On TechRepublic: 10 biggest failures in IT history
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Feb 21, 2004 12:39:00 AM

A variant of the MyDoom virus has started spreading, albeit slowly, and security experts expect it to target the main Web site of the music industry.

The variant, MyDoom.F, deletes several different types of files stored on an infected computer and aims to attack the Web sites of Microsoft and the Recording Industry Association of America with a flood of data, antivirus companies said Friday.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Neither site may feel much pain, however, as the virus has failed to spread quickly.

"It is not very prevalent," said Craig Schmugar, virus research manager for Network Associates' vulnerability emergency response team. "We haven't seen anything beyond (a single) sample in the past 24 hours."

The original MyDoom spread through e-mail in late January, infecting a new computer every time an unwary person opened the attached file containing the program. Between several hundred thousand and 2 million computers were infected, according to estimates.

Antivirus firms believe that the writer of the MyDoom.F virus is different from the person believed to have authored the first two versions of the code. A later worm, Doomjuice, spread to computers that were already infected by MyDoom and dropped copies of the original virus' source code. It's thought that the author of MyDoom.F used that code to write this new virus.

"Right now, it feels like someone took the original one and modified it," said Vincent Weafer, senior director for the antivirus research center at security company Symantec. "That's just a gut feeling."

The MyDoom.F virus spreads using a variety of subject lines and message text, usually attaching itself to the message as a Zip compressed file. The virus infects Windows computers when the user opens the file.

PCs compromised by the virus send out virus-laden e-mail messages using random addresses found in a variety of files, such as cached Web pages and the Windows address book. The virus also deletes Word documents, JPG picture files, Audio Video Interleaved files, Excel spreadsheets and a few other types of files.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 12 Talkback(s)
Obviously don't know how DRM works
DRM is to restrict me from using content that I purchase.

A virus writer doesn't want to restrict how I use thier virus. They want me to run in any possible and will go to great lenghts to convince and trick me into running the virus.

DRM won't help in the slightest.... (Read the rest)
Posted by: voska Posted on: 02/23/04 You are currently: a Guest | | Terms of Use
*yawn*  B_HI | 02/20/04
Exactly..take your "doom" and shove it up your pocket protector!  Bobby Sskcat | 02/20/04
not as powerful as the original...  ctk76 | 02/20/04
and who reads that web site?  V Sanders | 02/20/04
Does the author/s....  JoeMama_z | 02/20/04
Absolutely nobody  d_jedi | 02/21/04
It's helping them convince morons  zd-spam | 02/21/04
this is why we need DRM built into the OS  V Sanders | 02/21/04
You are joking right?  doe_z | 02/21/04
What are you talking about  zd-spam | 02/21/04
Obviously don't know how DRM works  voska | 02/23/04
big deal  lotta_anger | 02/23/04

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline