Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    MyDoom E-Mail Worm Spreading Quickly

    Written by

    Dennis Fisher
    Published January 26, 2004
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A fast-moving Windows worm known as MyDoom on Monday began spreading at a furious rate on the Internet.

      MyDoom arrives via e-mail and has a randomized senders address and subject line. The body of the message varies, but purports to be an error message, such as: “The message cannot be represented in 7-bit ASCII and has been sent as a binary attachment.”

      /zimages/1/28571.gifFor tips from PC Magazine on blocking and removing MyDoom, click here.

      The file attachment is often in a ZIP archive format and can have any one of a number of file extensions, including .exe, .pif and .scr. The icon for the attachment looks like the one used for text messages in Windows.

      Once the user runs the attached file, the worm copies itself to the machine in the following manner:

      • c:Program FilesKaZaAMy Shared Folderactivation_crack.scr
      • c:WINDOWSDesktopDocument.scr
      • c:WINDOWSSYSTEMtaskmon.exe

      One IT manager said he was now blocking all ZIP attachements to limit the spread of MyDoom.

      MyDoom also copies itself to the registry in Windows so that it executes at startup, according to a preliminary analysis by Network Associates Inc.s McAfee Security unit. The worm also opens Port 3127 and begins listening for instructions from a remote host.

      Much of the data in the worms code is encrypted, anti-virus experts said, making analysis of the worm much more difficult. Some users reported receiving as many as 100 copies of the worm in a 30-minute span on Monday afternoon.

      Next page: MyDoom infecting one of 12 e-mails.

      Page Two

      As IT departments continue to battle the MyDoom worm, it likely will come as little comfort that anti-virus companies are nearly unanimous in their opinion that the worm is the fastest-moving virus theyve ever seen.

      MyDoom is now infecting one in every 12 e-mail messages, worse even than the 1:17 ratio achieved last year by SoBig, according to MessageLabs Inc., a New York-based e-mail security company. The company said Tuesday morning that it has stopped more than 1.2 million copies of MyDoom from nearly 170 countries. Late Monday afternoon, officials at Network Associates said that one of the companys customers was blocking 5,000 copies of the worm every minute.

      These numbers are only going to get worse in the next few hours, experts say, as users in the western part of the United States come online and begin opening their e-mails.

      In addition to its ability to cripple corporate networks, MyDoom also has the ability to launch a denial-of-service attack and its intended target is The SCO Groups Web site. It seems to be doing that job as well, as the much-maligned companys site was unreachable Tuesday morning.

      /zimages/1/28571.gifRead “MyDoom More Bad News for SCO.”

      At the same time, MyDoom was hardly the only thing attracting security experts attention Monday. Two other viruses, dubbed Mimail.Q and Dumaru.Y also hit the Web in the last couple of days.

      Mimail.Q, which debuted Monday, is a polymorphic virus, meaning it changes its characteristics over time. It is a mass-mailer and contains the subject line: “Hi my sweet Nancy.”

      The Mimail.Q message body changes, as does the name of the attachment containing the virus, according to MessageLabs Inc., an e-mail security company based in New York.

      /zimages/1/28571.gif

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.