  • 30 January, 2004 10:43

European messaging and content security specialist GFI has issued the following technical explanation of the MyDoom/Novarg virus.
<p>The Mydoom/Novarg virus can be caught by GFI’s gateway-level Trojan scanner BEFORE anti-virus vendors release updates against it</p>
<p>"A two hour vendor warning can be two hour too late"</p>
<p>Sydney, 30 January 2004 –Novarg (also known as Mydoom and Mimail.R), the latest email virus to threaten the security of networks worldwide, highlights yet again that it is not enough to rely on anti-virus protection alone. The time it takes for anti-virus vendors to discover a virus and issue an update is too long and allows ample room for infection and distribution. GFI’s Trojan and Executable Scanner catches Novarg and other new viruses immediately - before their signatures are issued.</p>
<p>The difference between a virus engine and a Trojan and executable scanner:</p>
<p>Because anti-virus software is signature-based, it can only detect known viruses and Trojans, and is therefore unable to detect new viruses such as the Mydoom/Novarg as soon as they are released. GFI MailSecurity's Trojan and Executable Scanner takes a different approach: Rather than relying on signatures, it uses built-in intelligence to rate an executable’s risk level. It does this by disassembling the executable, detecting in real time what it might do, and comparing its actions to a database of malicious actions. This way, GFI MailSecurity can detect unknown viruses and Trojans before they enter the network - and before anti-virus engine vendors have issued signatures against them.</p>
<p>"A couple of hours too late"</p>
<p>"If a vendor takes a couple of hours to issue an update against a new virus, this is often a couple of hours too late. By then, the damage is done. All it takes is for one machine on a network to be infected. The virus then propagates to that network and others, causing great damage," explained Scott Hagenus, GFI Asia Pacific. "Organizations need to take a proactive approach to protecting themselves and should install gateway-level protection against one-off and unknown email threats and Trojans, as well as standard virus scanning software."</p>
<p>It is for this reason that GFI MailSecurity for Exchange/SMTP - GFI’s email content security and anti-virus product for Exchange and SMTP mail servers - incorporates a number of features against email threats, including the Trojan and Executable Scanner.</p>
<p>Mydoom or Novarg.A is reported to be infecting a vast number of computers. This worm is an executable that travels in the form of an email attachment, and it requires users to run the executable to be activated. The worm spoofs the email sender and the executable is usually compressed inside a zip file. It also launches a Denial of Service attack on and opens a backdoor on the infected computers. The GFI Trojan and Executable Scanner feature is able to catch Novarg.A because this infringes the scanner’s "CheckUPX" rule; the worm is compressed using a UPX packer, which indicates that such an executable might be malicious.</p>
