New MyDoom Piggybacks a Nastier Worm

執筆者
Jay Munro
Jay Munro
Published: Aug 18, 2004
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft on Aug. 25 is rolling out the Windows XP Service Pack 2 to the new Windows Update site so the public can update automatically. For the majority of home users, its a case of “just do it.”

Meanwhile, MyDoom is back with a new variation that downloads a particularly nasty Trojan called Backdoor.Ratos.A.

The SP2 update adds security features that home users should not be without. If you know a home user who doesnt understand security, make sure they update. Either click on Windows Update from the start menu, or visit the Microsoft home security site.

/zimages/2/28571.gifClick hereto read more about Microsofts decision to delay automatic delivery of Windows XP SP2.

But since the Service Pack 2 update has the potential to break applications, especially ones in corporate use, many companies are opting not to update until theyve had time to test.

Microsoft, in response, offered a way to disable automatic updating for four months from the public release date. One caveat is that the update disabler needs to be applied to a system before it is updated.

Once youve installed Windows XP SP2 and the new Windows Firewall is enabled, you may find that some programs do not work correctly. This is usually just a simple tweak of the firewall to let the application work with the Web. See our Security Tip for a jumpstart on how to exempt ports and applications in the new Windows Firewall.

A few weeks ago, we told you about a Windows CE concept virus, which had been sent to anti-virus vendors to prove it could be done. But the first Windows CE Trojan, Backdoor.Brador.A, has now been seen in the wild.

According to reports, the Trojan affects Windows CE Version 4.2 (on Pocket PCs) and spreads through e-mail or downloaded programs. The virus requires user interaction to install, either opening the e-mail or downloading the file. Once infected, the virus opens a back door and sends your IP address to the attacker.

The good news is that you have to do something to get it, and it doesnt spread on its own. F-Secure and TrendMicro claim to have solutions.

MyDoom is back with W32/MyDoom.S-mm. This variation, also known as MyDoom.Q@mm, Worm_Ratos.A, and I-worm.Win32.Ratos, was discovered Sunday and jumped to a medium-level threat very quickly.

While MyDoom.S doesnt really do much, it downloads a particularly nasty Trojan called Backdoor.Ratos.A. See our top threat for more information.

Advertisement

Meanwhile, Netcraft is reporting some encouraging information on phishing sites. According to a June report from the Anti-Phishing Working Group, here in PDF form, the average life of a phishing Web site is just 54 hours.

/zimages/2/28571.gifTo read the full story,click here.

Jay Munro

Jay Munro

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。