Advertisement
Promo

Online business Toolkit

MyLife variant viruses spawned over Easter

Matt Loney ZDNet.co.uk

Published: 02 Apr 2002 14:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Four mutations of the destructive MyLife virus were released over the weekend, according to anti-virus companies.

Of the four, only one appears to be spreading widely. Email outsourcing company MessageLabs said it had stopped over 140 copies of MyLife.f on Tuesday morning -- about half of these appeared to originate from Australia, and many of the rest were from the UK. A small number were from Hong Kong, the company said.

MyLife.f is a variation on MyLife.b (w32.mylife.b@mm, also known as Caric.a), which was notable for its caricature of Bill Clinton playing a saxophone with a bra hanging out. This virus fixed bugs that plagued the original worm, MyLife.a (w32.mylife.a@mm), and besides emailing copies of itself to everyone included in the Windows address book, MyLife.b executed its file-destroying payload whenever an infected computer is rebooted in an hour divisible by 8, such as 8:00 or 16:00

"Over Easter we spotted that the MyLife author released versions C, D, E and F of MyLife," said Alex Shipp, senior antivirus technologist at Messagelabs. "We saw MyLife.f kick off in Australia this morning and now coming over here." Variant F, which has been spreading since the weekend, appears to be "pretty tame", said Shipp, as do variants D and E.

But MyLife.c carries a payload which, according to antivirus firm Symantec, could format drives and delete files, depending on the system time. Shipp said that Messagelabs had only stopped one copy of MyLife.f by Tuesday morning, and was still analysing it. "The jury's still out on whether it will actually activate as it is meant to," Shipp added.

All four new variants of MyLife share the same mass-mailing characteristics of the original, and email themselves itself to all email addresses in the Microsoft Outlook address book and the MSN Messenger contact list.

According to Symantec, MyLife.c arrives as the attachment List.TXT.scr, and is likely to activate itself when the system time minutes variable is greater than or equal to 50 and the worm has been run on the system at least once already. If it does activate, it is likely to try to format drives D, E, F, G, H and I, as well as deleting all files on the C: drive.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 99 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters