943,311 Members | Top Members by Rank

Ad:
-7

Windows worm infects millions

by on Jan 16th, 2009, 7:13 pm
If you are a Windows user and have not installed the MS08-067 patch from last October, then perhaps you had better pull your finger out. Of course, it could well be too late, and you could well be one of the nine million or so users who have already fallen victim to one of the most widespread of worms to hit Windows for a long time. If you are a Linux or Mac user, of course, you can sit back and relax.

Known by various names such as Conficker, Downadup and Kido, the worm is exploiting the double-edged sword that is user slowness in applying Microsoft security patches and equal apathy in running up-to-date antivirus software.

The worm will adopt the guise of the services.exe executable, copy itself to your Windows folder as a .dll file and proceeds to modify the Registry in order to grant itself the necessary permissions to run as a service. At this point, things start turning really nasty. The malicious code will install an HTTP server on your network and even reset your Windows OS System Restore point just in case it is discovered so it can copy itself right back again.

Naturally it then goes on to start downloading various other bits of malware, but what makes Conficker a little unusual is that it is capable of generating hundreds of new and varied domain names each day. One of them will be the real host for the malware downloads, but finding it is like looking for the proverbial needle in a haystack.

Which is probably why security experts say that the bugger has infected at least nine million users so far, and the number is growing rapidly. China, Brazil, Russia and India would seem to be the worst hit countries.
News Story Tags: malware, news, security, windows, worm
Similar Threads
 
 
Comments on this News Story
Jan 17th, 2009
0

Re: Windows worm infects millions

Ah naive me. I thought the days of nasty Windows infections were over.
Posting Virtuoso
scru is offline Offline
1,624 posts
since Feb 2007
Jan 17th, 2009
0

Re: Windows worm infects millions

Windows viruses aren't over ... but they are getting nastier.
Newbie Poster
Lead Goat is offline Offline
8 posts
since Jan 2009
Mar 16th, 2009
0

Re: Windows worm infects millions

There is a new site in place from BitDefender, with two different tools that removes downadup/conficker infections. There's a home user tool and one that is recommended for sysadmins. The second one deploys a tool for scanning and disinfection in your managed network. - http://www.downadup.org
Newbie Poster
EsoxLucius is offline Offline
7 posts
since Nov 2006
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: browser search hijack - help please!
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: Please, please, please help if you can!!





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC