Beating the New MyDoom (Windows) Variant

Beating the New MyDoom (Windows) Variant

Written By
Jay Munro
Jay Munro
Jan 28, 2004
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The new W32/MyDoom.B-mm virus adds another twist to the MyDoom story. In addition to switching the DNS attack to Microsofts web site, it uses a standard mechanism in Microsoft Windows to block a users access to antivirus sites.

MyDoom.B overwrites the existing Windows Hosts file, normally empty, with a file that blocks the real addresses of most antivirus sites. This means that at a time when you need an antivirus software vendors support most (during infection), you wont be able to get it.

The Hosts file acts as a local DNS (Domain Name Server/Service) on a Windows machine, and takes precedence over the global DNS request that every browser makes when you enter a URL, such as www.pcmag.com. Normally, when you request a web site, your browser sends a request to a global DNS, which returns the actual IP address of the site. Your browser then uses that IP address to access the web site, and bring you the web pages. If an address, such as www.microsoft.com is in the Windows Hosts file, your browser gets whatever address is stored there, and doesnt bother going out to the global DNS.

Click here for the complete story, including removal instructions.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.