ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

MyDoom author appears to cover tracks

Published: 11 Feb 2004 08:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A worm that started spreading on Sunday places the source code for the original MyDoom virus on victims' hard drives, an action equivalent to planting evidence, antivirus experts said on Tuesday.

The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.

The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos.

"If he has spread his code around the Net onto innocent computers in an attempt to hide in the crowd, then he's more sneaky than the average virus writer," Cluley said in a statement.

Doomjuice is one of two opportunistic programs -- the other dubbed Deadhat -- that started spreading this week. Both viruses infect computers that have already succumbed to either of the two MyDoom viruses. Doomjuice also attempts to direct any re-infected PCs to attack Microsoft's Web site.

Doomjuice's possession of the source code for the original MyDoom virus suggests that the creator of the worm is also the writer of the original virus. A word in both MyDoom viruses -- the name "andy" -- has already suggested to some researchers that the original MyDoom and the MyDoom.B variant were created by the same person or group.

Other antivirus researchers agree that the latest hostile program could be intended to confuse investigations into who created the viruses.

"It stands to reason that the author might be hiding his tracks," said Craig Schmugar, virus research manager for Network Associates. "He might be trying not to get caught."

The SCO Group and Microsoft have made separate offers of $250,000 (£134,091) for information leading to the arrest and conviction of the person or group that started spreading the MyDoom.A and MyDoom.B viruses, respectively. If the viruses were created and released by the same person or group, it could result in a $500,000 payoff.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
73 out of 137 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

GCP SOP/ Technical Author/ Medical Writer - CRO/ Pharma

Urgent requirement for an experienced medical writer/ technical author. Role/ Requirments: - GCP experience - Phase II or III - Quality Assurance/ QA ...

Medical Writer, Medical Communications Oxford 28-40k

Leading medical education agency requires experienced Medical Writer This is an outstanding opportunity to join one of the leading names in medical ...

VB/Access/SLQ Reports Writer - Bristol

My exclusive client in Bristol is looking for a Reports Writer for a short term contract role. This will require a good all round IT professional ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment