Yet another E-mail Virus/Worm MyDoom

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Faram
Bastard Operator from Hell
Posts: 5270
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Yet another E-mail Virus/Worm MyDoom

Post by Faram »

Extra Extra! Read all about it!
Summary

Mydoom is a worm that spreads over email and Kazaa p2p network. When executed, the worm opens up Windows' Notepad with garbage data in it. In emails, it uses variable subjects, bodies and attachment names. It also attacks SCO.COM with a DDoS-attack. This attacks starts on February 1st.

The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE.

Mydoom is programmed to stop spreading on February 12th
Use common sense please, Don't open strange stuff in the mail.

And update your AV database.
Last edited by Faram on 2004-01-27 06:43am, edited 2 times in total.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Superman
Pink Foamin' at the Mouth
Posts: 9690
Joined: 2002-12-16 12:29am
Location: Metropolis

Post by Superman »

I really think that it's about time for every country in the world to impose the death penalty for people who create these things.
Image
User avatar
Daltonator
Reclusive Wanker
Posts: 383
Joined: 2003-03-23 03:10pm
Location: Zelda fanboy heaven
Contact:

Post by Daltonator »

Already on the news here. Apparently it spreads in a similar way to Swen.
JMS 4:22 | Image
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

http://slashdot.org/articles/04/01/27/1 ... 187&tid=88

Very lively thread about it on Slashdot. Multiple theories abound as to who did it, such as an obvious and malicious Libelous FUD Attack[cnn.com] on the OSS Community, RIAA attack on Kazaa[slashdot.org], and even a couple crackpot ones saying IBM made it to harm SCO (unlikely because of the spam, backdoor, and Kazaa functions), and SCO itself making it as a PR stunt! :shock: :wtf: :wtf:

These[slashdot.org] posts[slashdot.org] state what is IMO the most plausible scenario as to where it came from: Spammers. My experience with spammers has shown me that they have total disregard for who's property they steal and vandalize as long as they get Return On Investment from idiots who actually buy from the Terrorist (hold the 'yu0=Bush' flames please :teeth: ) blood-belching cuntfaces.

This[slashdot.org] one sums up my feelings about the matter to a T. I hate $CO as much as anyone else here for their bullshit crimes, but the only way OSS will win the day is to keep the fight clean and let the truth come down the pipe of its own accord.

As to the idiotic practice of server AV bouncing virus-infected emails (with live worm still attached!) to the sender even or ESPECIALLY if the virus spoofs the sender(thereby conveniently advertising the AV companies' software and compounding the problem by an order of magnitude), This[slashdot.org] is what I think. STOP BOUNCING THE FUCKING VIRUS EMAILS, ASSHOLES!! :roll:

/me dual-wield rattles Double LARTs in anger...
Image Image
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Since when was Slashdot considered a credible source?
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

phongn wrote:Since when was Slashdot considered a credible source?
Good point, but it was more to show what people are saying.

Bruce Perens also believes Mimail/Mydoom/Whatever is made by spammers too. Remember, earlier Mimail variants DDoSed SpamHaus and other anti-spam orgs until they folded. It fits the pattern.
Bruce Perens wrote:Message to the Linux and Free Software Community Regarding the SCO Denial-of-Service Virus

Bruce Perens <bruce@perens.com> (U.S.) 510-526-1165
Version 2, January 27, 2004.

The master version of this notice is at http://perens.com/Articles/SCO/DOS/ [perens.com]
Please check that location for a more recent version. You may re-publish this material. You may excerpt it, reformat it and translate it as necessary for your presentation. You may not edit it to deliberately misrepresent my opinion.

On January 26, 2004, a new virus became rampant. I have read reports that the virus payload has two purposes: to install a remote-execution back-end of a type commonly used by spammers to redistribute email, and to perform a denial-of-service attack on SCO's web site.

Denial-of-service attacks via virus have been a common trick of email spammers. They were first used to take out some of the anti-spam blacklist sites. Several of those sites had their (non-spam-related) business so heavily disrupted that they closed the doors of their anti-spam projects rather than be attacked again.

The Open Source developers are a target of spammers. We are the creators of most high-profile anti-spam technology. For example, SpamAssassin started out as, and remains today, an Open Source project. The predominant mail delivery programs of the Internet are Open Source projects such as Sendmail and Postfix, and thus most efforts to spam-proof those programs are Open Source as well. This is important, because it gives spammers a reason to defame us.

SCO also has a reason to defame us, as part of their stock-kiting scheme. We have assembled ample evidence that they have lied under oath in court. Such a company would not balk at attacking their own site in order to paint their opponents in a bad light.

Thus, it is likely that this virus has been assembled for the purpose of defaming the Linux developers by spammers, SCO, or others. Your behavior will influence whether or not it succeeds in this mission.

Thus, I urge all persons who have sympathy for Free Software, Open Source, and Linux:

* Do not cheer on attacks on the SCO site. By doing so, you falsely implicate our community in the attacks, in the eyes of outsiders who read your words. Our community believes in freedom of speech, not silencing our opponent's speech through net attacks. We will defeat SCO using the truth, not by gagging them.
* Publicly deplore the attacks as an attempt to defame us, and not an effort of our community. Show others this notice.
* Continue to fight SCO, using all legal means at your disposal. Show others the analysis of SCO's ongoing fraud at Groklaw.net [groklaw.net] and elsewhere, and explain to them your own experience as a participant in the Free Software community.
* Continue the visible presence of Free Software as a force for good in the world by producing excellent original software for everyone's free use and deploying it wherever possible. Promote these projects to the press and public as you carry them out. Do what you can for other public-good projects such as schools and non-profit organizations. FreeGeek.org [freegeek.org] is an excellent example of how to carry this out.
* Show others by example that our side always takes the high road. When they see a low-road sort of action like denial-of-service, spam, or stock fraud, they'll know who to blame.

Remember that your actions count. You are ambassadors of our community.

Many Thanks

Bruce Perens
Image Image
User avatar
Sokartawi
Crazy Karma Chameleon
Posts: 805
Joined: 2004-01-08 09:17pm
Contact:

Post by Sokartawi »

So what? The only one that are infected by this are lamers, and the only ones harmed by it appear to be the lamers, possibly M$ (I read somewhere that it will launch a DOS attack against that too) and SCO. I won't shed any tears for those.
Stubborn as ever - Let's hope it pays off this time.
User avatar
Faram
Bastard Operator from Hell
Posts: 5270
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Sokartawi wrote:So what? The only one that are infected by this are lamers, and the only ones harmed by it appear to be the lamers, possibly M$ (I read somewhere that it will launch a DOS attack against that too) and SCO. I won't shed any tears for those.
Great reasoning!

A computer is a tool and just because many don’t know how to maintain a computer and keep it and the applications on it updated we should call them lamers and assholes.

I mean everyone must have computer as their primary interest to use one otherwise they should stay out of your internet and bother you and your migty Haxx0r skills.

If you should blame anyone it’s Microsoft for writing an app where worms and viruses can infect and spread.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Sokartawi
Crazy Karma Chameleon
Posts: 805
Joined: 2004-01-08 09:17pm
Contact:

Post by Sokartawi »

Faram wrote:
Sokartawi wrote:So what? The only one that are infected by this are lamers, and the only ones harmed by it appear to be the lamers, possibly M$ (I read somewhere that it will launch a DOS attack against that too) and SCO. I won't shed any tears for those.
Great reasoning!

A computer is a tool and just because many don’t know how to maintain a computer and keep it and the applications on it updated we should call them lamers and assholes.

I mean everyone must have computer as their primary interest to use one otherwise they should stay out of your internet and bother you and your migty Haxx0r skills.

If you should blame anyone it’s Microsoft for writing an app where worms and viruses can infect and spread.
Oh but some are beyond the stage that they don't know how to use the PC, they don't WANT to know and they think they'll NEVER know, and yes I have had quite a few, since I work in a computer shop and also occasionally fix PCs, which I am going to stop doing BECAUSE of those lamers that keep on comming to the shop and calling me at home because of the most insane 'problems'. Let me give you a few:

A man bought a racing wheel. He came to us complaining he had plugged it in, and when he pressed the start button on the wheel, the computer didn't do anything.

Another lady came and said: "I cannot install the game, it wants me to put the next disk in the CD-ROM drive, but I only got a DVD-drive"

People trying to remove scratches from their CD's with toothpaste.

People emailing me if we were SELLING patches for the Atlantis game.
(I wouldn't be surprised if Microsoft introduces a monthly fee if you want to download patches)

We saying the person should download his latest videocard drivers. Him replying "Why doesn't it do that automatically?"
GRRR! It wouldn't surprise me if the next windows version actually DOES download the lastest drivers for everything automatically behind your back!

Giving a Windows 98 CD to someone because he cannot install certain software without it, the person puts it in the drive directly, it boots, and the person manages to completely reinstall Windows...

A certain person saying internet doesn't work, while it worked fine after I had installed it for him. Me getting fed up and not wanting to help this person. A week later you hear that despite you having told him and shown him twice, he didn't use the shortcut to connect to the internet first, and then proceed to open his mail or internet explorer.

A person on the phone INSISTING the app has to be installed from CD2 and when I say to her to put disk 1 in she gets angry and refuses to do so.

And of course idiots opening every damn attachment ending up in their mailbox.

It aren't just lamers, some of the people I have seen seem to be completely mentally retarded, not just in cases where it comes down to technology.

As for M$ writing vulnerable apps, you are right on that part, however I must say that a lot of the people writing malicous software just writes it for windows etc because it is the easiest target, and affects the largest group of people.
Stubborn as ever - Let's hope it pays off this time.
User avatar
Faram
Bastard Operator from Hell
Posts: 5270
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Oh but some are beyond the stage that they don't know how to use the PC, they don't WANT to know and they think they'll NEVER know, and yes I have had quite a few, since I work in a computer shop and also occasionally fix PCs, which I am going to stop doing BECAUSE of those lamers that keep on comming to the shop and calling me at home because of the most insane 'problems'. Let me give you a few:
I feel your pain, try working as a sysadmin for a midsized company...

But no one dars call me at home, I am a consultant and happely answes questions from home and bill them afterwars.

Last time somone did that I debited 10 000skr for 2h work on a Sunday answering question on howto install a game on his personal computer.
A man bought a racing wheel. He came to us complaining he had plugged it in, and when he pressed the start button on the wheel, the computer didn't do anything.
that's the PS2 sickness

Another lady came and said: "I cannot install the game, it wants me to put the next disk in the CD-ROM drive, but I only got a DVD-drive"
Pexplain to her that a DVD can read CD and if she looks dumbfolded just debit her for the work, easy gigs is hard to come buy nowdays.
People trying to remove scratches from their CD's with toothpaste.
:wtf:
People emailing me if we were SELLING patches for the Atlantis game.
(I wouldn't be surprised if Microsoft introduces a monthly fee if you want to download patches)
Burn it on a CD and sell the CD.
We saying the person should download his latest videocard drivers. Him replying "Why doesn't it do that automatically?"
Because he ain't correctly connected to da net. Show him da windowsupdate and the drivers tab, Happy customer and more cash for you.
GRRR! It wouldn't surprise me if the next windows version actually DOES download the lastest drivers for everything automatically behind your back!
They would not dare, then we could demand that if a patch breaks a system the are responsible, so this will not happen.
Giving a Windows 98 CD to someone because he cannot install certain software without it, the person puts it in the drive directly, it boots, and the person manages to completely reinstall Windows...
Dumb user he got what he deserves
A certain person saying internet doesn't work, while it worked fine after I had installed it for him. Me getting fed up and not wanting to help this person. A week later you hear that despite you having told him and shown him twice, he didn't use the shortcut to connect to the internet first, and then proceed to open his mail or internet explorer.
Use the dependancy in IE to auto dial if there is no network connections and bill him.
A person on the phone INSISTING the app has to be installed from CD2 and when I say to her to put disk 1 in she gets angry and refuses to do so.
Talk to him and in the middle of a scentance hang up the phone, he will think there is a line problem and redial, transfer him to -> nul
And of course idiots opening every damn attachment ending up in their mailbox.
Shoot them, mind some unpatched systems autoexecs attacthments. I love this reg hack:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail]
"ReadAsPlain"=dword:00000001


I force this on any user that don't update.
It aren't just lamers, some of the people I have seen seem to be completely mentally retarded, not just in cases where it comes down to technology.
Agree but I earn cash on them so I can't be to mad at them
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
Thunderfire
Jedi Master
Posts: 1063
Joined: 2002-08-13 04:52am

Post by Thunderfire »

Faram wrote:
I feel your pain, try working as a sysadmin for a midsized company...
It is a good thing that we mostly use Macs for internal work here. Many external workers have windows PCs and I have to tell some of them where the apple / start menu is...
Post Reply