Advertisement
Promo

Online business Toolkit

MyLife variant viruses spawned over Easter

Matt Loney ZDNet.co.uk

Published: 02 Apr 2002 14:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Four mutations of the destructive MyLife virus were released over the weekend, according to anti-virus companies.

Of the four, only one appears to be spreading widely. Email outsourcing company MessageLabs said it had stopped over 140 copies of MyLife.f on Tuesday morning -- about half of these appeared to originate from Australia, and many of the rest were from the UK. A small number were from Hong Kong, the company said.

MyLife.f is a variation on MyLife.b (w32.mylife.b@mm, also known as Caric.a), which was notable for its caricature of Bill Clinton playing a saxophone with a bra hanging out. This virus fixed bugs that plagued the original worm, MyLife.a (w32.mylife.a@mm), and besides emailing copies of itself to everyone included in the Windows address book, MyLife.b executed its file-destroying payload whenever an infected computer is rebooted in an hour divisible by 8, such as 8:00 or 16:00

"Over Easter we spotted that the MyLife author released versions C, D, E and F of MyLife," said Alex Shipp, senior antivirus technologist at Messagelabs. "We saw MyLife.f kick off in Australia this morning and now coming over here." Variant F, which has been spreading since the weekend, appears to be "pretty tame", said Shipp, as do variants D and E.

But MyLife.c carries a payload which, according to antivirus firm Symantec, could format drives and delete files, depending on the system time. Shipp said that Messagelabs had only stopped one copy of MyLife.f by Tuesday morning, and was still analysing it. "The jury's still out on whether it will actually activate as it is meant to," Shipp added.

All four new variants of MyLife share the same mass-mailing characteristics of the original, and email themselves itself to all email addresses in the Microsoft Outlook address book and the MSN Messenger contact list.

According to Symantec, MyLife.c arrives as the attachment List.TXT.scr, and is likely to activate itself when the system time minutes variable is greater than or equal to 50 and the worm has been run on the system at least once already. If it does activate, it is likely to try to format drives D, E, F, G, H and I, as well as deleting all files on the C: drive.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 99 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters