PDA

View Full Version : Mydoom worm spreading rapidly.


johnbryanpeters
01-27-2004, 12:06 PM
January 26, Computerworld

A new e−mail worm has appeared on the Internet and is spreading rapidly, according to leading anti−virus companies. The worm, called W32/Mydoom, surfaced late Monday, January 26. "This worm is taking off like a rocket, with well over 20,000 interceptions in just 2 hours of it being discovered," Ken Dunham of iDefense Inc. said. The virus is also being called MiMail.R, Shimg, Novarg and Mydoom, althought it's not certain yet that this code is a variant of the MiMail virus, Dunham said. Mydoom carries varying subjects such as "HELLO" or a blank subject, as well as a variety of messages and attachments. When loaded, it calls up Notepad and displays random characters, while creating a copy of itself and modifying the infected machine's Windows registry to run the code upon start−up. It may open a TCP port to listen for commands from a remote attacker, according to Dunham. "It also attacks sco.com with a DDoS [denial−of−service] attack," said a statement from F−Secure. It can spread by both e−mail and the Kazaa file−sharing system, several anti−virus vendors said. Computer Associates International Inc.'s research labs received 11 copies of the new worm almost simultaneously today, indicating a rapidly spreading infection. The Mercury News reports that Vincent Gullotto of McAfee AVERT said the company had received reports from some companies receiving MyDoom e−mails at rates as great as 1,000 a minute. He added at as many as six Fortune 500 companies have been affected.

Source:
http://www.computerworld.com/securitytopics/security/virus/story/0,10801,89449,00.html

Ridemonkey
01-27-2004, 12:08 PM
Anyone who has any problems related to this virus can PM Tenchiro for complimentary support :devil:

Knuckleslammer
01-27-2004, 12:14 PM
Yeah, and anybody that doesn't want the virus, the only way to avoid it is to shut off your pc for a week. Ok?

Knuck

BarbaRosa
01-27-2004, 12:29 PM
its a social virus.. inother words if you are a dumbaas and open something you should not... there you go..

but, here is a mcafee tool to eradicate the beast

http://vil.nai.com/vil/stinger/


hey AARRONN! send an email update sometime...

just the beard
:monkey: dork

gorgechris
01-27-2004, 12:37 PM
Originally posted by BarbaRosa
its a social virus.. inother words if you are a dumbaas and open something you should not... there you go..
Exactly!

"Huh, here's an email from someone I have not heard from in a long time. There's a zip file attached, but only a vague message. I better open it up to see what it is!"

Tech Ninja
01-28-2004, 10:40 AM
Originally posted by gorgechris
Exactly!

"Huh, here's an email from someone I have not heard from in a long time. There's a zip file attached, but only a vague message. I better open it up to see what it is!"

That'd be my dumbass co-worker alright.

johnbryanpeters
01-29-2004, 08:50 AM
January 28, Government Computer News

The first variant of the virulent MyDoom worm has been discovered, just 48 hours after the worm first appeared. The original version, W32/MyDoom.a, also known as Norvag, has since its discovery on Monday, January 26, become one of the fastest spreading e−mail worms ever, and is set to launch a denial−of−service (DoS) attack against the Website of SCO Group Inc. The company confirmed that it is already experiencing a distributed DoS attack. The new version, MyDoom.b, appears to target the Microsoft Website, and carries a few more tricks with it. MyDoom.b blocks access to 65 sites, most of them antivirus vendors. SCO is working with the Secret Service and the FBI. People with information should contact their local FBI office. Several security and antivirus experts have said that the new variant could be spreading via computers already infected by the original version. The back door placed on those computers could allow the machines to be used as relays for infected e−mails. “If this is the case, MyDoom.b will likely become very prevalent in the wild in just a few short hours,” Dunham said. “This does not mean that millions of computers are infected, but that millions of e−mails harboring the worm are in the wild.” Whether these e−mails infect new machines depends on whether users open the executable attachment carrying the infection.

Source:
http://www.gcn.com/vol1_no1/daily−updates/24776−1.html

BarbaRosa
01-29-2004, 11:31 AM
hey johnny, i get that mag too... who do you work for?

i do city/county gov it in colorado how is the vt weather?

johnbryanpeters
01-29-2004, 07:50 PM
Got about six inches of snow last night, it's five below and falling.

I work at an outfit that develops web applications. We also do system and network design and monitoring.

J