MyDoom author may be covering tracks
The worm, Doomjuice, spreads to computers that have already been infected by either the original MyDoom virus or the MyDoom.B variant, and among other actions, places several copies of the source code for MyDoom.A on a victim's computer.
The author may be using the tactic to create a crowd of PC users in which to hide, or the author could be spreading the code in hopes that other virus writers will create variations on MyDoom, said Graham Cluley, senior technology consultant for antivirus company Sophos.
"If he has spread his code around the Net onto innocent computers in an attempt to hide in the crowd, then he's more sneaky than the average virus writer," Cluley said in a statement.
[ Read more ]
- Software: MyDoom Removal Tool
- Virus News: Novarg: New Worm - New Epidemic (28 January 2004)
- Virus News: Mydoom Worm Spreading Fast, Sophos Warns (27 January 2004)
- Virus News: New "Mydoom" Worm Launching a World-Wide Attack (27 January 2004)
- Virus News: Central Command Warns of New Worm Named Worm/MyDoom (27 January 2004)
- Review: Viruses Revealed (28 April 2003)
Reading our newsletter every Monday will keep you up-to-date with security news.
Receive a daily digest of the latest security news.