喉咙里痰多是什么原因| 乳腺属于什么科室| 最里面的牙齿叫什么| 酸菜是什么菜做的| 和珅属什么生肖| 八面玲珑代表什么生肖| 黄精为什么要九蒸九晒| 杯葛是什么意思| 不打狂犬疫苗会有什么后果| db是什么单位| 看见壁虎是什么兆头| 牙龈起包是什么原因| fnc是什么意思| 党参不能和什么一起吃| 高考报名号是什么| 什么是血脂| 茉莉花什么时候开花| 生存是什么意思| 冬眠的动物有什么| 痔疮是什么科室看的| 慢性浅表性胃炎吃什么药好| 化石是什么| 天干指的是什么| 金银花洗澡对婴儿有什么好处| rot是什么意思| 黄体破裂有什么症状| 木薯是什么| 煮牛肉放什么容易烂| 马加大是什么字| 十月十七是什么星座| lpn什么意思| 薄情是什么意思| 益母草长什么样| 检查甲状腺挂什么科| 乳头痒用什么药| 咏柳的咏是什么意思| 机电一体化学什么| 红色连衣裙配什么鞋子好看| vivo手机是什么牌子| 夯实是什么意思| 什么地跑步| 无疾而终是什么意思| 用什么点豆腐最健康| 补肾壮阳吃什么| 血液属于什么组织| 周星驰是什么星座| 脸部肌肉跳动是什么原因| 女性更年期潮热出汗吃什么药| 什么是私人会所| 六月十一是什么星座| array是什么意思| 托塔李天王的塔叫什么| 女人喝胶原蛋白有什么好处| 新疆人为什么长得像外国人| 幽门螺旋杆菌什么意思| 破鞋是什么意思啊| 发烧什么症状| 女人肾虚吃什么| 法不传六耳什么意思| 涵字五行属什么| 姓许的女孩取什么名字好听| 昆明的别称是什么| 怎么判断自己什么脸型| 际遇是什么意思| 湿热内蕴是什么意思| 在家里做什么能赚钱| 阴道是什么| badus是什么牌子的手表| 大腿肌肉跳动是什么原因| 小孩子上户口需要什么证件| 公务员是做什么工作的| 阵容是什么意思| 牙齿痛用什么药| 羊奶有什么作用与功效| 6.19是什么日子| 赭石色是什么颜色| 啤酒兑什么饮料好喝| 脑疝是什么意思| blazer是什么意思啊| 我的手机是什么型号| 雨打棺材是什么征兆| 水代表什么数字| 应景是什么意思| 红色的海鱼是什么鱼| 乳房胀痛什么原因| 胸小是什么原因| 新生儿什么时候吃ad| 忉利天是什么意思| 鼻涕是绿色的是什么原因| 牙痛 吃什么药| 好哒是什么意思| 敛肺是什么意思| 朱砂是什么东西| 尿频是什么意思| 甲状腺是什么病啊| 诸多是什么意思| 羊水破了有什么感觉| 高血糖是什么原因引起的| 窦性心律左室高电压什么意思| 广州有什么区| 什么惊什么怪| 宫外孕是什么意思| 汇字五行属什么| 天神是什么意思| 什么叫伪娘| 左旋肉碱什么时候吃效果好| 娃娃鱼用什么呼吸| 杏和什么不能一起吃| 山茶花是什么颜色| 常喝蜂蜜水有什么好处和坏处| 两个a是什么牌子| 解脲支原体阳性是什么病| 屁股长痣代表什么| 弓山文念什么| 属虎和什么属相相冲| 感冒嗓子痒咳嗽吃什么药| 什么是肝炎| 纹身有什么讲究和忌讳| 喉结下面是什么部位| 夹腿是什么意思| 乌鸡炖什么好吃又有营养| 客源是什么意思| 长焦是什么意思| 去痛片又叫什么名| 邓超什么星座的| 长生殿讲的是什么故事| 玻璃体切除后对眼睛有什么影响| 肚脐右边疼是什么原因| 打三个喷嚏代表什么| 怀孕吃什么有营养| 1992年属什么生肖| 9月21号是什么日子| 心脏造影是什么| 52是什么意思| 一个雨一个亏念什么| 肚子胀疼是什么原因| 土是什么颜色| 梦代表什么生肖| 狂鸟读什么| 虚有其表的意思是什么| 什么是氧化剂| 尿隐血阳性是什么病| 网是什么结构的字| 今年是什么生肖| 开背鱼是什么鱼| 空腹喝啤酒有什么危害| 四个雷念什么| 马失前蹄下一句是什么| 甲片是什么| 什么是卵巢囊肿| 汗疱疹吃什么药| 跨界是什么意思| ais是什么意思| 尿毒症吃什么最好| 外阴溃烂用什么药| 火龙果和香蕉榨汁有什么功效| 浙江属于什么方向| 梦到蛇是什么预兆| 腰椎退行性变是什么病| 尿道炎什么症状| 深度水解奶粉是什么意思| 瞳字五行属什么| 霸王别姬是什么意思| 北京为什么是首都| 为什么一喝酒就头疼| atp是什么| 驳是什么动物| 月经期喝什么汤好| 做梦梦到蛇是什么征兆| 寓言故事有什么特点| 踩水是什么意思| 医院脱毛挂什么科| 心悸心慌吃什么药| gr什么意思| 什么是权力| 老佛爷是什么意思| 拜阿司匹林和阿司匹林有什么区别| ny什么牌子| seconds是什么意思| 手腕痛什么原因| 加号是什么意思| 什么是慢阻肺| 惟字五行属什么| 全身大面积湿疹暗示着什么| 行尸走肉什么意思| 桌游是什么| 工作坊是什么意思| 宝宝不吃奶是什么原因| 梦见抓蛇是什么预兆| 喝酒为什么会吐| 传度是什么意思| 什么车可以闯红灯| 乳果糖什么时候吃效果更佳| 拉肚子可以喝什么| 安利什么意思| 胯骨在什么位置| 苏州立夏吃什么| 肚子疼吃什么药| 梗米是什么米| 折什么时候读she| 肝硬化是什么症状| 双抗是什么药| fujixerox是什么牌子| 小孩吃鹅蛋有什么好处| 尿失禁是什么原因| 肾衰竭吃什么好| 鼻头长痘痘什么原因| 吃什么可以降低血糖| 很man是什么意思| 干咳喝什么止咳糖浆好| 纳氏囊肿是什么意思| bb霜和cc霜有什么区别| 脚出汗多是什么原因怎么办| 吃什么对肺最好| 四六级要带什么| 子宫肌瘤手术后吃什么好| t1w1高信号代表什么| 什么排球好| 为什么医生很少开阿斯美| 什么叫脑梗| 副处是什么级别| 梦魇什么意思| 君子兰什么时候开花| 腹水是什么| 扁桃体发炎是什么症状| lh是什么意思啊| 榴莲为什么这么贵| 蛋白高是什么原因| 什么的老师| 葡萄柚是什么水果| 嗓子上火吃什么药| 淋巴细胞比率低是什么意思| 白细胞高吃什么药| 什么黄河| 火镰是什么意思| 附睾炎吃什么药最有效| 牦牛角手串有什么作用| 月经推迟什么原因| 省略号的作用是什么| 什么是泡沫尿| 87年属什么| 红血丝用什么护肤品修复比较好| 双侧肾盂无分离是什么意思| 上睑下垂是什么原因造成的| 南京市市长什么级别| 梦见自己输液是什么意思| 曹操原名叫什么| 包皮过长是什么样的| 加码是什么意思| 双向情感障碍吃什么药| save是什么意思| 摩羯座女生和什么星座男生最配| 大队书记是什么级别| 总是感觉口渴是什么原因| 哦哦是什么意思| 后脖子出汗多是什么原因| 月支是什么意思| 胆结石有什么治疗方法| 子宫直肠窝积液是什么意思| 菊花泡茶有什么功效| uu什么意思| 来月经可以吃什么水果| 胰腺上长瘤意味着什么| 水泊梁山什么意思| 百度Jump to content

