Quantcast

Mydoom worm spreading rapidly.

January 26, Computerworld

A new e−mail worm has appeared on the Internet and is spreading rapidly, according to leading anti−virus companies. The worm, called W32/Mydoom, surfaced late Monday, January 26. "This worm is taking off like a rocket, with well over 20,000 interceptions in just 2 hours of it being discovered," Ken Dunham of iDefense Inc. said. The virus is also being called MiMail.R, Shimg, Novarg and Mydoom, althought it's not certain yet that this code is a variant of the MiMail virus, Dunham said. Mydoom carries varying subjects such as "HELLO" or a blank subject, as well as a variety of messages and attachments. When loaded, it calls up Notepad and displays random characters, while creating a copy of itself and modifying the infected machine's Windows registry to run the code upon start−up. It may open a TCP port to listen for commands from a remote attacker, according to Dunham. "It also attacks sco.com with a DDoS [denial−of−service] attack," said a statement from F−Secure. It can spread by both e−mail and the Kazaa file−sharing system, several anti−virus vendors said. Computer Associates International Inc.'s research labs received 11 copies of the new worm almost simultaneously today, indicating a rapidly spreading infection. The Mercury News reports that Vincent Gullotto of McAfee AVERT said the company had received reports from some companies receiving MyDoom e−mails at rates as great as 1,000 a minute. He added at as many as six Fortune 500 companies have been affected.

Source:
http://www.computerworld.com/securitytopics/security/virus/story/0,10801,89449,00.html
 

gorgechris

Monkey
Mar 25, 2003
242
0
Traveling the eastern U.S.
Originally posted by BarbaRosa
its a social virus.. inother words if you are a dumbaas and open something you should not... there you go..
Exactly!

"Huh, here's an email from someone I have not heard from in a long time. There's a zip file attached, but only a vague message. I better open it up to see what it is!"
 

Tech Ninja

Chimp
Mar 13, 2003
20
0
Originally posted by gorgechris
Exactly!

"Huh, here's an email from someone I have not heard from in a long time. There's a zip file attached, but only a vague message. I better open it up to see what it is!"
That'd be my dumbass co-worker alright.
 
January 28, Government Computer News

The first variant of the virulent MyDoom worm has been discovered, just 48 hours after the worm first appeared. The original version, W32/MyDoom.a, also known as Norvag, has since its discovery on Monday, January 26, become one of the fastest spreading e−mail worms ever, and is set to launch a denial−of−service (DoS) attack against the Website of SCO Group Inc. The company confirmed that it is already experiencing a distributed DoS attack. The new version, MyDoom.b, appears to target the Microsoft Website, and carries a few more tricks with it. MyDoom.b blocks access to 65 sites, most of them antivirus vendors. SCO is working with the Secret Service and the FBI. People with information should contact their local FBI office. Several security and antivirus experts have said that the new variant could be spreading via computers already infected by the original version. The back door placed on those computers could allow the machines to be used as relays for infected e−mails. “If this is the case, MyDoom.b will likely become very prevalent in the wild in just a few short hours,” Dunham said. “This does not mean that millions of computers are infected, but that millions of e−mails harboring the worm are in the wild.” Whether these e−mails infect new machines depends on whether users open the executable attachment carrying the infection.

Source:
http://www.gcn.com/vol1_no1/daily−updates/24776−1.html