refer to the "Digital signature" section later in this writeup.
4. Close all the running programs before running the tool.
5. If you are on a network, or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
6. If you are running Windows Me or XP, then disable System Restore. Refer to the "System Restore option in Windows Me/XP" section later in this writeup for further details. HERE
Caution: If you are running Windows Me/XP, we strongly recommend that you do not skip this step.
7. Double-click the FxNovarg.exe file to start the removal tool.
8. Click Start to begin the process, and then allow the tool to run.
9. Restart the computer.
10. Run the removal tool again to ensure that the system is clean.
11. If you are running Windows Me/XP, then reenable System Restore.
12. If you are using Active Desktop, you may need to restore it.

Note:If you have issues using this tool, consult the website link above or contact your Anti Virus software vendor for assistance.

You should also check your Anti Virus software vendors website for information on the virus, particular removal and steps you should untertake to ensure your system is protected.

Adam News Archive