The Virus Squad
dncsky1530 writes "Sydney Morning Herald - The Virus Squad - 'A new species has been discovered. So new, it's still unnamed, but researchers are racing to tag it - before it spreads around the world. For the next 10 to 30 minutes, the computer virus or worm is dissected, analysed and identified... "On the day we detected MyDoom, we did another 18 viruses," says Paul Ducklin, Sophos's head of technology for the Asia-Pacific. "There are about 800 new viruses a month. And the unglamorous bit of our work is often the other 798."'"
Back then, at lot of them didn't infect executables, but went for boot sectors like STONED. And there are arbitrary EXE infectors around still, but they tend to get noticed and whacked faster than ones that don't.
One line blog. I hear that they're called Twitters now.
I have been working as a consultant for small office and home office users since being laid of from Intel in 2002. The view from the small office and home office is very different from the view from within the IT industry. I've been working to educate my clients on the importance of regular backups, anti-viral protection and firewall protection. I spent the last two weekends removing viruses from computers that were on cable modem connections with no ant-viral software installed and no firewall installed.
I am starting to think that I need to help my clients to protect their data and make their systems hard targets. I'd like to think that the virus problem will be addressed by operating system changes. However, the reality in the small office and home office is that operating system upgrades are almost always tied to the purchase of a new computer. Third party security products will continue to be important as long as users stick with what works for them today without worrying about what might be available tomorrow.
Old schoool viruses tended to be designed to do damage. They infected as many files on the system as possible often destroying the file in the process.
This approach is counterproductive if you want it to spread. Modern e-mail worms rarely show much evidence of their presence, if it seems like nothing is wrong then the user won't look for a problem. This leaves the worm free to mail itself to thousands of others and the system is added to the long list of compromised machines at the crackers disposal for DDoS attacks or spam relays.
This is the same reason you don't get any 'wipe your hard drive on a certain date' viruses anymore. It isn't about doing damage it is about infecting as many machines as possible either for the 'fame' or to build up nets of infected drone machines for another purpose.
I am surprised the article didn't mention the real reason MyDoom targeted SCO, it was a diversion. Spammers need new drone machines to send spam from but they don't want the backlash from being connected to a virus so they add in a diversion, the attack on SCO. This took the heat off the spammers and placed it firmly on the OSS community. And it worked, kind of, only recently has the spamming 'features' of MyDoom seen any press. For weeks all that was reported was how it was probably created by a OSS zealot lashing out at SCO.
Well, the article hints at some sort of collusion between spammers and the author of MyDoom, but it seems like this would be the exception, even if it's true. The virus writers are in it for the fun, of course (not to mention revenge).
It also seems possible that the antivirus companies themselves are writing the viruses, then charging to protect users against them, but this also seems unlikely, given the police investigations that inevitably follow major virus outbreaks.
Its quite ironic that over the years ive downloaded a hell of a lotta dodgy programs from dodgy sites and P2P and never used an anti-virus tool and the only trouble ive had (never used outlook) is when i've connected an unpatched windows machine to the net and been infected in 3 minutes.
This comment does not represent the views or opinions of the user.
At each hop in the infection, a virus could gather PayPal and other account information from the hard drive. That would be passed along in all the mailings it sends out to other machines, gathering more account info along the way. Once it travelled five hops, it would use the information to send five dollars to the account at the top of its list, remove top account, move the others up, repeat.
The social engineering aspects are huge: "Gee, my computer has been infected, but if I wait until it's infected several other computers before removing it, I could make millions!" It could even come with a reassuring EULA: "This is really legal honest! The FTA said so!"
There are privacy concerns, of course, but if it only passed on the account information required to deposit and not to withdraw money, I'm sure people would feel so much better about it. :^P
One line blog. I hear that they're called Twitters now.
I received a few emails with attachments which just smelled like worms, although neither the AV checker I had on my Linux system nor one of the online AV checkers identified them as infected. Curious about this, I saved them in a directory and rechecked them from time to time. It wasn't until 3 or 4 months later that the AV checkers fingered them as worms, and worms that had been floating around for almost a year. (I assume a virus writer must have tweaked the code on an existing virus just enough to make its signature unidentifiable as the original worm.)