Windows worm rears ugly head

Datom.A virus poses as Microsoft update

Written by James Middleton

Advertisement

Windows users are being warned to be on the lookout for a virus disguised as 'copyrighted Microsoft code' and claiming to be a Windows update.

One expert has even warned that the Windows worm, Datom.A, "could mark an evolution for viruses' modus operandi".

The worm may arrive as an email purporting to be a Microsoft update, but it can also spread through open network shares.

The actual worm itself consists of three components: MSVXD.exe, MSVXD16.dll and MSVXD32.dll, created using Borland C++.

"Taken separately, these files cannot be considered as malware, but together they form a pretty malicious code," said Costin Ionescu, virus researcher at BitDefender.

Aside from dropping copies of itself in all subfolders and network folders, experts have said that the worm may mark a significant evolution in virus coding because of the unusual tricks it uses to hide itself.

Relevant strings of characters are stored in an encrypted format in the virus files in order to avoid disassembly and analysis, and the virus also uses a few anti-debugger tricks.

The worm uses another trick to make itself 'invisible' in the registry and kills personal firewall Zone Alarm if it is found running, before attempting to connect to the Microsoft website.

It is also thought that the worm tweaks the registry and modifies the default application that opens .html files - presumably a web browser. But it is unclear exactly why it does this or why it tries to connect to Microsoft's website.

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

Most commented stories

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

05 Sep 2008

8.64 MBPodcast Special: Views from the Valley More...

Podcast image

04 Sep 2008

12.7 MBComputing podcast 4 September 2008 More...

Podcast logo

02 Sep 2008

8.39 MBEco-Entrepreneur Podcast: Bulldog More...

Poll

INTERNET EXPLORER 8

INTERNET EXPLORER 8

Are you intending to download Internet Explorer 8 when it becomes available?

Previous poll results

Spotlight

LogMeIn Rescue+Mobile

BlackBerry gets LogMeIn remote support

Rescue+Mobile lets a support technician take control of the handset   More...

Dell manufacturing plant

Dell planning factory closures to cut costs

Report claims that PC maker is looking to sell off...  More...

Google Chrome

More growing pains for Chrome

Google wrestles with licensing and security problems   More...

Smartphone

US takes 3G crown from Europe

Americans finally catch up with Europeans in adoption of 3G   More...

Primary Navigation