Cheeky virus writers have put a secret message in the latest versions of the MyDoom e-mail worm asking antivirus vendors for a job.MyDoom.V and MyDoom.U contain a malicious e-mail attachment that attempts to download . . .. MyDoom.V and MyDoom.U contain a malicious e-mail attachment that attempts to download a backdoor Trojan horse called Surila if the recipient tries to open the infected file. Also secretly embedded inside the malicious code is a message to the antivirus industry: "We searching 4 work in AV industry." It is not clear if the job request is entirely serious but if the virus authors thought that the antivirus industry would be impressed with their handiwork, they've opened a whole different can of worms. Graham Clulely, senior technology consultant for antivirus firm Sophos, said no one in the industry would "touch them with a bargepole." . MyDoom.V and MyDoom.U contain a malicious e-mail attachment that attempts to download a backdoor Tro. cheeky, virus, writers, secret, message, latest, versions, mydoom, e-mail. . LinuxSecurity.com Team
A likely target appears to be The SCO Group, a provider of Unix software based in Lindon, Utah. SCO has stirred emotions in the Linux community by claiming that important pieces of the open-source operating system are covered by SCO's Unix copyright. The worm is programmed to instruct infected PCs to send a flood of bogus traffic, or a denial-of-service attack, to SCO's Web server Feb. 1 through Feb. 12. The worm can also drop a backdoor program onto a PC, allowing an intruder to take control of the machine, Huger said. . . .. A new mass-mailing computer worm that began rapidly spreading throughout the Internet Jan. 26 apparently avoids targeting the e-mail addresses of government agencies, military facilities and large software companies, according to a security expert at a leading antivirus firm. The worm -- known as MyDoom, W32.Novarg.A@mm, Shimgapi or as a variant of the MiMail worm -- is an encrypted program that creates a mass-mailing of itself, which may clog mail servers or degrade network performance. By avoiding federal sites and large software companies, the worm's author could be "attempting to get lead time before antivirus definitions" are written to block the worm, said Alfred Huger, senior director of engineering with Symantec Security Response, a unit of Symantec Corp. that tracks and responds to virus outbreaks. If the worm started attacking .mil and .gov e-mail addresses as well as antivirus vendors, then signatures could be written to thwart it much sooner, he said. Symantec and other leading antivirus vendors have pushed out software updates to customers to help protect against the worm. A likely target appears to be The SCO Group, a provider of Unix software based in Lindon, Utah. SCO has stirred emotions in the Linux community by claiming that important pieces of the open-source operating system are covered by SCO's Unix copyright. The worm is programmed to instruct infected PCs to send a flood of bogus traffic, or a denial-of-service attack, to SCO's Web server Feb. 1 through Feb. 12. Theworm can also drop a backdoor program onto a PC, allowing an intruder to take control of the machine, Huger said. The link for this article located at fcw.com is no longer available. . A fresh email-borne virus started proliferating on January 26, focusing on the SCO Group and posing risks to system efficiency.. MyDoom, DenialOfService, InternetThreat. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.