ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Viruses target MyDoom infections

Published: 10 Feb 2004 08:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two worms that take advantage of computers whose security has already been compromised started spreading on Monday, antivirus software companies warned.

The two opportunistic programs -- dubbed Doomjuice and Deadhat -- threatened only those users still infected with a version of the MyDoom virus, and didn't pose a major problem for businesses that had previously cleaned systems infected with the virus, the companies said.

"There are only about 50,000 or 75,000 machines left that are infected," said Vincent Gullotto, vice president for antivirus and vulnerability emergency response team at Network Associates.

Doomjuice, whose spread has been moderate, attempts to direct any re-infected PC to attack Microsoft's Web site, Gullotto said. The re-invigorated attack may be responsible for making Microsoft's site inaccessible on Sunday night and early Monday morning, according to Internet performance measurement firm Netcraft.

The first version of MyDoom spread through email two weeks ago, infecting a new computer every time an unwary user opened the attached file that contained the program. As many as 2 million PCs may have been infected, according to some estimates, while others put the number at 1 million or a few hundred thousand computers.

The original virus was programmed to attack the SCO Group's Web site on 1 February, while the variant MyDoom.B was programmed to target Microsoft's site from 3 February until 1 March.

The original attack succeeded in making the SCO Web site inaccessible when PCs infected with the original version of the MyDoom virus started sending mock Web requests to the company's main server. However, Microsoft appears to have suffered less from its MyDoom strike, benefiting from the slow spread of the second virus and a bug in the code that limits the attack to only 7 percent of all infected computers.

However, Microsoft had some Web site problems early on Monday, according to Netcraft. It's unknown if the latest worms caused the issues. Microsoft couldn't immediately comment on the issue.

Doomjuice, which scans for PCs infected with MyDoom, has spread to enough computers that customers have submitted samples to Network Associates' Gullotto.

"The Doomjuice has had some success," Gullotto said. "It only infects machines that [have been compromised], so obviously some people didn't know they were infected."

Network Associates still hasn't received any samples of the other worm, Deadhat. While some antivirus companies, including Network Associates and Symantec, believe the virus spreads by scanning for vulnerable computers that have already been infected with the MyDoom viruses, the worm hasn't spread as far as Doomjuice. Deadhat also spreads through the peer-to-peer file sharing program SoulSeek.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
61 out of 112 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

McAffee Anti-Virus Rollout Engineer (Field Based)

My West Midlands based client has a requirement for 2 Engineers to rollout McAfee Anti-Virus on to 600+ desktops at multiple sites throughout the ...

McAffee Anti Virus Rollout Engineer CRB Cleared

The role will require the following - - Experienced in field support - Windows 2000 / XP / Vista - Anti - Virus experience For an immediate telephone ...

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS Active Directory 2000/2003 and MS Exchange messaging ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment