Advertisement
Promo

Security threats Toolkit

Viruses target MyDoom infections

Published: 10 Feb 2004 08:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Two worms that take advantage of computers whose security has already been compromised started spreading on Monday, antivirus software companies warned.

The two opportunistic programs -- dubbed Doomjuice and Deadhat -- threatened only those users still infected with a version of the MyDoom virus, and didn't pose a major problem for businesses that had previously cleaned systems infected with the virus, the companies said.

"There are only about 50,000 or 75,000 machines left that are infected," said Vincent Gullotto, vice president for antivirus and vulnerability emergency response team at Network Associates.

Doomjuice, whose spread has been moderate, attempts to direct any re-infected PC to attack Microsoft's Web site, Gullotto said. The re-invigorated attack may be responsible for making Microsoft's site inaccessible on Sunday night and early Monday morning, according to Internet performance measurement firm Netcraft.

The first version of MyDoom spread through email two weeks ago, infecting a new computer every time an unwary user opened the attached file that contained the program. As many as 2 million PCs may have been infected, according to some estimates, while others put the number at 1 million or a few hundred thousand computers.

The original virus was programmed to attack the SCO Group's Web site on 1 February, while the variant MyDoom.B was programmed to target Microsoft's site from 3 February until 1 March.

The original attack succeeded in making the SCO Web site inaccessible when PCs infected with the original version of the MyDoom virus started sending mock Web requests to the company's main server. However, Microsoft appears to have suffered less from its MyDoom strike, benefiting from the slow spread of the second virus and a bug in the code that limits the attack to only 7 percent of all infected computers.

However, Microsoft had some Web site problems early on Monday, according to Netcraft. It's unknown if the latest worms caused the issues. Microsoft couldn't immediately comment on the issue.

Doomjuice, which scans for PCs infected with MyDoom, has spread to enough computers that customers have submitted samples to Network Associates' Gullotto.

"The Doomjuice has had some success," Gullotto said. "It only infects machines that [have been compromised], so obviously some people didn't know they were infected."

Network Associates still hasn't received any samples of the other worm, Deadhat. While some antivirus companies, including Network Associates and Symantec, believe the virus spreads by scanning for vulnerable computers that have already been infected with the MyDoom viruses, the worm hasn't spread as far as Doomjuice. Deadhat also spreads through the peer-to-peer file sharing program SoulSeek.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
63 out of 115 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters