The computer virus which affected Google and other search engines is on the wane, say net security experts. But they warn that net users should be on the lookout for a new variant of the worm appearing in the next few days. The MyDoom.O virus spread quickly on Monday, causing some outages on Google, as well as a slight slowdown in internet traffic. It used a sneaky new technique to spread itself, scanning search engines for additional e-mail addresses. Virus evolution The MyDoom.O variant spreads in the form of an e-mail attachment. The attached message pretended to be from the user's net provider's or company's support team saying that their PC has been used by hackers to send spam. It first emerged early on Monday and quickly spread. By Tuesday afternoon, e-mail filtering firm MessageLabs said it had intercepted almost 600,000 copies of the virus. The latest version marked a worrying evolution of the MyDoom worm that infected hundreds of thousands of computers earlier this year. This latest variant, MyDoom.O, not only scanned infected machines for e-mail addresses, but it also used search engines to look for even more addresses. Google, as well as Lycos, AltaVista and Yahoo were bombarded with requests until they could not cope. "This virus has introduced a new technique in e-mail propagation, in this case using search engines," said Jack Clark, McAfee anti-virus expert. "You had potentially ten of thousands of machines, each generating tens of thousands of request to Google. That would be enough to bring Google to its knees," he told BBC News Online. The worms affects Windows systems but not Linux or Apple Mac computers. 'Warhol effect' In a statement, Google confirmed it had been flooded with automated searches generated by the MyDoom virus. But it said only a small number of users and networks had been affected and that the Google website was not "significantly impaired." MyDoom now appears to be subsiding, with Google and other search engines working as normal. "We can expect to see a massive slowdown," said Mr Clark. "You have this Warhol effect. "A virus is famous for 15 minutes, or in this case for 15 hours, and then there is a big drop off the next day as people update their anti-virus software." But he added that it was almost certain that more versions of the virus would appear in the coming days, incorporating the new technique used by MyDoom.O.
thanks a ton for this update shabbir .... on an update you can download the tool that finds and removes the virus users download from http://securityresponse.symantec.com/avcenter/FxMydoom.exe. or from http://vil.nai.com/vil/stinger. vishal sharma
this virus is easy decomissioned... once the main source varibles are maxed out this ones bust... thats why trogans for there time were the best. only scary part is when a sicko out there will add a deltree c:\ code in there LOL x,x or a temp flux disrupter... can anyone say meltdown x.x
well friend, The argument is based on the principle that blacklists of signatures?small files that contain a unique string of bits, or the binary pattern, that identifies all or part of a virus?do not, and cannot, provide adequate protection against viruses. This is because the signature files can only be written once a virus or other form of malicious software program has been identified. When a new malware program is discovered, the race is on to write a signature file for protecting against that virus. It's like putting a plaster on an open wound, rather than taking care not to get cut in the first place.?