February 09, 2004

New version of MyDoom appears

MyDoom.C does not use e-mail to spread

Internet security companies said Monday that they discovered a new version of the MyDoom e-mail worm circulating on the Internet.

The new version, MyDoom.C, is a modified copy of the virus that ravaged the Internet in January. Unlike its predecessor, however, the new variant does not use e-mail or the Kazaa peer-to-peer network to spread and is not expected to make much of an impact on the Internet, said managed security services provider LURHQ Corp.

MyDoom.C both refines and tames the earlier version of the virus, known as MyDoom.A. Among other changes, the new virus fixes problems with the original MyDoom e-mail worm, including errors in the worm's code that made it impossible for many MyDoom-infected machines to launch a programmed denial of service (DoS) attack against The SCO Group Inc.'s Web site, www.sco.com. Gone also is the expiration date that told machines infected with the original MyDoom virus to stop their DoS attack on February 12, 2004, LURHQ said.

Also, instead of depositing a file that opens a backdoor on infected machines, the new virus distributes a compressed archive of the worm's original source code, the company said.

However, the MyDoom.C author also removed many of the most dangerous features of the original virus, including the highly efficient SMTP (Simple Mail Transfer Protocol) engine that enabled infected machines to spew out e-mail messages containing the virus. That component made the original MyDoom worm the fastest spreading e-mail worm in history, easily defeating Sobig-F, the previous record holder, according to antivirus software companies, the company said.

Instead, MyDoom.C seeks out and infects machines that are already infected with the original MyDoom virus by searching for machines that are listening on port 3127, a telltale sign of MyDoom infection, said security company iDefense Inc. in a security alert.

That approach will give MyDoom.C a solid base of as many as 500,000 machines, but will keep MyDoom.C from spreading much beyond the community of already-infected machines, LURHQ and iDefense said.

The MyDoom.C author also removed a Trojan horse "backdoor," but included a copy of the worm's source code, which is deposited on machines infected with the new variant, the companies said.

Unlike the first MyDoom virus, MyDoom.C takes its sights off of The SCO Group Web site, but continues an attack on Microsoft Corp.'s Web site that was introduced by the MyDoom.B variant, LURHQ and iDefense said.

The new MyDoom variant does not remove existing versions of the virus and can even run alongside them, said Joe Stewart, senior security researcher at LURHQ of Chicago.

If started on or between February 8, 2004 and February 12, MyDoom.C- infected machines will launch randomly timed DoS attacks against Microsoft.com. Machines started after the February 12 will launch constant attacks against the Redmond, Washington, company's Web page, LURHQ said.

An analysis of the worm's code also uncovered an IP (Internet Protocol) address linked to www.ford.com, the Web page of Ford Motor Co. However, it is not clear whether the worm targets Ford, iDefense said.

The lack of aggressive spreading features, a staple of most e-mail worms, and the inclusion of the MyDoom.A source code may mean that the MyDoom author is closing shop and handing off his creation to other virus writers to refine, LURHQ said.

Close

On Twitter now

Applications

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Applications Resource Alerts

Subscribe to the Applications Newsletter

Stay informed of the latest news and technologies around application, project and performance management.

White paper

Turn Your IT Department into a Lean Machine

Like any valuable resource, IT is a terrible thing to waste. But by applying the same lean techniques that have been used to streamline manufacturing processes, IT departments can reduce costs, improve performance and better manage resources.

Download now! »

Podcast

Economy Makes Automation a Must-Have Tech for 2009

Stephen Elliot, vice president of strategy for CA's Infrastructure Management and Data Center Automation business unit, explains why difficult economic times drive the need for simplified management capabilities and advanced automation tools.

Listen now! »

White paper

What You Need to Know About Virtual Infrastructure Management - Now

According to a recent study CA conducted with 300 CIOs and top IT executives, 64 percent of respondents say they've already invested in virtualization, and the other 36 percent reported that they plan to invest in virtualization.

Download now! »

Webcast

Leveraging Virtualization and Process Automation

In this video learn about process automation in a virtualized world. How CA and VMware are enabling enterprise datacenter automation.

View now! »
©1994-2009 Infoworld, Inc.