Latest MyDoom worm causing major havoc

podo

Well-Known Member
Joined
Apr 16, 2004
Messages
288
Reaction score
1
Location
South Africa.
This might be considered slightly off topic, but I feel I should warn you all anyway. The latest version of the MyDoom mail worm is causing serious problems around the world, including Google being unavailable for most of the day in some parts of the world.

The new virus searches victims' address books for e-mail domains, in other words, @example.com, and the uses search engines to search for any addresses it can find inside the domain. This has been causing havoc for big search engines, and excessive bandwidth wastage around the world, as the worm uses PCs to swamp search engines with requests. It appears, from early reports, that the worm will also crawl search engine results to harvest all addresses, not just to grab addresses from the first ten matches. Basically, the worm is turning victims' PCs in to Google-scale web crawlers.

Please be aware of this worm and watch all machines carefully. If performance on your machine or network, specifically internet speed, begins to suffer, or, if you have a modem with status LEDs and they are flashing out of controle, for no aparent reason, you may be a victim of the latest MyDoom attack already. Please try to update all virus scanning software, and be weary of e-mail from untrusted or unknown sources. Also, do not open a suspicious looking e-mail, even from a trusted source, delete it immediately.

I do not think it necessary to remind you all that Telkom will not be discounting virus related traffic from their bandwidth usage metering system, so any traffic used up by an infected PC will count against your cap. For the safety of all internet users and your bandwidth, please try your best to avoid this virus.

If your machine appears to be showing symptoms of MyDoom infection, please disconnect it from the ADSL network immediately. An ADSL connected system offers the worm great striking power and allows it to propagate quickly. An infected system on a broadband line is a serious danger to the internet. It might also be prudent to disconnect any infected machines from any other network connections, even local area networks, as any connection is an invitation for the worm to spread further and continue on with its destructive agenda.

Please do not try to use an infected system to download patches or virus updates. The downloads will slow to a crawl while the worm continues to abuse your system to spread itself and waste your bandwidth. Instead, try to find an uninfected machine where you can download a patch or fix, and transfer the fix to the infected machine. Please do not use a network connection to transfer any files, including fixes, to the infected system, this will give the worm the opportunity to spread through what ever network the system is connected to.

The full story is available from the ISC here:
http://isc.sans.org/diary.php?isc=d46940064182f61f40ca333bc3c2f439

Willie Viljoen
Web Developer

Adaptive Web Development
 
Top
Sign up to the MyBroadband newsletter
X