MyDoom is a computer worm which is also known as Mimail.R, Shimgapi, Novarg and W32.MyDoom@mm. This computer worm targets computers running Microsoft Windows and was first discovered on 26th January 2004. This quickly became the fsatest spreading worm of all time which beats the previous record of the Sobig Worm.
MyDoom sends junk email to many different addresses which is how it spreads itself. The worm also has the text message "Andy, I'm just doing my job, nothing personal, sorry" This makes people believe that the worm was written by someone who was paid to write it. Although the actual creator of the w32.mydoom virus remains unknown it has been speculated that the worm was created by an underground professional programmer in Russia.
It has also been suggested that the worm is designed to target the SCO group in a denial of service attack. A quarter of all MyDoom.A infected computers targeted www.sco.com which was enough to affect their servers. SCO suggested this was as a result of their recent claims over Linux, this theory was soon discounted, the most recent theory is that the worm was created by organised crime gangs on the internet. The first researchers of mydoom suggested that it was a close relative of the Mimail worm, which is why it's also known as the Mimail.R worm.
The name Mydoom was given by Craig Schmugar who works at McAfee, this name was chosen because the program code contained the text "mydom" and that it was a very important and serious virus.
Mydoom is normally transmitted by email attachments, the subject line normally says something like "Mail Delivery System", "Error", "Test", or "Mail Transaction Failed" These messages appear in many different languages, including French & English. If you run the attachment contained in an infected message then the worm will resend itself to anyone in your address book, it will also copy the worm to the shared files folder of KaZaA to try and speed up how fast it spreads.
Mydoom is a pretty smart virus, it deliberately avoids sending emails to Symantec, Microsoft, and some universities such as UC Berkeley, Stanford, Rutgers and MIT.
There are two versions of Mydoom, Mydoom.A and Mydoom.B. Mydoom.A is thought to have two functions, it opens a backdoor on port 3127 which allwos the remote computer to be accessed. It also attempts a DOS (Denial of service) attack on the SCO Group website. This only worked on 25% of infected computers.
The second version, Mydoom.B carries the same payloads, but it also targets additional websites such as the Microsoft site and restricts access to certain websites such as the Microsoft and the main antivirus websites.
Fortunately it's not that difficult to find mydoom removal methods, you can often follow the same techniques used to remove virus. Updating your antivirus application is the way to go, one great antivirus program you might like to try is Micro Antivirus. Make sure that you regularly update the virus definitions to ensure that the mydoom fix works. It's also possible to download a free mydoom fix from many popular antivirus websites.
|