Unreal Ops Forum Index

Home FAQ Memberlist
 
View next topic
View previous topic
 Unreal Ops Forum Index » Unreal Ops News Comments
Author Message
Peoii
Ultimate Fanboy


Joined: 19 May 2003
Posts: 572
Location: Post Falls, ID, USA, North America, Earth, Sol, Milky Way

PostPosted: Tue Feb 10, 2004 1:37 am

Yup folks, it's time again for another round of the beloved MyDoom virus, now in it's .C variation, this one doesn't even require Outlook or Outlook Express to transmit itself! To quote from the Eweek article which covers the release:
When it's executed, the new variant, called MyDoom.C, or Doomjuice, begins scanning for machines listening on TCP port 3127. When it finds available PCs, it copies itself to the new machine's Windows directory under the file name "intrenat.exe" and also creates a file named "sync-src-1.00.tbz" in several locations.

But unlike the two previous versions of MyDoom, this third variant does not spread via e-mail, nor does it install a backdoor on infected machines or have a kill date, according to an analysis done by Ken Dunham, malicious code manager for iDefense Inc., based in Reston, Va. The worm's code is not encrypted, but it contains all of the source code for MyDoom.A.Fun fun fun, time to update those virus definitions and bring up those firewalls people. Gosh it's a great time to be on the Internet.
alpha2003
The Underworld God of Spamming


Joined: 07 Dec 2003
Posts: 748
Location: USA

PostPosted: Tue Feb 10, 2004 1:51 am

dear god not another varitation. Good post peoii Wink
Guest






PostPosted: Tue Feb 10, 2004 2:42 am

It only can infect machines that are already infected with MyDoom.
Not too scarry.
Guest






PostPosted: Tue Feb 10, 2004 3:36 am

Or that run Windows. Break out the Linux or Mac version of UT, kids! Wink
Lalli-Oni
UO Staff


Joined: 21 May 2003
Posts: 767
Location: A small island in the middle of the Atlantic ocean...

PostPosted: Tue Feb 10, 2004 4:05 am

does it do much harm? doesn't it just use your machine to attack Microsoft? or am I just hallucinating?

_________________
"The cow is you." -David Grohl
barbos
Ultimate Fanboy


Joined: 18 May 2003
Posts: 508

PostPosted: Tue Feb 10, 2004 8:30 am

Mydoom.a doesn't necessarily need Outlook or Outlook Express. It has the capabilities of using it's own SMTP engine. I've also noticed that it doesn't need an address book to feed it. It will scan your temporary internet files, and make up addresses, such as dave@unrealops.com.

And since people don't clear their internet files, nor protect their machines, anyone with a catch-all address to a popular domain will get blasted away with emails.
Gandalf
Guest





PostPosted: Tue Feb 10, 2004 8:48 am

internat.exe is also a "normal" file http://www.liutilities.com/products/wintaskspro/processlibrary/internat/
Guest






PostPosted: Tue Feb 10, 2004 8:58 am

Anonymous wrote:
Or that run Windows. Break out the Linux or Mac version of UT, kids! Wink


Windows really has nothing to do with it... it's more about people's stupid ablity to open executeable files and run them without any idea what they are doing. Heavy user intervention is required.

Linux or Mac has simply the same fault. If I send you a bogus executeable and you run it, who knows what it is going to do!
Gandalf
Guest





PostPosted: Tue Feb 10, 2004 10:15 am

Nope, this is a windows only thing, that only infects Windows PC's that already have the myDoom virus. It launches DoS attacks on microsoft.com, which may be why my MSN messenger wouldn't log on yesterday night Sad

http://news.bbc.co.uk/1/hi/technology/3475235.stm
Raven
UO Staff


Joined: 19 May 2003
Posts: 2235
Location: Clyde, Ohio

PostPosted: Tue Feb 10, 2004 10:17 am

i wonder if that's the culprit for all the messages that i have been getting in my inbox titled "hi" and "hello".....

i hope not even tho i delete all those messages before i read them because i dont know who they are (and because they have an EXE as an attachment, eventho it says it's a unicode attachment)

_________________
nevaR ask Raven
Because he nevaR knows!
Http://www.guardiansofdeath.com
Lalli-Oni
UO Staff


Joined: 21 May 2003
Posts: 767
Location: A small island in the middle of the Atlantic ocean...

PostPosted: Tue Feb 10, 2004 9:25 pm

I would be glad to have the wirus if it only attacks Microsoft

_________________
"The cow is you." -David Grohl
zenmaster
Crazed Fan


Joined: 17 Aug 2003
Posts: 282
Location: Wilmingtion, 1 1/2 hours from Epics office

PostPosted: Tue Feb 10, 2004 9:49 pm

Lalli-Oni wrote:
I would be glad to have the wirus if it only attacks Microsoft


Twisted Evil Cool A bit of voiced detest Wink I'm botherd they don't have a simple way to remove it yet; at leas that I know about.

Zen

_________________
When the enlightend is asked were he will go when he dies his reply is to hell for that is were the most help is needed. Ego complex?
Display posts from previous:   

View next topic
View previous topic


 

Powered by phpBB © 2001, 2005 phpBB Group :: Theme zoneCopper designed by yassineb.