
Latest virus attempts to cover tracks as bounty hunt continues
By Robert Lemos
Published: 11 February 2004 09:00 GMT
A worm that started spreading on Sunday places the source code for the original MyDoom virus on victims' hard drives, an action equivalent to planting evidence, antivirus experts said Tuesday.
The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.
The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos.
"If he has spread his code around the net onto innocent computers in an attempt to hide in the crowd, then he's more sneaky than the average virus writer," Cluley said in a statement.
Doomjuice is one of two opportunistic programs - the other dubbed Deadhat - that started spreading this week. Both viruses infect computers that have already succumbed to either of the two MyDoom viruses. Doomjuice also attempts to direct any re-infected PCs to attack Microsoft's website.
Doomjuice's possession of the source code for the original MyDoom virus suggests that the creator of the worm is also the writer of the original virus. A word in both MyDoom viruses - the name "andy" - has already suggested to some researchers that the original MyDoom and the MyDoom.B variant were created by the same person or group.
Other antivirus researchers agree that the latest hostile program could be intended to confuse investigations into who created the viruses.
"It stands to reason that the author might be hiding his tracks," said Craig Schmugar, virus research manager for Network Associates. "He might be trying not to get caught."
The SCO Group and Microsoft have made separate offers of $250,000 for information leading to the arrest and conviction of the person or group that started spreading the MyDoom.A and MyDoom.B viruses, respectively. If the viruses were created and released by the same person or group, it could result in a $500,000 payoff.
Robert Lemos writes for CNET News.com
Huxley Associates are recruiting for a Tender Writer and Co-ordinator to join a leading organisation based in Bristol. As Tender Co-ordinator you ...
Job Description - Technical Writer Responsibilities Technical Writer's responsibilities are as follows: To be a focal point for technical ...
Our client currently have a requirement for a Script Writer/Instructional Course Designer to join their existing team. Duties will include:- Develop ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy