Getting your Trinity Audio player ready...

The media barrage over the MyDoom worm attack pretty much glossed over something hugely important: This worm displayed programming expertise and cunning strategies far more dangerous than ever before exhibited by hackers.

All that grief lurks in a package about half the size of the 42-kilobyte Microsoft Word file this column occupies on my laptop. The terrorists behind MyDoom sent the Internet worm burrowing into the heart of the digital economy by unleashing a masterfully composed computer file of just 22.5 kilobytes.

Already MyDoom, also known as Novarg and Worm MiMail, has cost businesses well above $2 billion, turned a great many corporate and home e-mail inboxes into gibberish and created near panic about what is yet to come. Virus experts decompiled the hackers’ code and found that the e-mail bomb part of MyDoom was the first of a two-punch attack. The sucker punch will attempt to use the uncounted thousands of “zombie” machines corrupted in the e-mail bomb phase to flood the Web site of a controversial Utah company, SCO Group, starting Sunday, and Microsoft a bit later.

MyDoom’s malicious code already constitutes the most effective e-mail attack in history, and it may not be over. Computer managers have had nearly 4 days to prepare for that telegraphed second punch.

If the good guys don’t stop it then, there is good reason to fret over Internet technology’s future.

Even if the second wave gets thwarted, a study of the plumbing behind this nasty worm shows that computer terrorists have acquired dangerous expertise that puts them on a par with terrorists with guns and bombs in terms of their potential threat.

In a world where money itself has become digital files on computer networks instead of cash in vaults, hacking at the level displayed by MyDoom chills to the bones.

Like a guided missile with multiple warheads, MyDoom’s sophisticated payload starts with the obvious module that generates e-mails with a large number of different and dissimilar subject lines and body text to goad a recipient into making the mistake of opening the attachment that will launch the worm onto another batch of targets.

Using random-number generators and a list of potential disguises and names drawn from each victim’s own address book, the software composes a flurry of different bogus messages.

Some of the messages, for example, are drafted to be nearly identical to the commonplace “System Administrator” messages that e-mail users get daily reporting lost messages.

One of the most effective MyDoom formats claims to be from the company IT department or Internet service provider saying that an important message arrived only partially intact and telling the user the attached file is all that was salvageable.

Since the sender’s name comes from the address book of a friend or associate that was sucked dry by an earlier iteration of the worm, many people fell for other strategies also in MyDoom code.

Other booby-trapped attachments look like screen savers and Web pages sent by friends. Another ploy makes the bomb look like compressed Zip files that used to be a way to avoid malicious programming.

Another of the multiple warheads is a subroutine that writes contaminated files called dynamic link libraries, or DLLs, onto the hard drive and then tricks the computer into running those bits of software to further the chaos by opening back doors to future attack.

This is accomplished by creating a program called taskmon.exe that is a virtual copy of a valid file in Windows 98 and ME. The bogus taskmon.exe goes into a different folder in the Windows directory than the real taskmon.exe. This tactic makes attempting to remove the worm by hand something akin to a bomb squad’s decision about whether to cut the red wire or the blue one.

The false taskmon.exe file gets run by writing sophisticated changes into the Windows system registry, a master list of settings and commands that govern how a computer acts.

MyDoom’s code also includes its own e-mail subprogram called SMTP that handles sending copies of the worm to other targets. Past worms tried to use the host’s own SMTP and were easily detected.

Each compromised computer is left with an open port capable of using the SMTP module to bounce torrents of e-mail to targets picked by the hackers.

After the planned assault on licensing company SCO, other coming MyDoom backdoor attacks will target users of the Kazaa peer-to-peer file sharing network by creating worm-laden copies of popular entertainment software swapped over Kazaa like the Winamp music player and the game Nuke2004. When run, these generate new floods of MyDoom e-mail.

The combination of a virtuoso’s programming skill and a chess player’s knack for making moves ahead of opponents clearly makes MyDoom the most dangerous hack attack yet.

And with the bulk of Round 2 backdoor attacks set to begin Sunday and run until Feb. 12, the computer-dependent United States faces 10 days of very rough midwinter sledding.

———-

Binary beat readers can participate in the column at chicagotribune.com/askjim, or e-mail [email protected]. Snail-mail him in Room 400, 435 N. Michigan Ave., Chicago 60611