07.28.2004. After the distribution yesterday of the new virus MyDoom.N,
which used the
major search engines to look for personal e-mail addresses to send itself
and affected the Google, Altavista, Lycos and Yahoo! services, a new worm
has appeared: Zindos.A,
This worms uses the effects of MyDoom.N in the computers. MyDoom.N downloads
a Trojan horse trough the TCP port 1034, and Zindos.A looks for this open
port in different IP addresses. If so, it introduces itself on the PC,
infecting it.
In the case the computer has an Internet connection, the virus is prepared
to launch and denial service attack (DoS) against Microsoft' web page
www.microsoft.com.
To execute itself every time Windows starts, this malicious code creates the
following registry entry:
Due to the possibility of being infected by Zindos.A, Panda Software advises
users to stay on their guard and make sure their antivirus is updated. The
company has already made the updates to its products available to its
clients to ensure their solutions can detect and eliminate Zindos.A.
Users can also scan and disinfect their computers using Panda ActiveScan,
the free, online scanner available from: www.pandasoftware.com. More
information about these and other IT threats is available from:
http://www.pandasoftware.com/virus_info/encyclopedia/