PRESS RELEASE
Oslo, 28 January 2004

Norman ASA announces a new variant on the MyDoom worm named MyDoom.B. The worm is at present time set to low risk by Norman. Norman advices all to download the latest definition files to protected themselves against this new threat.

This variant of MyDoom deletes the backdoor installed by the A variant and replaces it with a new backdoor file.

The main spreading function is by email but also propagates through Kazaa. The worm MyDoom.B searches through several types of files hunting for email addresses to send itself to.

The worm is still in analysis.

Detection and removal

This worm is detected by the Norman Sandbox technology as W32/P2Pworm.

A complete list of details is found on the Norman web site

For all users of Norman Virus Control or Norman Internet Control this worm is detected and removed using definition files from Jan 28th 2004 and newer.

For further information www.norman.com.


For further information, please contact

Arvid Gomes Product marketing, Norman ASA +47 415 39 790
Audun Lødemel VP marketing, Norman ASA, +47 934 46 531