After 7 Years, MyDoom Worm Is Still Spreading
An anonymous reader writes "Researchers at Sophos have revealed that the MyDoom worm, which spread via email and launched denial-of-service attacks against websites belonging to SCO and Microsoft, is still spreading on the internet after more than seven years in existence. The firm suggests, tongue-in-cheek, that it would be nice if computer users updated their anti-virus software at least once every 5 years to combat the malware threat."
Hello dear christian friend,
In the year of 2004 it is with great pleasure that I leave to you the sum ...
But if you got a MyDoom message in any modern software you'd get tons of warnings, and many e-mail programs would strip the attached executable as a matter of policy.
Maybe people should have to register their PC before they connect it to the Internet?? Maybe people should have to get a license to use a PC on the Internet? It might reduce the carnage on our roads ^H^H^H^H^H^H^ Internet....
search engines. use them.
Sure it's not XP mode?
I don't run antivirus software in the VM because the VM almost is never up, but I wonder about people using it for significant amounts of time on a non-firewalled system. XP versions before SP1 would get root'd by simply having internet access.
The only thing that comes to mind is 'PEBKAC'.
Is this really any surprise to anyone? People still believe that Bill Gates is going to pay you for forwarding email. Most attacks (malware, trojans, viruses, etc.) feed on the ignorance of the average person. It's sad really, but I don't expect anything different 27 years later, much less 7.
I hear from users and fanboys that Win7 is much more hardened than say WinXP
So my question is does this old virus still run on Win7?
If you actively run it and give it permission, yes. Since you mention fanboys, the Mac variety always claim malware doesn't count if users have to do that. Compared to XP it helps that Win7 have UAC, but the best defense against PEBKAC malware like this is running antimalware software like Security Essentials, which you also can do on XP.
If you really were interested, there is a lot of information out there about the security differences between XP and Windows 7, they are quite extensive (ASLR, DEP, UAC, improved firewall (with multiple active profiles), Windows Service Hardening, Protected Mode browser, etc.)
Or alternatively, not have a virus checker at all as it slows down PCs, and misdiagnoses all the time (I don't need it deleting files which I know are NOT a problem).
Just be careful what sites you visit, do backups (using SyncBack of course) and a system restore will usually solve minor problems.
Why OpalCalc is the best Windows calc
If you really want to get people to run virus scanners (without making the scanner a virus itself) you'll have to make it beneficial to the individual. Create some really fun game and buried in the EULA mention that the program does a virus sweep each time it launches.
Either that or fight fire with fire.
No sig for you. YOU GET NO SIG!
About the users :)
"The likes of Facebook and WhatsApp are free to those whose privacy is of zero value."
Now this is a ridiculous description: "infected computers as part of a civil war between different factions of the Linux community."
"It is our choices, Harry, that show what we truly are, far more than our abilities." -- Prof. Dumbledore
If you are a multi million dollar company you can afford to upgrade from IE6, and if you are a computer novice who keeps getting viruses you need to either learn or if like this case you should get your brain examined.
Any malware that gets executed by the user and granted privileges runs on any system that the executable format it is in can run on. That's true for Windows 95, Windows 7, MacOS of any version and Linux of any flavor.
No system can defend against the stupidity of its owner. Unless the system is actually "protected" from its owner. For further reading, look up DRM and TCPA.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Why should the average Joe care if a virus creates a DoS attack on Microsoft or SCO? all that he cares about (and he is right to do) is if his computer does the job he wants. If it is too slow, he can always service it or buy a new one.
Instead of blaming the people actually responsible for the mess (i.e. the developers of the virus or of the operating system that let this happen), it is the users that are blamed? WTF?
" that haven't been updated for nigh-on a decade." - by pandrijeczko (588093) on Saturday June 18, @08:02AM (#36484458)
That doesn't help either on what you note, but, staying on that track/line-of-thinking?
Well, I've read online that for instance, the communist block (think China, Russia, etc.) has TONS of illegal copies of Windows XP in use, AND going around for "sale".
Not good!
Most especially in regards to what you are alluding to in your post I have replied to now.
I.E.-> You can't update stolen/illegal copies of Windows XP via Windows Update! At least not typically & "automagically" via Windows update...
So, they're most likely sooner or later going to become "malware nests" as well - which IS exactly what I call them here personally!
Bit "off track" here but trying to make another point on ignorance of end-users (which is excusable, as nobody is "all-knowing", plus, they are expert in other things, & in this case medical know-how)
E.G.-> A pal of mine's a security guard/PI - he works a large complex where young doctors & interns live nearby a local hospital where they work.
Sometimes when he's on duty, I go & hang out w/ he (lots of idle time in those jobs until he does rounds or documentation) & play chess when I have time.
There, doing his rounds, He finds computers that these often fairly wealthy folks just "toss out" to the dumpster area, & guess what?
THEY ARE LOADED with malware, & I mean way, Way, WAY LOADED...
Case-in-point example: Once on 1 system we salvaged for my buddy to use - upon testing it, I think I sent enough infestation samples to ESET (via NOD32) that must have made their signatures table WAY more effective & off of only 1 system we found!
(Once cleaned, that system was perfectly FINE too, no less, but just so "lagged" by malware, it would take 10 minutes for it just to boot up).
APK
P.S.=> So, imo @ least? The worst part of the equation, & this holds true on ANY Operating System platform, are the users that don't give a hoot, or are just ignorant, of how to keep safe online & also to secure their computers beyond the default!
Personally, were I Microsoft (or really, ANY OS maker)?
FIRST - I'd ship the system TOTALLY "security-hardened" & I don't mean "playing around" Firewall + AntiVirus reactive technology hardened only! Odd part here is, that MS does make such a build, for the U.S. Military & has for almost a decade now in fact.
SECOND - I'd also ship it 'shut down' on a LOT of things in it initially: By that, I mean anything (think services, disk/file shares, & remote access possible apps onboard etc.) that could potentially be a vector for infestation...
Then, the user themselves would have to "open the doors" themselves. When they do, & start trying to?? A help message would pop up & have SOLID as easily understood as possible explanations of what the thing does they are opening up/enabling AND MORE IMPORTANTLY, potential downsides (& how to avoid them).
This also would put MORE of the liability ONTO THE USER, and give them a "schooling" @ the same time!
(Especially the irresponsible OR ignorant/uninformed users that keep this stuff on their systems for years-to-decades & keep getting more as well)
That also would take some the "heat" off the OS vendor also, to an extent, as well!
Just a thought.
... apk
the computer user runs untrusted code that was sent to them by strangers
Then how should code become trusted?
Often times they "have to install this special video codec to watch [insert celebrity name here] boobs". Not only do they install this "codec", they give it admin rights.
As I understand it, codec installers require the user to elevate because operating systems' multimedia frameworks offer no easy way to install a codec to a single user's account. Instead, codecs must be installed to the system for all users.
the 3 applications they use (internet, mail, some word processor) [...] require at best 10% of the CPU's capacity.
If by "internet" you mean the web, then I've seen sites using Adobe Flash or HTML5 new features use far more than 10% of a core.
Which IS what most "ignorant/unaware" OR uncaring end-users utilize typically, because they are NOT aware of anything else & typically want - "automagically done for they" (or again, just don't care)...
Now, THAT was my point!
Perhaps you missed "catching my drift" is all!
(OR perhaps I did not express myself as well as I should have & was not clear enough on that - even though my posts are VERBOSE as all "get out" admittedly, & that's why: To make points, via details & examples, usually)...
Per this:
"Security updates work fine, even if the copy of XP is pirated." - by jmottram08 (1886654) on Saturday June 18, @12:03PM (#36485614)
If applied manually... grabbing them from say, here:
http://www.microsoft.com/technet/security/bulletin/ms11-jun.mspx
Each "Patch Tuesday"...
In that case? Yes, I may agree. Otherwise, & per MY point (which I don't think you got)?? Well... there you are.
APK
P.S.=>
" Either way, anti wirus / malware software is free." - by jmottram08 (1886654) on Saturday June 18, @12:03PM (#36485614)
Agreed, & thank goodness (alongside firewall tech as well), but... it's REACTIVE TECHNOLOGY (mostly, unless you consider heuristics "best guess" tech (ala "smells like a duck, tastes like a duck - it must be a duck") but, that opens up the possibility of FALSE POSITIVES).
Which is why I put in the part I did in my "p.s." in my last post... super-harden the OS by default, ship with anything that can be accessed remotely off by default also!
I think THAT would do a hell of a job for end-users education, security, AND for OS vendors also!
... apk
2004? Pfft. My IDS is still showing probes from the Blaster Worm, that was 2003.
Poor means hoping the toothache goes away.
I think some ppl should make a mimic my doom virus that simple informs the ppl
they need to patch and until then their tcp/ip files have been removed.
Gets them off the network and educates them.
google "32 trillion offshore needs IRS attention"
Update once every 5 years. Got it. Cheers.
This virus has accomplished what no one else has managed on the Windows Platform. Backward Compatibility. 7 years and running!
Just create a modified MyDoom to format the machines after one month of being infected, you will find less machines getting infected after that.
I think some ppl should make a mimic my doom virus that simple informs the ppl they need to patch and until then their tcp/ip files have been removed.
Gets them off the network and educates them.
I think most users would find it hard to patch their system if they no longer have network access to do it.