唯“美”的进化 试驾凯迪拉克XT5 28T四驱铂金版

From Wikipedia, the free encyclopedia
Mydoom
Example of a randomly generated file opened by Mydoom after execution
TypeComputer worm
Technical details
PlatformWindows 2000, Windows XP
Written inC++
Discontinued
  • 12 February 2004 (Mydoom.A)
  • 1 March 2004 (Mydoom.B)
百度 同时,工行的收单支付服务具有银行级安全保障,在支付过程中采用国际先进技术对支付个人卡号进行变异处理,隐藏真实卡号信息,确保客户交易安全和信息安全。

Mydoom was a computer worm that targeted computers running Microsoft Windows. It was first sighted on January 26, 2004. It became the fastest-spreading e-mail worm ever, exceeding previous records set by the Sobig worm and ILOVEYOU, a record which as of 2025 has yet to be surpassed.[1]

Mydoom appears to have been commissioned by e-mail spammers to send junk e-mail through infected computers.[2] The worm contains the text message "Andy; I'm just doing my job, nothing personal, sorry," leading many to believe that the worm's creator was paid. Early on, several security firms expressed their belief that the worm originated from a programmer in Russia. The actual author of the worm is unknown.

The worm appeared to be a poorly sent e-mail, and most people who originally were e-mailed the worm ignored it, thinking it was spam. However, it eventually spread to infect at least 500 thousand computers across the globe.[3]

Speculative early coverage held that the sole purpose of the worm was to perpetrate a distributed denial-of-service attack against SCO Group. 25 percent of Mydoom.A-infected hosts targeted SCO Group with a flood of traffic. Trade press conjecture, spurred on by SCO Group's own claims, held that this meant the worm was created by a Linux or open source supporter in retaliation for SCO Group's controversial legal actions and public statements against Linux. This theory was rejected immediately by security researchers. Since then, it has been likewise rejected by law enforcement agents investigating the virus, who attribute it to organized online crime gangs.

Mydoom was named by Craig Schmugar, an employee of computer security firm McAfee and one of the earliest discoverers of the worm. Schmugar chose the name after noticing the text "mydom" within a line of the program's code. He noted: "It was evident early on that this would be very big. I thought having 'doom' in the name would be appropriate."[4]

Technical overview

[edit]

Mydoom is primarily transmitted via e-mail, appearing as a transmission error, with subject lines including "Error", "Mail Delivery System", "Test" or "Mail Transaction Failed" in different languages, including English and French. The mail contains an attachment that, if executed, resends the worm to e-mail addresses found in local files such as a user's address book. It also copies itself to the "shared folder" of peer-to-peer file sharing application Kazaa in an attempt to spread that way.

Mydoom avoids targeting e-mail addresses at certain universities, such as Rutgers, MIT, Stanford and UC Berkeley, as well as certain companies such as Microsoft and Symantec. Some early reports claimed the worm avoids all .edu addresses, but this is not the case.

The original version, Mydoom.A, is described as carrying two payloads:

  • A backdoor on port 3127/tcp to allow remote control of the subverted PC (by putting its own SHIMGAPI.DLL file in the system32 directory and launching it as a child process of Windows Explorer); this is essentially the same backdoor used by Mimail.
  • A denial-of-service attack against the website of the controversial company SCO Group, timed to commence 1 February 2004. Many virus analysts doubted if this payload would actually function. Later testing suggests that it functions in only 25% of infected systems.[5]

A second version, Mydoom.B, as well as carrying the original payloads, also targets the Microsoft website and blocks access to Microsoft sites and popular online antivirus sites by modifying the hosts file, thus blocking virus removal tools or updates to antivirus software. The smaller number of copies of this version in circulation meant that Microsoft's servers suffered few ill effects.[6][7]

Timeline

[edit]
  • 26 January 2004: The Mydoom virus is first identified around 8am EST (1300 UTC), just before the beginning of the workday in North America. The earliest messages originate from Russia. For a period of a few hours mid-day, the worm's rapid spread slows overall internet performance by approximately ten percent and average web page load times by approximately fifty percent. Computer security companies report that Mydoom is responsible for approximately one in ten e-mail messages at this time.
Although Mydoom's Denial of Service (DoS) attack was scheduled to begin on 1 February 2004, SCO Group's website goes offline briefly in the hours after the worm is first released. It is unclear whether Mydoom was responsible for this. SCO Group claimed it was the target of several distributed denial of service attacks in 2003 that were unrelated to computer viruses.
  • 27 January 2004: SCO Group offers a US$250,000 reward for information leading to the arrest of the worm's creator. In the US, the FBI and the Secret Service begin investigations into the worm.
  • 28 January 2004: A second version of the worm is discovered two days after the initial attack. The first messages sent by Mydoom.B are identified at around 1400 UTC and also appear to originate from Russia. The new version includes the original denial of service attack against SCO Group and an identical attack aimed at Microsoft.com beginning on 3 February 2004; however, both attacks are suspected to be either broken, or non-functional decoy code intended to conceal the backdoor function of Mydoom. Mydoom.B also blocks access to the websites of over 60 computer security companies, as well as pop-up advertisements provided by DoubleClick and other online marketing companies.
The spread of Mydoom peaks; computer security companies report that Mydoom is responsible for roughly one in five e-mail messages at this time.
  • 29 January 2004: The spread of Mydoom begins to decline as bugs in Mydoom.B's code prevent it from spreading as rapidly as first anticipated. Microsoft offers US$250,000 reward for information leading to the arrest of the creator of Mydoom.B.
  • 1 February 2004: An estimated one million computers around the world infected with Mydoom begin the virus's massive distributed denial of service attack—the largest such attack to date. As 1 February arrives in East Asia and Australia, SCO removes www.sco.com from the DNS around 1700 UTC on 31 January. (There is as yet no independent confirmation of www.sco.com in fact suffering the planned DDOS.)
  • 3 February 2004: Mydoom.B's distributed denial of service attack on Microsoft begins, for which Microsoft prepares by offering a website which will not be affected by the worm, information.microsoft.com.[8] However, the impact of the attack remains minimal and www.microsoft.com remains functional. This is attributed to the comparatively low distribution of the Mydoom.B variant, the high load tolerance of Microsoft's web servers and precautions taken by the company. Some experts point out that the burden is less than that of Microsoft software updates and other such web-based services.
  • 9 February 2004: Doomjuice, a “parasitic” worm, begins spreading. This worm uses the backdoor left by Mydoom to spread. It does not attack non-infected computers. Its payload, akin to one of Mydoom.B's, is a denial-of-service attack against Microsoft.[9]
  • 12 February 2004: Mydoom.A is programmed to stop spreading. However, the backdoor remains open after this date.
  • 1 March 2004: Mydoom.B is programmed to stop spreading; as with Mydoom.A, the backdoor remains open.
  • 26 July 2004: A variant of Mydoom attacks Google, AltaVista and Lycos, completely stopping the function of the popular Google search engine for the larger portion of the workday, and creating noticeable slow-downs in the AltaVista and Lycos engines for hours.
  • 23 September 2004: Mydoom versions U, V, W and X appear, sparking worries that a new, more powerful Mydoom is being prepared.
  • 18 February 2005: Mydoom version AO appears.
  • July 2009: Mydoom resurfaces in the July 2009 cyber attacks affecting South Korea and the United States.[10]

