BleepingComputer.com: New MyDoom variant

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New MyDoom variant

#1 User is offline   raw 

  • Bleeping Hacker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,299
  • Joined: 14-April 04
  • Gender:Male
  • Location:Texas

Posted 04 August 2004 - 07:17 PM

Quote

The SANS Institute reports a new variant of MyDoom in the wild actually not recognized
by AV vendors:

New MyDoom On The Loose

Initial analysis (we will update as we know more):

Currently (16:00GMT), signatures are not yet available.
UPDATED (17:00GMT):
- Signatures are starting to come out, identifying this as MyDoom.O, MyDoom.P or Evaman.C
- It appears that this may only work on Win2K and WinXP machines because the executable
requires psapi.dll.
- Copies itself to the Windows' system directory as winlibs.exe and installs itself
under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


http://www.securityfocus.com/archive/1/370...01/2004-08-07/0

Quote

Targets Yahoo's people search:

http://email.people.yahoo.com:80/py/psSearch.py?

Posted Image
Posted ImageHOSTFix only works on XP,no longer maintained

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users