Skip to navigation
Latest News

Dumaru worm twists again

By Alun Williams

Posted on 29 Sep 2003 at 11:27

The Dumaru worm is continuing to evolve. First appearing only in mid-August, it has now reached its fifth generation in the wild with the Dumaru-E variant.

Purporting to come from 'security@microsoft.com', the virus email will have a subject line of 'Use this patch immediately !' and a patch.exe attachment.

As we always repeat, Microsoft does not send security updates by email so this message should be easily identifiable as a rogue mailing. Do not execute the patch attachment!

As well as carrying its own SMTP engine (to spread itself further by email) and attempting to infect all executables with copies of itself, the worm will monitor your computer activities.

It creates the file guid32.dll in the Windows folder to monitor running programs and keystrokes, and these will be logged into the files vxdload.log and winload.log in the Windows folder. These logs may later be uploaded to a remote FTP server.

More information can be found at the Sophos website.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.