Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Virus and Vulnerability Roundup
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Update: New Mydoom worm discovered

The new variant, Mydoom.B, targets Microsoft for a denial-of-service attack

January 28, 2004 12:00 PM ET

Computerworld - A new variant of the Mydoom.A (Novarg.A) worm, which has been spreading swiftly across the Internet since Monday, emerged today, according to London-based security vendor Mi2g Ltd.
The variant, Mydoom.B, has a larger payload and targets Microsoft's Web site for a distributed denial-of-service attack on Feb. 1, instead of The SCO Group Inc.'s Web site, which was targeted by the first version, Mi2g said in a statement. Mi2g pointed to minor changes to the text padding in the malware and said it's possible that Mydoom.B is being disseminated via infected computers turned into zombie machines by Mydoom.A, as well as the Kazaa file-sharing system.
If so, "this could turn the whole Mydoom episode into a much more adverse series of unfortunate events," Mi2g said.
No one has yet reported an infection by Mydoom.B, said David Perry, global director of education at Cupertino, Calif.-based antivirus vendor Trend Micro Inc. "If 100 people in the world had been infected, we would know," he said. "In fact, almost all of the viruses that have ever been detected never infected anybody ever. We say that there are about 77,000 known viruses, but only about 900 of them have ever infected anyone."
Even so, security companies said the emergence of another version of the worm could cause problems.
"This is an extremely unwelcome development. Mydoom.b may have just multiplied the full impact of Mydoom.A a few fold," said D.K. Matai, executive chairman of Mi2g. "We know that many large and small organizations as well as homes are struggling to cope with the deluge of e-mails originating from the 'a' variant infections -- never mind the arrival of 'b,' which shows signs of being just as vicious."
Early information indicates that the new variant is likely spreading in the wild, said Ken Dunham, director of malicious code at iDefense Inc., a security consulting company in Reston, Va.
Dunham said the Mydoom.B worm modifies the standard hosts file in a Windows folder that can block access to 65 Web sites, most of which are antivirus Web sites, in an apparent attempt to block users from downloading antivirus solutions and data.
"This new variant of Mydoom is worse than Mydoom.A," Dunham said in a statement via e-mail. "And an attack on the Microsoft.com Web site could cause a significant disruption of services for users worldwide. It's feasible that Mydoom.A computers are now being used to help launch Mydoom.B, via the proxy setup supported by the worm. If this is the case, Mydoom.B will likely become very prevalent in the wild in just a few short hours."
Although that doesn't mean millions of computers are actually infected, it could mean millions of e-mails harboring the worm are in the wild, Dunham said.
He said computer users should be on guard for a succession of worm attacks this year. "Undoubtedly, attackers are now mirroring the success of worms like Sobig to launch successive attacks in 2004," Dunham said.
Security vendor BitDefender in Bucharest, Romania, said Mydoom.b is only slightly different from the first virus variant.
"Still, we can expect a new wave of infections, as the author already has a base target," said Mihai Neagu, a virus researcher at BitDefender. "It seems, by the sheer amount of the first version that got sent through networks at this point, that many users will inadvertently cause a new major outbreak."
Moscow-based security software developer Kaspersky Labs has a different reading of the new variant than Mi2g. It said Mydoom.B is scheduled to launch a DoS attack between Feb. 1 and Feb. 12 on both www.sco.com and www.microsoft.com.
"Our analysts believe that Mydoom.B is probably using machines infected by the original Mydoom, which could mean as many as 600,000 units," Kaspersky Labs said in a statement via e-mail. "These infected computers may have received a command to send out copies of Mydoom.B. Therefore, the computer community may be facing a much more serious outbreak than the one caused by Mydoom.A on Jan. 27."






Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

Case Study: The Ritz London
Discover how the superior capabilities of Webroot E-mail Security SaaS allows user to focus on their principal tasks instead of wasting their time...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Case Study: Richmond Ambulance Authority (RAA)
In this case study, find out how Webroot Web Security SaaS delivers the proactive web security RAA needs....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Can Heuristic Technology Help Your Company Fight Viruses?
(Source: MessageLabs - now part of Symantec) In the face of today's increasingly sophisticated malware, using multiple layers of email and web protection...  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....