Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

MyDoom.A worm causes numerous infections

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 09:48 PM
Original message
MyDoom.A worm causes numerous infections
Posted in GD as a public service. The poster is not an employee of or in any way associated with Panda Software.
---

New worm W32/MyDoom.A worm causes numerous infections in corporate environments

Virus Alerts, by Panda Software (http://www.pandasoftware.com)

MADRID, January, 27, 2004 - New worm W32/Mydoom.A.worm has already reached red alert status according to the virus labs of Panda Software. There have already been many incidences with thousands of users in numerous countries.
The ability of W32/MyDoom.A to spread rapidly, as well as the damage it is leaving behind, makes W32/Mydoom.A.worm as serious as last summers Bugbear and Blaster.

W32/Mydoom.A worm forwards itself to all the addresses found in the affected computers. As other countries begin the usual workday increasing computer activity it is expected that this virus will grow and create more issues.

W32/Mydoom.A worm comes via an e-mail message with an attached file. Like the other recent virus epidemics, social engineering techniques cheat the user making the think they are supposed to open the file. The virus not only infects the computer that received the e-mail but then mails itself to all the contacts found in addresses book.

In addition, it opens the TCP port 3127 in the infected computer, allowing remote control of the computer. It means any malicious hacker may get access and steal, modify or destroy any kind of Information stored in the computer.

As additional Information, this virus is ready to launch a Denial of Service attack against the web site www.sco.com next February, 1st this year.

W32/Mydoom.A worm search e-mail addresses in the computer files with the
extensions: .htm, .sht, .php, .asp, .dbx, .tbb, .adb, .pl, .wab, .txt. It uses its own SMTP engine to send itself by e-mail.

The message content changes, and may be composed by the following sentences:

Subject:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Body:
Mail Transaction Failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment

Attached file name:
document
readme
doc
text
file
data
test
message
body

File extension:
.pif
.scr
.exe
.cmd
.bat
.zip

Once the virus has infected the computer, it then searches for the peer-to-peer file sharing Network KaZaa. If KaZaa is detected a file is copied to the shared folder allowing its distribution via this peer to peer system. The filename may be one of the following ones:

winamp5
icq2004-final
activation_crack
strip-girl-2.0bdcom_patches
rootkitXP
office_crack
nuke2004

and PIF, .SCR o .BAT extension.

Panda Software offers updates to all its customers to detect and eliminate W32/Mydoom.A worm. Users who have not enabled automatic updates can upgrade the antivirus in http://www.pandasoftware.com/.

Due to the possibility of being infected by W32/Mydoom.A.worm, Panda Software advises users to treat all e-mails received with caution, and to update their antivirus solutions as soon as possible and installing a good firewall.

Similarly, users can also detect and disinfect this and other malicious code using the free, online antivirus, Panda ActiveScan, which is available on the company's website at http://www.pandasoftware.com/. Also, PQRemove http://www.pandasoftware.com/download/utilities/ free disinfection tool is available for all users.

Detailed technical information on W32/Mydoom.A.worm is available from Panda Software's Virus Encyclopedia.

NOTE: The addresses above may not show up on your screen as single lines. This would prevent you from using the links to access the web pages. If this happens, just use the "cut" and "paste" options to join the pieces of the URL.
Printer Friendly | Permalink |  | Top
dweller Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 10:22 PM
Response to Original message
1. thanks for your info P#6
:kick:

dp
Printer Friendly | Permalink |  | Top
 
Wonk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 10:26 PM
Response to Original message
2. Here's the LBN thread I posted about this last night
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 10:32 PM
Response to Reply #2
3. I thought I may have seen a thread about this
but I couldn't recall it. No matter-- this needs to be seen by one and all. As a computer repairman, I think I'm gonna be going on little sleep when this kicks in over here.... :nuke:
Printer Friendly | Permalink |  | Top
 
Unforgiven Donating Member (613 posts) Send PM | Profile | Ignore Tue Jan-27-04 11:08 PM
Response to Original message
4. Fix For That
Lose the Habit, Click on link:



http://www.mandrakelinux.com/en/
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jan-27-04 11:20 PM
Response to Reply #4
5. I prefer Suse myself
But to each their own... :evilgrin:
Printer Friendly | Permalink |  | Top
 
Unforgiven Donating Member (613 posts) Send PM | Profile | Ignore Wed Jan-28-04 09:51 PM
Response to Reply #5
6. That works as Well!
anything, but that wretched M$.
Printer Friendly | Permalink |  | Top
 
depakid Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jan-28-04 10:31 PM
Response to Original message
7. It spoofs e-mail return e-mail addresses
Edited on Wed Jan-28-04 11:09 PM by depakote_kid
I've gotten about 20 of these messages overnight: "Mail delivery failed: returning message to sender" (the same way e-mail gets rejected if you make a typo). To be sure that our server wasn't infected, I did an IP lookup and sure enough, the messages originated elsewhere. Haven't gotten any in the last 6 hours, so maybe this round is petering out-

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon May 06th 2024, 01:17 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC