main

Mydoom.M giving ISP's a headache

Steven Parker   on 29 July 2004 - 11:33 · 10 comments & 477 views

Advertisement (Why?)
I just got an ISP wide alert from my Internet Provider Planet Internet who are obviously concerned about a new outbreak of the MyDoom worm, MyDoom.M

A new variant of MyDoom, MyDoom.M is currently spreading fast through users systems using the typical mailworm behavior by searching (Google, Lycos, Yahoo en Altavista) for e-mail adresses of possible victims. The mails are then sent using a fake email address with an attachment. The most popular used subjects are: ´error´, ´Message could not be delivered´ and ´Mail System Error - Returned Mail´. As always you shouldn't open attachments unless you know who sent it and you can verify the file type.

We recommend members to download the removal tool from Symantec (if only to check if the infection is already present).

Download: MyDoom Removable Tool (multiple variants)
View: MyDoom.M Alert @ Planet.nl (Dutch)
News source: In-House


Cont...

Additionally, McNealy said, "We believe that SNE is preparing now for the production of its next-generation of products, from the Sony PlayStation Portable to the next-generation PlayStation console and other consumer electronics devices that will be based on its cell processor."

Suggesting such a ramp-up was one of the reasons the game division earnings had slumped, Katsumi Ihara, group chief financial officer for Sony, reportedly said at a Tokyo news conference. "For the PSP and the next-generation entertainment system we continue to have a high level of investment which is bringing down profit."

Sony's net sales for the quarter were flat at 1.6 trillion yen ($14.8 billion), up just 0.5 percent from the previous year, and operating income was 9.8 billion yen ($87.7 million), down from 16.7 billion yen ($149 million) a year earlier.

Post a comment · Send to friend Comments · There are 10 additional comments
(3 replies) #1 spampalupdate on 29 Jul 2004 - 11:40
.. You can also download Stinger to remove it: http://vil.nai.com/vil/averttools.asp
.. If it's an unknown file, try this *single file* virus checker: http://virusscan.jotti.dhs.org/
#1.1 sard on 29 Jul 2004 - 11:50
Cool site http://virusscan.jotti.dhs.org/ similar to Virus Total.


virusscan.jotti.dhs.org publish the detection rate though which is very interesting. I wonder why McAfee asked for their scanner to be removed.

Last edited by 53238 on 29 Jul 2004 - 11:58
#1.2 spampalupdate on 29 Jul 2004 - 12:02
That virus total site is good too... I know that AV vendors do take virus samples from Jotti's site,
which is great for use in ClamWin (http://www.clamwin.net/) eg. search for Jotti in the updates database:
http://news.gmane.org/gmane.comp.security.virus.clamav.virusdb
#1.3 rogerroger on 29 Jul 2004 - 17:09
Looks like the reason McAfee asked to be removed was that Jotti was posting detection ratios and McAfee's product was not one of the greatest. I bet they didn't want the negative publicity. What a bunch of cowards!
#2 Robinski on 29 Jul 2004 - 12:19
Got the same eMail here.. good luck I updated the virusscan of the mailserver just before that
(2 replies) #3 Colonel_Angus on 29 Jul 2004 - 12:19
If my pr0n download speeds slow due to traffic from this virus, I'm personally kicking a random windows user in the nuts.
#3.1 MoRiA on 29 Jul 2004 - 12:39
.... Or you can just kick one of the random n00bs in the nuts? Not all Windows users are insecure morons, y'know....
#3.2 OptiPlex on 29 Jul 2004 - 21:47
He's just a stupid Linux fanboy trying to act cool. Ignore all his n00b comments.
#4 mrk on 29 Jul 2004 - 13:04
I used to keep getting spam in my isp's mail inbox with viruses et so today I decided enough was enough, I added an extra character to my email username and as I use my domain name for my email just changed the redirect to the new username :p - bam! no more spam to te old username
#5 StaticX on 29 Jul 2004 - 13:35

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)