Mydoom-Virus
Ashwin HarishP
Red Teaming | Bug Hunter | Pentester | CTF Player | Researcher | IEEE Member | Full Stack Developer
Mydoom is a computer virus that's considered by many to be the worst virus in history thus far. In 2004, it cost around $38 billion worth of damage.
Introduction
Some people call MyDoom a virus. Some people call it a worm. Some people spell the term My Doom.?Others just call it the Doom Virus.?
No matter what you call it or how you spell it, MyDoom is serious. This tiny bit of code spreads from one computer to another via email attachments. If you get these messages and open their files, the program sits on your computer. Soon, everyone in your address book gets a message from your computer.?
People became aware of MyDoom in 2004, and the attacks launched then have long since passed. But plenty of infected computers remain. So it’s wise to know how this worm works and how you can rid your computer of the code.?
MyDoom virus development?
In January and February of 2004, people all around the globe started getting mysterious email messages that said, "I'm just doing my job, nothing personal, sorry." Each email came with an attachment, and every time people checked their inboxes, they got another copy. The MyDoom virus was responsible.?
MyDoom is a very effective worm made to create zombies out of hundreds of thousands of computers. Hackers could then use each hijacked terminal to wage a?denial of service (DoS) attack?toward a company they identified.?
In 2004, no one knew who developed the code. Some felt that the MyDoom worm looked?very similar to other worms?developed in Russian labs. But suspicion isn't proof, and in the end, no one really knew who created this code or why they did so.?
But experts agreed that MyDoom was dangerous.?Reporters said the code was:
?The virus took over host computers, and most cleanup reporting focused on what people needed to do to eliminate the code. But two companies were the real victims.?
The first version of the worm used infected computers to?bombard SCO Group?with homepage requests. The company couldn't handle that kind of traffic, and the site crashed. After an hour of constant attack, the company changed website addresses altogether.
The second version of the worm?did two things.
Before hackers released MyDoom, experts knew that an attack like this was possible. But they had no idea what it would look like, how it would work, or how users could clean up their computers. They would learn all about these attacks in the coming months.
领英推荐
How does MyDoom work??
People on infected computers likely had no idea anything was wrong. They may have encountered slow speeds or glitchy service. But they probably didn't get an alert or warning that their computers weren't functioning properly. But code working deep within the Windows environment allowed the worm to spread.?
The MyDoom worm:
Users should keep in mind that, while hackers made the worms to attack a specific website, the code doesn't expire or uninstall. Your computer could be infected now, or you could be working on a tainted machine from a message you don't even remember opening.?
Can the MyDoom virus hurt you??
Any computer infected with MyDoom has an open backchannel that, in theory, attackers could hijack. Suddenly, you could be part of a zombie attack.?
If your computer is part of an attack like this, you might notice:
You may notice nothing at all, of course. Your computer may never be part of a new attack on a company or country. But that backdoor is still there, just waiting for hackers to use it. It will continue to be a security risk unless you act.
MyDoom defense approaches?
If you believe that you have been infected by MyDoom, seek out the problem and remove it. Then turn to prevention to ensure you're never infected again.?
If you believe you are infected:
Worms like MyDoom rely on you to download the virus. That means you have opportunities for prevention. Start by?paying attention to sender addresses. If you get notes from people you don't recognize, don't open the message at all. And never click attachments in email messages that look suspicious.?
If you work on security for a large company, ensure that all of your employees know these same rules. Encourage them to send you anything they think is suspicious, so you can check it for them.