Feeds

Infected PCs spew MyDoom variant

Business as usual

  • alert
  • submit to reddit

Protecting against web application threats using SSL

The MyDoom worm saga continued today with the release of yet another variant of the noxious email worm. The latest variant - MyDoom-S (AKA MyDoom-Q or MyDoom-R) - poses as a funny photographs in order to dupe users into opening an infectious attachment called photos_arc.exe.

MyDoom-S runs when a Windoze user (Linux or Mac users are immune) clicks on this malicious attachment. Thereafter the worm mass-mails itself to email addresses harvested from the infected machine with the subject line "photos" and message body "LOL!;))))". Like other variants of MyDoom, MyDoom-S also tries to download a backdoor Trojan (in this case Surila-G) from one of a number of websites onto infected PCs. The Trojan allows infected machines to be controlled remotely by attackers in order to send spam, for example.

Finnish AV firm F-Secure reckons virus writers bulk-mailed copies of MyDoom-S from machines infected by earlier versions of the worm in an effort to give their latest creation a kick-start.

In an advisory, F-Secure states: "The source addresses of the spams appear to be from DSL and cable modem pools, suggesting that the MyDoom gang is using a botnet created with earlier MyDoom variants to send this one out. They've also carefully checked that none of the common antiviruses detect this new variant. The worm contains a backdoor. System administrators may also want to block access to domains www.richcolour.com and zenandjuice.com from their network for a while. This variant tries to download components from these addresses but the sites themselves have nothing to do with the virus group."

MyDoom-S began spreading (fairly extensively) today. Most AV vendors rate MyDoom-S as a medium risk threat. MyDoom-S is programmed to stop spreading on 20 August 2004 but the backdoor does not have an expiration date. ®

Related stories

Latest MyDoom hunts victims via Yahoo!
We're all MyDoomed
Microsoft attack worm rides on the back of MyDoom
Google goes gimpy from MyDoom infection
Zombie PCs spew out 80% of spam
Phatbot arrest throws open trade in zombie PCs
MyDoom and Netsky cause chaos
MyDoom is the worst virus ever

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.