On TechRepublic: Badly configured laptop ruins man's life
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Jul 13, 2004 1:53:00 PM

The latest mass-mailing worm, Atak, hides by going to sleep when it suspects that antivirus software is trying to detect it.

Atak was first discovered Monday. Although antivirus companies do not expect it to cause much damage, they say it will be a nuisance because it can generate a large amount of spam.

Graham Cluley, senior technology consultant for antivirus company Sophos, said authors of malicious software generally try to make the job of antivirus researchers as difficult as possible by adding confusing code and using evasion techniques.

"Atak tries to tell when someone is stepping through the code to analyze whether it is a virus or not. Often, a virus will contain lots of code that is designed to make it more complicated for (antivirus) companies to write the detections," Cluley said.

Mikko Hypponen, director of antivirus research at Finnish company F-Secure, said that although it is common practice for virus writers to protect their malware, this worm is exceptional.

"It is standard for worms to have layers of encryption--or armoring--to keep out snoopers, but this goes way beyond that. It tries actively to detect if it is being analyzed by antivirus research tools. If it thinks it is being analyzed, it stops running and shuts down," Hypponen said.

Atak is not thought to be a serious threat. But because of recent detection and in-built protection, the worm's full functionality has not yet been fully analyzed. However, it is known that the worm contains text that seems to threaten other well-known worms and viruses, such as MyDoom, Bagle and Netsky.

Hypponen said there is a possibility that Atak will try to seek out and destroy "rival" worms.

"We haven't been able to figure out if Atak tries to disable some of these viruses," he said. "The message implies it does contain some code that attacks other viruses."

Munir Kotadia of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 107 Talkback(s)
IE won't go away...
You're an idiot if you really believe IE will ever be overtaken by another browser. Do you not realize how powerful 95% market share really is? There may be alternatives to IE, but they are not better... (Read the rest)
Posted by: FastEddie_z Posted on: 07/26/04 You are currently: Logged In | Log out
Wow, they don't even bother to mention it's a "W32" only problem anymore Xunil_Sierutuf   | 07/13/04
If it was Linux virus, it wouldn't even make the news. No_Ax_to_Grind   | 07/13/04
LOL... you just keep thinking that in your own little reality Xunil_Sierutuf   | 07/13/04
And you keep the "dream" alive. k? No_Ax_to_Grind   | 07/13/04
Windows didn't catch on in a year Michael Kelly   | 07/13/04
Linux won't replace Windows - BUT... coffeeroyal@...   | 07/13/04
You know better than that... Michael Kelly   | 07/13/04
just because he knows better, ryusen   | 07/13/04
Same ole bity, same ol BS. AmusedAtItAll   | 07/13/04
I have a dog, you. No_Ax_to_Grind   | 07/13/04
Sticklers Unite Grammarian   | 07/13/04
RemedialEnglish is not one of No_Ax’s strong points. B.O.F.H.   | 07/13/04
RemedialEnglish dumbumpkin   | 07/13/04
But isn't the real problem AH_in_Detroit   | 07/13/04
no i don't beleive it... ryusen   | 07/13/04
LOL!...Exactly! jstoker@...   | 07/13/04
It would affect more than you can even imagine ECLS   | 07/13/04
7.9 for references to the "spork" (NT) Monkey_MCSE   | 07/13/04
It'd be HEADLINE news voska   | 07/13/04
re: It'd be HEADLINE news richdave   | 07/13/04
Conversely michael-t   | 07/13/04
They dont have to LTE   | 07/13/04
Sticklers Unite Grammarian   | 07/13/04
Wonder how much $ ... bjbrock   | 07/13/04
UHHH ... Isn't it assumed it's MicroSoft gitmo   | 07/13/04
Linking Mystery eric.d.dobbs@...   | 07/13/04
That seems to be machine-specific problem NT Admin   | 07/13/04
Linking Mystery? rgetsla   | 07/14/04
i dunno about that... ryusen   | 07/13/04
Got Exploit? Chad_z   | 07/13/04
No thanks - having a wonderful day... Confused by religion   | 07/13/04
Here you go Milly.. Xunil_Sierutuf   | 07/13/04
she just likes to rant.. Monkey_MCSE   | 07/13/04
Actually... Confused by religion   | 07/13/04
definitely no apology sent... Monkey_MCSE   | 07/13/04
Netgear has been Linux User 147560   | 07/13/04
Milly did you try michael-t   | 07/13/04
give me a break Milly; ryusen   | 07/13/04
But can it run Photoshop CShock   | 07/13/04
tried codeweavers? ryusen   | 07/13/04
who's paying? ryusen   | 07/13/04
Core Wars rgriffith64@...   | 07/13/04
Wow, all that coding talent going to this FilledOut   | 07/13/04
Now Linux User 147560   | 07/13/04
You're absolutley correct!!! medezark   | 07/13/04
i would hardly call "certain companies" ryusen   | 07/13/04
Yes, as the most widely distributed OS with flaws and exploitable features FilledOut   | 07/14/04
Smith and Wesson makes Bank Heists easier also.... GregSalts   | 07/14/04
Re: Smith& Wesson analogy eulagree   | 07/15/04
Making criminals Job easier... Boyd   | 07/15/04
Re: You're absolutely correct! RealAusTech   | 07/13/04
Excellent Post!! djc1309@...   | 07/14/04
All that coding talent - It's the Economy goldy_z   | 07/15/04
Win vs Lin and people destorying PC's ibabadur1   | 07/13/04
Agree to a point. GoodOyster   | 07/13/04
Re: Win vs Lin and people destorying PC's BXLE   | 07/13/04
re: Re: Win vs Lin and people destorying PC's Iain_Peters   | 07/13/04
Actually, no. middle of nowhere   | 07/13/04
Computers for n00bs... strawbrn   | 07/13/04
You're just clueless. hulse_kevin   | 07/13/04
blah blah blah blah blah hulse_kevin... DigitalKid   | 07/13/04
re:blah blah richdave   | 07/13/04
re:blah blah richdave   | 07/13/04
Thank you! strawbrn   | 07/14/04
Amen! tgrady   | 07/15/04
Becareful strawbrn.....don't make too much sense.. DigitalKid   | 07/13/04
"She has a Mac." tgrady   | 07/15/04
three points of defense... ryusen   | 07/13/04
With what we have to use now, I agree. agottschald   | 07/13/04
I wholeheartedly... eulagree   | 07/15/04
You say twblackmon@...   | 07/15/04
And it's not just computer n00bs fgreyfox   | 07/13/04
Who is responsible wisperingwind@...   | 07/13/04
Not caused by poor code ibabadur1   | 07/13/04
But what if the lock is defective voska   | 07/13/04
Doesn't Matter gsquared   | 07/13/04
Lock anology Cerebral*Origami   | 07/13/04
Please excuse the typos/spelling - I forgot to proof read. Cerebral*Origami   | 07/13/04
re: Lock anology Iain_Peters   | 07/13/04
9 months eh? PmAc_z   | 07/13/04
Lock Quality is the issue, security cost $$$ for a reason voska   | 07/13/04
Poor code is the Root Cause NT Admin   | 07/13/04
Not caused by poor code but michael-t   | 07/13/04
Question NT Admin   | 07/13/04
It's good to know michael-t   | 07/13/04
For the love of god, why is everything a linux/MS war? DigitalKid   | 07/13/04
C'mon Digi don't mince words tell us how you really feel Squawkbox   | 07/13/04
Funny! strawbrn   | 07/13/04
The Same reason Chev and Ford driver fight voska   | 07/13/04
I like my Ford Truck toadlife   | 07/13/04
I Feel For You, Digi...... tlciii   | 07/14/04
Right you are! DigitalKid   | 07/14/04
Funny haven't seen this on a major AV site pjg1173   | 07/13/04
Interesting if... Domb2   | 07/13/04
What we REALLY need are michaelchapek@...   | 07/13/04
NanoWorms dr_who@...   | 07/14/04
(NT) NanoWorms - Steve Gibson could write them. toadlife   | 07/14/04
Ahh- the joys of Talkback messenge boards! mrb971@...   | 07/14/04
WORM WARS!! (: dr_who@...   | 07/14/04
worm sleeps to avoid detection twomanyhats@...   | 07/14/04
Atak worm avoiding detection krystaltierz@...   | 07/15/04
Actually... eulagree   | 07/15/04
Worm sleeps to avoid detection a8a09923@...   | 07/15/04
I also wanted to add a final/semi-final note. eulagree   | 07/15/04
That is because victor@...   | 07/15/04
ATTACK! Roderick2359   | 07/19/04
IE won't go away... FastEddie_z   | 07/26/04

What do you think?

  • Printers
  • 'Green' Font Cuts Costs and Saves Trees (BNET)
  • Three Ways to Save Paper (BNET)
  • CNET Reviews printer buying guide (CNET)
  • View all printers-tagged content on ZDNet
  • Plan B from Brother
  • It's the smarter way to work in color Our professional color ink-jet all-in-ones give you more choices, more features, and more value. Make the Smarter Choice. Learn More »
advertisement
Click Here