See also

[edit]

References

[edit]
  1. ^ "Security firm: MyDoom worm fastest yet". CNN.com. Time Warner. 2025-08-06. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  2. ^ Tiernan Ray (2025-08-06). "E-mail viruses blamed as spam rises sharply". The Seattle Times. The Seattle Times Company. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  3. ^ "Mydoom threat still high;Microsoft offers reward". NBC News. 26 January 2004. Archived from the original on August 5, 2021. Retrieved 2025-08-06.
  4. ^ "More Doom?". Newsweek. Washington Post Company. 2025-08-06. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  5. ^ "[Review] MyDoom Virus: The Most Destructive & Fastest Email Worm". MiniTool. Retrieved 2025-08-06.
  6. ^ "Mydoom virus starts to fizzle out". BBC News. BBC. 2025-08-06. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  7. ^ "How to Thwart Renewed 'MyDoom' E-Mail Bug". ABC News. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  8. ^ "Microsoft Information: MyDoom (Wayback Archive from 4 Feb 2004)". microsoft.com. 2025-08-06. Archived from the original on February 4, 2004.
  9. ^ "W32.HLLW.Doomjuice". Symantec Corporation. 2025-08-06. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
  10. ^ "Lazy Hacker and Little Worm Set Off Cyberwar Frenzy". Wired News. 2025-08-06. Archived from the original on 2025-08-06. Retrieved 2025-08-06.
[edit]
为什么不能抠肚脐眼 周到是什么意思 甲亢是一种什么病严重吗 脾胃有火是什么症状 中性粒细胞偏高是什么原因
总梦到一个人说明什么 唇炎看什么科最好 嗣是什么意思 拍手腕中间有什么好处 喝枸杞子泡水有什么好处和坏处
羊水破了是什么感觉 黄晓明和杨颖什么时候结婚的 痤疮吃什么药 丙二醇是什么 r一谷氨酰转移酶高说明什么
amo是什么意思 巴旦木是什么 养神经的药是什么药最好 2001属什么 嘴上长痘痘是什么原因
气管炎的症状吃什么药好得快hcv9jop5ns3r.cn 腹泻期间宜吃什么食物hcv8jop4ns5r.cn 小ck是什么牌子hcv9jop6ns5r.cn 犯了痔疮为什么老放屁hanqikai.com 什么的香味hcv8jop7ns0r.cn
存在是什么hcv9jop4ns9r.cn 性交是什么感觉hcv9jop1ns0r.cn 6.15是什么星座hcv9jop5ns3r.cn 阿胶配什么吃不上火hcv8jop3ns9r.cn 血清铁蛋白低说明什么hcv8jop6ns1r.cn
人言轻微是什么意思hcv8jop3ns2r.cn 抚琴是什么意思hcv7jop7ns4r.cn 2027是什么年hcv8jop8ns4r.cn 为什么下雨后会出现彩虹travellingsim.com 高脂血症是什么病hcv7jop6ns3r.cn
吃饭咬到舌头什么原因hcv9jop0ns6r.cn 继发性高血压是什么意思hcv8jop5ns1r.cn 甲醛中毒吃什么药解毒hcv8jop9ns0r.cn 西柚不能和什么一起吃hcv8jop7ns6r.cn 鼠和什么属相相冲hcv8jop3ns5r.cn
百度