CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Advisories!: New worm W32/MyDoom.A image
Worms

New worm W32/MyDoom.A



- New worm W32/MyDoom.A worm causes numerous infections in corporate
environments -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)


MADRID, January, 27, 2004 - New worm W32/Mydoom.A.worm has already reached
red alert status according to the virus labs of Panda Software.

There have
already been many incidences with thousands of users in numerous countries.
The ability of W32/MyDoom.A to spread rapidly, as well as the damage it is
leaving behind, makes W32/Mydoom.A.worm as serious as last summers Bugbear
and Blaster.

W32/Mydoom.A worm forwards itself to all the addresses found in the affected
computers. As other countries begin the usual workday increasing computer
activity it is expected that this virus will grow and create more issues.

W32/Mydoom.A worm comes via an e-mail message with an attached file. Like
the other recent virus epidemics, social engineering techniques cheat the
user making the think they are supposed to open the file. The virus not only
infects the computer that received the e-mail but then mails itself to all
the contacts found in addresses book.

In addition, it opens the TCP port 3127 in the infected computer, allowing
remote control of the computer. It means any malicious hacker may get access
and steal, modify or destroy any kind of Information stored in the computer.

As additional Information, this virus is ready to launch a Denial of Service
attack against the web site www.sco.com next February, 1st this year.

W32/Mydoom.A worm search e-mail addresses in the computer files with the
extensions: .htm, .sht, .php, .asp, .dbx, .tbb, .adb, .pl, .wab, .txt. It
uses its own SMTP engine to send itself by e-mail.

The message content changes, and may be composed by the following sentences:

Subject:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Body:
Mail Transaction Failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary
attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent
as a binary attachment

Attached file name:
document
readme
doc
text
file
data
test
message
body

File extension:
.pif
.scr
.exe
.cmd
.bat
.zip

Once the virus has infected the computer, it then searches for the
peer-to-peer file sharing Network KaZaa. If KaZaa is detected a file is
copied to the shared folder allowing its distribution via this peer to peer
system. The filename may be one of the following ones:

winamp5
icq2004-final
activation_crack
strip-girl-2.0bdcom_patches
rootkitXP
office_crack
nuke2004

and PIF, .SCR o .BAT extension.

Panda Software offers updates to all its customers to detect and eliminate
W32/Mydoom.A worm. Users who have not enabled automatic updates can upgrade
the antivirus in http://www.pandasoftware.com/.

Due to the possibility of being infected by W32/Mydoom.A.worm, Panda
Software advises users to treat all e-mails received with caution, and to
update their antivirus solutions as soon as possible and installing a good
firewall.

Similarly, users can also detect and disinfect this and other malicious code
using the free, online antivirus, Panda ActiveScan, which is available on
the company's website at http://www.pandasoftware.com/. Also, PQRemove
http://www.pandasoftware.com/download/utilities/ free disinfection tool is
available for all users.

Detailed technical information on W32/Mydoom.A.worm is available from Panda
Software's Virus Encyclopedia.

NOTE: The addresses above may not show up on your screen as single lines.
This would prevent you from using the links to access the web pages. If this
happens, just use the cut and paste options to join the pieces of the
URL.
Posted on Tuesday, 27 January 2004 @ 18:23:34 UTC by phoenix22 (1328 reads)
[ Trackback ]
image

"Advisories!: New worm W32/MyDoom.A" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· PHP-Nuke
· HotScripts
· W3 Consortium
· More about Worms
· News by phoenix22


Most read story about Worms:
Kama Sutra/Blackworm Worm Timebomb

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer