| « The power of naming | Stolen wisdom » |
The gift that keeps giving
I won't spend all my time ragging on China, but this incident is especially irritating because it's affected me personally. Consider this a public service message: don't buy digital photo frames from China. The viruses they contain are wicked.
A small reward for anyone who can name the "group" mentioned below: Notice that it blocks antivirus software.
The virus, which Computer Associates calls Mocmex, recognizes and blocks antivirus protection from more than 100 security vendors, as well as the security and firewall built into Microsoft Windows. It downloads files from remote locations and hides files, which it names randomly, on any PC it infects, making itself very difficult to remove. It spreads by hiding itself on photo frames and any other portable storage device that happens to be plugged into an infected PC.
The authors of the new Trojan Horse are well-funded professionals whose malware has "specific designs to capture something and not leave traces," Grayek said. "This would be a nuclear bomb" of malware.
By studying how the code is constructed and how it's propagated, Computer Associates has traced the Trojan to a specific group in China, Grayek said. He would not name the group.