
27 JAN, 2004 - 1145 CST This is the most rapidly spreading virus I have seen. When I downloaded my email a few minutes ago, I found my ISPs filter program had intercepted and destroyed 8 copies of this virus that was attached to 8 totally bogus email messages. I then had to manually destroy a 9th copy in a bogus message my ISP let pass. Be careful out there. Below is an extract from the Sophos web site that describes the current characteristics of this virus. 73 - Dick, W9GIG ====================================================================== Extract from the Sophos web site. We started seeing these viruses late Monday afternoon. W32/MyDoom-A and W32/MyDoom.A Type: Win32 worm Description W32/MyDoom-A is a worm which travels by email. The worm harvests email addresses from your hard disk and uses randomly-chosen addresses for both the "to" and "from" fields. This means that the "from" address is spoofed and does not tell you where the mail really came from. W32/MyDoom-A arrives in emails with the following characteristics: Subject lines include: error hello hi mail delivery system mail transaction failed server report status test [random collection of characters] Attachment names include: body data doc document file message readme test [random collection of characters] Attachment extensions: bat cmd exe pif scr zip W32/MyDoom-A attaches itself to emails in either EXE (Windows program) or ZIP (Zip archive) format.