CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Advisories!: variant B of the Mydoom image
Worms


- Panda Software reports the appearance
of variant B of the Mydoom worm -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, January 28, 2004 - Even though incidents caused by Mydoom.A.worm are
still on the rise, PandaLabs has already detected variant B of this worm:
Mydoom.B.worm.

This new variant is even more dangerous than its predecessor, as it is
designed to prevent several antivirus programs from updating correctly.
This, nevertheless, does not affect Panda Software antivirus solutions.

Like Mydoom. A, the new worm is designed to attack and saturate networks of
any size. To do this, it searches e-mail addresses in the Outlook Address
Book as well as in computer files with the extensions: .htm, .sht, .php,
.asp, .dbx, .tbb, .adb, .pl, .wab, .txt. Then, the worm uses its own SMTP
engine to send itself by e-mail. Mydoom.B.worm also spreads via KaZaA.

Mydoom.B.worm also modifies the Windows hosts file. By doing this, it
manages to redirect certain Internet addresses -including those of several
antivirus vendors - so that, when users try to access them, the Internet
browser shows an error message indicating that the page could not be found.
In this way, it prevents several antivirus programs from updating properly.

Unlike Mydoom.A, this new malicious code has been designed to launch DoS
(Denial of Service) attacks against the Microsoft Corporation servers.

Panda Software has already made the updates to its products available to its
clients to ensure their solutions can detect and eliminate Mydoom.B. Even
though Panda Software's products can be automatically updated every day,
those whose software is not configured to update automatically, should
update their solutions from http://www.pandasoftware.com/.

Users can also detect this and other malicious code using the free, online
antivirus, Panda ActiveScan, which is available on the company's website at
http://www.pandasoftware.com/.

Finally, the epidemic caused by the Mydoom.A worm shows no signs of
cooling. The number if infected e-mails that are in circulation is
continuously increasing, which means that the possibility of becoming
infected by Mydoom.A is still very high. Mydoom.A.worm has infected seven
times more computers than Bugbear.B, the second virus most frequently
detected by the online antivirus Panda ActiveScan.

Everything seems to indicate that the writer or writers of these two worms
aim at putting as many copies of their creations as possible in circulation.
In this way, on the dates when the denial of service attacks are set to
occur, there will be more possibilities for these to be successful.

Detailed technical information on Mydoom.A.worm and Mydoom.B.worm is
available from Panda Software's Virus Encyclopedia.

More detailed information on Mydoom.A.worm and Mydoom.B.worm is available
from Panda Software's Virus Encyclopedia, at
http://www.pandasoftware.com/virus_info/encyclopedia/.

NOTE: The addresses above may not show up on your screen as single lines.
This would prevent you from using the links to access the web pages. If this
happens, just use the cut and paste options to join the pieces of the
URL.
Posted on Thursday, 29 January 2004 @ 09:15:52 UTC by phoenix22 (1016 reads)
[ Trackback ]
image

"Advisories!: variant B of the Mydoom" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· More about Worms
· News by phoenix22


Most read story about Worms:
Kama Sutra/Blackworm Worm Timebomb

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer