On mySimon: Cat Mate C20 Automatic Pet Feeder
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jan 27, 2004 7:35:00 PM

The mass-mailing MyDoom virus has become the fastest spreading program to date and the damage could continue for months or years.

The virus, also known as Novarg and Mimail.R, spread quickly across the Internet on Monday, traveling as an e-mail attachment and infecting PCs whose users opened the malicious file.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


When opened, the virus installs a stealth program on the victim's computer that opens up a software "back door." Attackers can then bypass the PC's security and turn the system into a bounce point, or proxy, for any network-based attack.

The virus has programmed infected PCs to send data to the SCO Group's Web server between Feb. 1 and Feb. 12. The SCO Group has incurred the wrath of the Linux community for its claims that important pieces of the open-source operating system are covered by SCO's Unix copyrights. IBM, Novell and other Linux backers strongly dispute the claims.

Perhaps more troubling is the fact that other online vandals could route new attacks through the infected PCs, said Alfred Huger, senior director of engineering for security software firm Symantec.

"For people that handle incident response, (the proxies) will cause problems," he said. Attackers can use the proxies to hide their real locations, making it very difficult to trace the origin of an online assault. "This is going to hang around and hound us for a long time--if Code Red is any indication, for years."


Special report
20-year plague
From the first experiments
to today's epidemics,
computer viruses have
come a long way.


The Code Red worm infected Windows computers running Microsoft's Web server software, called Internet Information Server. While the primary infection hit in July 2001, tens of thousands of computers remain infected with the worm, which is still scanning the Internet looking for vulnerable systems to infect.

The effects of the massive spread of the MyDoom virus have already been felt.

The virulent program has flooded the Internet with e-mail messages bearing the program, doubling the time it takes most major Web sites to deliver a page. About one in every 12 messages being sent through the Internet contains the virus, said e-mail service provider MessageLabs. The previously most prevalent mass-mailing virus, called Sobig.F, only accounted for one out of every 17 e-mail messages.

Audiocast
arrow Latest computer virus runs rampant in a high-risk outbreak
play audio

"This is the most aggressive that we have seen to date," said Mark Sunner, chief technology officer for MessageLabs, which filters e-mail for corporate customers. However, Sunner believed that the infection rate of the virus had begun slowing by Tuesday afternoon. "It has had one cycle around the world, so it's likely that it's peaked." In the first 27 hours of the infection, MessageLabs quarantined more than 1.5 million messages that included the virus.

The virus affects computers running Windows versions 95, 98, ME, NT, 2000 and XP, and arrives in the user's in-box as an attachment to an e-mail message that appears to be an error response from an e-mail server.

The message sports one of several different random subject lines, such as "Mail Delivery System," "Test" or "Mail Transaction Failed." The body of the e-mail contains an executable file and a statement such as: "The message contains Unicode characters and has been sent as a binary attachment." and "The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment."

The Web site for SCO Group, the target of the virus, was slow to load on Monday and Tuesday, a SCO spokesperson acknowledged. The site has had intermittent problems responding to requests over the past two days, according to Internet performance measurement firm NetCraft.

SCO's Web site was knocked offline by denial-of-service attacks several times in the past year, none of which had been initiated by a virus. In the past, the company has blamed Linux sympathizers for at least one of the attacks.

The MyDoom virus also copies itself to the Kazaa download directory on PCs, on which the file-sharing program is loaded. The virus camouflages with one of seven file names: Winamp5, icq2004-final, Activation_Crack, Strip-gril-2.0bdcom_patches, RootkitXP, Officecrack and Nuke2004.

Not everyone agreed that the attack tools installed on infected systems will have a significant impact on Internet security. With the large number of PCs with poor security, MyDoom-infected computers will be a drop in the bucket, said Vincent Gullotto, vice president of antivirus research for security software company Network Associates.

"There are lots and lots of people that are out there that are compromised today," he said. "I think the mass-mailing part will have more of an impact."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 77 Talkback(s)
Good point
Windows users are not dumb per se, just highly un-trained and some are un-trainable. As are most users on any platform.

You are the exception to the rule. And I don't care what anyone else sa... (Read the rest)
Posted by: bhanes@... Posted on: 02/03/04 You are currently: a Guest | | Terms of Use
MS should apply antivirus thru patches  dg mh | 01/27/04
Best plan ever  Letophoro | 01/27/04
will m$ indemnify their customers?  stephen732@... | 01/27/04
Sarcasm missed  Letophoro | 01/27/04
no sarcasm intended  stephen732@... | 01/27/04
virus should be named "m$doom"  stephen732@... | 01/27/04
Thoughts  gmyx | 01/27/04
Mostly a user problem not an OS problem  scidhuv00 | 01/27/04
Not quite  zen_dogen | 01/27/04
Actually..  d_jedi | 01/27/04
Re: Mostly a user problem not an OS problem  issthatso | 01/27/04
Security was not designed into many products  Sunny Jalolly | 01/27/04
Quick Fix  nite_w0lf | 01/27/04
or perhaps...  stephen732@... | 01/27/04
Fact, some users are as dumb as a rock.  No_Ax_to_Grind | 01/27/04
You're right..look at how many run Windows  SloooeShflu | 01/27/04
So, what you are suggesting is...  vferrara | 01/27/04
Windows Users are dumb  voska | 01/27/04
Rocket science  Yagotta B. Kidding | 01/27/04
Can't help but wonder....  vferrara | 01/27/04
Only people who know how drive can drive  voska | 01/27/04
Hey voska!!  nite_w0lf | 01/27/04
Intelligence???  libertyaikido | 01/28/04
Good point  bhanes@... | 02/03/04
We'll let you tell that to...  BitTwiddler | 01/27/04
I do, CONSTANTLY!  No_Ax_to_Grind | 01/27/04
Message has been deleted.  SloooeShflu | 01/27/04
They do know better  voska | 01/27/04
No internet no e-mail  scidhuv00 | 01/28/04
re: No internet no e-mail  Wolfie2K3 | 01/28/04
Correct, axe...  mvaar | 01/27/04
To quote Einstein (of E=MC^2 fame)  betelgeuse68 | 01/27/04
On Spam  voska | 01/27/04
Good idea! I'd take it a step further...  Yen_z | 01/27/04
Why not?  Yagotta B. Kidding | 01/27/04
Actually it's more like saying  voska | 01/27/04
Food poisoning  Yagotta B. Kidding | 01/27/04
That's true.  Immanuel Tranz-Mischen | 01/27/04
tens of thousands of computers remain infected  Tammee | 01/27/04
psst...  stephen732@... | 01/27/04
this is funny you should read  mattfrand | 01/27/04
Wrong, Tammee  Yen_z | 01/27/04
Exactly but...  Tammee | 01/28/04
Naturally ... Microsoft will claim it's not their fault  George Jay | 01/27/04
re  XunilLinux | 01/27/04
XunilLinux!!  nite_w0lf | 01/27/04
Windows Does that  voska | 01/27/04
I didnt say This Might Be  nite_w0lf | 01/27/04
why?  stephen732@... | 01/27/04
Reply  mattfrand | 01/27/04
Response ...  George Jay | 01/28/04
Blame Game  Aknot | 01/28/04
illogical and irrelevant  Oakman7111 | 02/01/04
2000/05/28:Microsoft Applications Security  David Mohring | 01/27/04
Lets remove the delete key then(nt)  voska | 01/27/04
Why Isn't Microsoft responsible  mattfrand | 01/27/04
Hmmmm  quietLee | 01/28/04
Honestly  mattfrand | 01/27/04
MS should be liable for gross negligance due to sheer number of virii ...  Plain Logic | 01/27/04
Here's a clue  Oakman7111 | 02/01/04
The spread of viral code directly damaging SCO.  xbee | 01/27/04
viral code damage SCO???  thomasmac | 01/30/04
It's an ATTACHED EXECUTABLE  John CarrollZDNet Moderator | 01/28/04
Attached executable  dnmott@... | 01/28/04
Don't TEND...  John CarrollZDNet Moderator | 01/28/04
"Average/normal" Windows users are incompetant?  MarcB_z | 01/28/04
Most of them can spell incompetant  Oakman7111 | 02/01/04
So, basically...  Yen_z | 01/28/04
Wrong villain....  quietLee | 01/28/04
(NT) Lindows changed from 'everyone is root' some time ago :o)  Jack-Booted EULA | 01/28/04
There are no costs associated with this outbreak. microsoft say so.  jellyclock | 01/28/04
Info  SCJames | 01/28/04
Ultimate Linux religious FUDster_prankster  quietLee | 01/28/04
You got that right  Oakman7111 | 02/01/04
mydoom and mac  foxii2000 | 01/28/04
One good thing about MyDoom ---  rbrucecarter | 01/28/04
free antivirus  empty_z | 01/30/04

What do you think?