New MyDoom Worm variant strikes
By Jake Winemiller
July 2004
On Monday, July 26th, an apparent variant of the MyDoom worm was
unleashed and is currently severely affecting overall performance on the
internet.
It has specifically been programmed to attack search engines (Google,
Yahoo, AltaVista, and Lycos) from infected machines and brought those
engines to a near crawl today.
It also affects performance of individual computers that are infected
because of the memory and processor usage on the individual machines.
According to reports, messages sent by the variants pose as either a
"returned mail" message from a postmaster or an alert from an internal IT
administrator and were realistic enough to fool many workers this morning.
There may also be a potential “backdoor” installed on the home computer
that can allow hackers to get easy access and control your home or office
computer.
If you notice slow moving email or believe that your web site is not
loading as quickly as before, please understand there is essentially a
logjam on the internet, but shared web servers are predominantly Unix, and
not susceptible to this worm.
For more information and removal instructions, please visit
http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.m@mm.html.
In the meantime, here are some tips to help avoid any danger or infection
caused by this worm:
- DO NOT open ANY email attachments from anyone- whether you know them
or not- unless you are expecting that particular file from them.
- Update your virus definitions immediately (even if you have it set to
automatically update) and continue to do so over the next few days.
- If you notice mild performance issues on your computer (not browsing
the web, but actually processing), use instructions found on Symantec’s
web site to determine if you have been infected.
New Virus Update
There is another new piece of malicious code that has been infecting
machines over the past couple days. The email features a link purporting to
contain pictures of Osama Bin Laden committing suicide, taken by CNN
photographers.
This is a FRAUD.
The link simply gives the virus a way to breach you computer and installs
the proper pieces of code to turn your PC in a “Zombie”- one that is
completely able to be controlled by the hacker to perform whatever illegal
activity he or she feels is necessary.
If you come across a link claiming to have these pictures in an email or
message board, please discount it immediately. Also, update you virus
definitions, as most companies have issued fixes/detectors for the latest
virus. |