Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

MyDoom Variant Continues to Cause Confusion
eWeek ^ | Jnauary 28, 2004

Posted on 01/28/2004 3:58:52 PM PST by Leroy S. Mort

Edited on 04/13/2004 2:59:00 AM PDT by Jim Robinson. [history]

Russian anti-virus specialist Kaspersky Labs has identified a variant of MyDoom, the worm that has been spreading through the Internet at a furious pace since Monday.

The variant, which Kaspersky has labelled MyDoom.b, has a slightly larger payload compared with MyDoom.a and targets Microsoft Corp. for a denial-of-service attack to be launched starting on Feb. 1, instead of The SCO Group Inc. The worm features minor modifications to the text of the e-mail that carries it, but is otherwise identical to the original.


(Excerpt) Read more at eweek.com ...


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; News/Current Events; Technical
KEYWORDS: kaspersky; microsoft; mydoom; mydoomb; sco
expanding on an earlier Reuters post...
1 posted on 01/28/2004 3:58:52 PM PST by Leroy S. Mort
[ Post Reply | Private Reply | View Replies]

To: Leroy S. Mort
I posted some additional info about this worm here:

http://www.freerepublic.com/focus/f-news/1065831/posts?page=670#670

Buried in its programming code -- and only readable after it has been decrypted -- was also the message "Andy; I'm just doing my job, nothing personal, sorry" from the creator, Hyppoenen said.

2 posted on 01/28/2004 4:34:52 PM PST by justlurking
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leroy S. Mort
Virus Removal Tools are available free from Symantec.

List of Virus removal tools

The specific tool for this virus is:

Symantec removal tool: Mydoom
3 posted on 01/28/2004 4:37:12 PM PST by TaxRelief (P-A-N-T-H-E-R-S, Go panthers!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leroy S. Mort
There are some interesting domains in the list:

Why is the perpetrator of this worm blocking banner ad sites, along with anti-virus sites and microsoft (particularly Windows update)?

4 posted on 01/28/2004 4:45:30 PM PST by justlurking
[ Post Reply | Private Reply | To 1 | View Replies]

To: justlurking
Why is the perpetrator of this worm blocking banner ad sites, along with anti-virus sites and microsoft (particularly Windows update)?

Probably because those entries were already in the creator's host file. It is a common ad-blocking technique.

While testing the exploit, he listed all of those sites in his own host file. When he entered hosts into the list in the worm, he just grabbed the contents of his host file, thus adding in the addresses that were previously in there.

5 posted on 01/28/2004 5:17:24 PM PST by Knitebane
[ Post Reply | Private Reply | To 4 | View Replies]

To: Knitebane
While testing the exploit, he listed all of those sites in his own host file. When he entered hosts into the list in the worm, he just grabbed the contents of his host file, thus adding in the addresses that were previously in there.

An interesting theory, and plausible. Thanks!

6 posted on 01/28/2004 5:27:27 PM PST by justlurking
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson