Computing.Net > Forums > Security and Virus > New sleeping worm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

New sleeping worm

Reply to Message Icon

Name: IronMan
Date: July 13, 2004 at 11:10:03 Pacific
OS: XP
CPU/Ram: P4 512MB
Comment:


Published by CNET News.com
_________________________________

Worm sleeps to avoid detection

By Munir Kotadia

The latest mass-mailing worm, Atak, hides by going to sleep when it suspects that antivirus software is trying to detect it.

Atak was first discovered Monday. Although antivirus companies do not expect it to cause much damage, they say it will be a nuisance because it can generate a large amount of spam.

Graham Cluley, senior technology consultant for antivirus company Sophos, said authors of malicious software generally try to make the job of antivirus researchers as difficult as possible by adding confusing code and using evasion techniques.

"Atak tries to tell when someone is stepping through the code to analyze whether it is a virus or not. Often, a virus will contain lots of code that is designed to make it more complicated for (antivirus) companies to write the detections," Cluley said.

Mikko Hypponen, director of antivirus research at Finnish company F-Secure, said that although it is common practice for virus writers to protect their malware, this worm is exceptional.

"It is standard for worms to have layers of encryption--or armoring--to keep out snoopers, but this goes way beyond that. It tries actively to detect if it is being analyzed by antivirus research tools. If it thinks it is being analyzed, it stops running and shuts down," Hypponen said.

Atak is not thought to be a serious threat. But because of recent detection and in-built protection, the worm's full functionality has not yet been fully analyzed. However, it is known that the worm contains text that seems to threaten other well-known worms and viruses, such as MyDoom, Bagle and Netsky.

Hypponen said there is a possibility that Atak will try to seek out and destroy "rival" worms.

"We haven't been able to figure out if Atak tries to disable some of these viruses," he said. "The message implies it does contain some code that attacks other viruses."



Sponsored Link
Ads by Google

Response Number 1
Name: aosclay
Date: July 13, 2004 at 15:21:13 Pacific
Reply:

BEHOLD!

THE END IS NIGH!

ABANDON ALL HOPE YE WHO ENTER HERE!

Please, sir, I want some more. Did we really need a new rather sophisticated worm? Can we not be content with the ones we have?

Oh, well, I guess there's just always going to be somebody out there making this harder everyday.

What can I say? I guess "Let's dance!"

gotta love it.

AOSCLAY
Primary Hard World Fail


0
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: New sleeping worm

New Bagle Worm www.computing.net/answers/security/new-bagle-worm/13525.html

New APHER Worm... www.computing.net/answers/security/new-apher-worm/1918.html

NEW Worm www.computing.net/answers/security/new-worm-/3124.html