Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

So I got the MyDoom virus today, my story of agony and success

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:10 PM
Original message
So I got the MyDoom virus today, my story of agony and success
Edited on Tue Feb-24-04 09:33 PM by sgr2
EDIT: BTW, it doesn't just spread with outlook, it also bulk emails itself with Yahoo, MSN, and AOL (If they are open).

My boss got it, and her Outlook sent me a copy of it entitled "Important Document". Since it was from my boss I opened it, big mistake. Almost immediately I knew something was wrong when two things happened:

I got 20 emails labled "Undeliverable" to addresses I never emailed to.

Folders 35kb in size and named randomly like "sfdsfsf" or "cducyud" (Looking like compressed zipped folders) began appearing EVERYWHERE on my computer.

So I pulled up Norton antivirus and did an update. It started going nuts saying found "W32.Mydoom.F@mm". But as soon as it finds them they reappear. Basically what it does is place a script file in your system folder. That file begins rapidly multiplying itself and copying into every folder it can find. When the script appears in a new folder, it runs and finds as many files with certain extensions (.doc, .jpg, .xls, .exe) and tries to delete them.

Luckilly I found the following site:
http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom.f@mm.html

Downloaded the "REMOVAL TOOL" and followed the instructions. 45 minutes later that bastard virus was dead. That thing multiplied 6000 times in 5 hours. I say they give these hacker virus people life in prison.

NOTE: I ran the removal tool twice, second time it found nothing.
Printer Friendly | Permalink |  | Top
revolve Donating Member (255 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:15 PM
Response to Original message
1. So you were inconvenienced for 45 minutes
but they should spend the rest of their lives in jail?
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:18 PM
Response to Reply #1
2. No, I Iost six hours of work time
Edited on Tue Feb-24-04 09:19 PM by sgr2
That 45 minutes was how long the removal program took. And it deleted about 30 work files and somewhere around 200 pictures. So add that time in. Multiply that by the thousands of people who get the virus and calculate the damage.

Lock em up. For a long long time. It's no different than someone coming into my work and holding us hostage. For no reason other than to wreack havoc I might add.
Printer Friendly | Permalink |  | Top
 
revolve Donating Member (255 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:28 PM
Response to Reply #2
4. Its a lot different than someone holding you hostage
No one forced you to open that email, no one forced you to use outlook, the only program its transmitted through.

I feel bad that you lost some files, but don't try and make it into something bigger than it was.
Printer Friendly | Permalink |  | Top
 
SOteric Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:30 PM
Response to Reply #4
7. I think his assessment is reasonable
and that perhaps you're trying to make it seem like it couldn't possibly be much of a threat. I'd say your perspective needs a little work.
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:31 PM
Response to Reply #4
8. No one forced the programmer of the virus
To cost millions in damage and lost time. Lock him/her up. I do not have ANY pity for cyber terrorists.
Printer Friendly | Permalink |  | Top
 
SharonAnn Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 11:23 PM
Response to Reply #8
21. Right. I'm with you - these people cause lots of damage and
cost lots of money.

Lock him up! (I'm pretty sure it's not a her).
Printer Friendly | Permalink |  | Top
 
Mrs. Venation Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 11:39 PM
Response to Reply #4
22. Wrong!
I don't use Outlook; I use Netscape, and my PC got infected with the mydoom virus. It took a couple of days and several disk scans to get rid of all the iterations of the darn thing.

People who write malicious programs intend to do harm, and I think they should be severely penalized, including fines and jail time.
Printer Friendly | Permalink |  | Top
 
SOteric Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:29 PM
Response to Reply #1
5. Given the extraordinary damage such programs effect worldwide
I don't think that sounds unreasonable. Millions of dollars in damage are evoked in countless business, sometimes lives are lost. We had a case here about 6 months ago where a trojan shut down a hospital computer network and patient charts and histories were unavailable. A programmer who unleashes such unleashes such a distructive script has no idea who and what will be affected. Emergency services are not exempt from malicious scripts.
Printer Friendly | Permalink |  | Top
 
revolve Donating Member (255 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:35 PM
Response to Reply #5
9. I understand it can cause harm
and then they should be prosecuted for that harm, but to lock someone up for life because they caused you six hours of inconvenience is ridiculous and shows how conceited you are if you think your time is worth that much more than the other persons.
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:38 PM
Response to Reply #9
10. I don't think you get it
I'm not the only one getting affected. Thousands of other individuals and companies are also getting it to. It might have only caused me 6 hours, but add the files I have to redo and that becomes aboout 30-40. Multiply that by the thousands. Millions possibly billions in lost productivity.

That's STEALING and cyber-terrorism. Lock them up. Throw away the key.
Printer Friendly | Permalink |  | Top
 
revolve Donating Member (255 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:40 PM
Response to Reply #10
11. Those damn terrorists
causing you to lose your money, for shame for shame.

Well since you say it should be done, who am I to argue.

Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:43 PM
Response to Reply #11
12. If someone comes into your work and sledgehammers your comp
Is that ok? Because there is no difference. You may be pro-virus, but I suggest you'll change your tune when you're old enough to work.
Printer Friendly | Permalink |  | Top
 
Name removed Donating Member (0 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:48 PM
Response to Reply #12
15. Deleted message
Message removed by moderator. Click here to review the message board rules.
 
Name removed Donating Member (0 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:49 PM
Response to Reply #15
16. Deleted message
Message removed by moderator. Click here to review the message board rules.
 
SOteric Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:51 PM
Response to Reply #9
17. I'm not sure how you got such a conclusion from his statements..
Looks to me like he made a statement about his inconvenience. And then made a statement about how the writers of malicious code should be treated.

It requires a leap to judgement to assume that he meant those punishments specifically and only because he was personally inconvenienced.
Printer Friendly | Permalink |  | Top
 
Name removed Donating Member (0 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:54 PM
Response to Reply #17
18. Deleted message
Message removed by moderator. Click here to review the message board rules.
 
silverlib Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:22 PM
Response to Original message
3. Thank you!
I got it last night. I have McAfee and it caught one file and suggested I run a full new check. I did, and three more files were infected.

I ran it again later, and I guess two more were infected before the scan was complete.

I'll go to the link and hopefully be done with this thing!

Thank you soooooo much!
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:29 PM
Response to Reply #3
6. Click the removal tool in the middle of the page
Edited on Tue Feb-24-04 09:32 PM by sgr2
Scroll down and find the .exe program for the tool.

Dowload it and follow the directions!

DISABLE system restore by clicking "SYSTEM" in control panel, clicking system restore tab, then click the little button that says disable for drives.

Ok, now UNPLUG your internet connection and run the program. Should take a while but it will be fixed. You will lose some files.

Any questions don't email me! PM me. hehe
Printer Friendly | Permalink |  | Top
 
SiriusLiberal Donating Member (67 posts) Send PM | Profile | Ignore Tue Feb-24-04 09:44 PM
Response to Original message
13. Thank You
Thanks. The link was quite useful.
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 09:46 PM
Response to Reply #13
14. No problem
I searched for that bugger for hours. :-)
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 10:12 PM
Response to Original message
19. Kicked for prosperity
Knowledge!
Printer Friendly | Permalink |  | Top
 
ShaneGR Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Feb-24-04 11:16 PM
Response to Reply #19
20. Judo!
Chop!
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue Apr 16th 2024, 03:04 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC