MyDoom author may be covering tracks
The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.
The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos.
"If he has spread his code around the Net onto innocent computers in an attempt to hide in the crowd, then he's more sneaky than the average virus writer," Cluley said in a statement.
[ Read more ]
- Software: MyDoom Removal Tool
- Virus News: Novarg: New Worm - New Epidemic (28 January 2004)
- Virus News: Mydoom Worm Spreading Fast, Sophos Warns (27 January 2004)
- Virus News: New "Mydoom" Worm Launching a World-Wide Attack (27 January 2004)
- Virus News: Central Command Warns of New Worm Named Worm/MyDoom (27 January 2004)
- Review: Viruses Revealed (28 April 2003)
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.