Advertisement
Promo

Security threats Toolkit

Microsoft offers bounty for creator of MyDoom variant

Published: 30 Jan 2004 08:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft announced on Thursday that it will offer $250,000 (£136,563) for information leading to the capture and conviction of the individual or group responsible for the release of MyDoom.B.

The original MyDoom virus started spreading on Monday and quickly swamped the Internet. The MyDoom.B variant appeared on Wednesday and, among other things, prevents an infected PC from accessing some Microsoft Web sites and targets Microsoft's main Web site with a denial-of-service attack due to start on 1 February.

"When we looked at the B variant, we found it to be much more malicious," said Sean Sundwall, a spokesman for the software giant. "It's not that we think the person who wrote the original [virus] is not just as culpable."

The reward is the third time Microsoft has posted a $250,000 "Wanted" sign on the Internet. It offered the same amount for information leading to the capture and conviction of the persons or groups responsible for releasing the MSBlast worm and the Sobig.F virus.

Microsoft's reward is the second prompted by the MyDoom epidemic. The SCO Group announced on Tuesday that it is offering $250,000 for information that leads to the capture of the writer of the original virus. Both the original MyDoom virus and the modified version released on Wednesday target SCO's Web site with a denial-of-service attack.

While the people who have released variants in the past haven't been considered to be as malicious as the original virus writer, Microsoft's Sundwall said the modified MyDoom seems much worse than the original. It overwrites the original and attempts to block an infected computer's access to sites that could host important security updates.

"And it attacks us (at Microsoft), of course," Sundwall said.

Computers infected by the variant are expected to begin to deluge the Web sites of Microsoft and the SCO Group with traffic from 1 February, or the first time they are turned on after that, until 12 February, or when they are shut down after that. It is likely that the attack will be difficult to stop, because it will just appear to be regular attempts to access the Web sites.

Neither the FBI, which should be contacted with tips, nor Microsoft, have indicated what, if any, progress has been made tracking down the two perpetrators, for which rewards have already been offered.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
89 out of 147 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters