Friday, February 13, 2004

MyDoom author may be covering tracks - News - ZDNet:
"A worm that started spreading on Sunday places the source code for the original MyDoom virus on victims' hard drives, an action equivalent to planting evidence, antivirus experts said Tuesday.

The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.

The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos. "


Doomjuice is one of two opportunistic programs--the other dubbed Deadhat--that started spreading this week. Both viruses infect computers that have already succumbed to either of the two MyDoom viruses. Doomjuice also attempts to direct any re-infected PCs to attack Microsoft's Web site.

Doomjuice's possession of the source code for the original MyDoom virus suggests that the creator of the worm is also the writer of the original virus. A word in both MyDoom viruses--the name "andy"--has already suggested to some researchers that the original MyDoom and the MyDoom.B variant were created by the same person or group.

Other antivirus researchers agree that the latest hostile program could be intended to confuse investigations into who created the viruses.

http://zdnet.com.com/2100-1104_2-5156836.html

No comments: