Conficker is back and twisted

happygeek 1 Tallied Votes 355 Views Share

Remember Conficker, the virulent worm which caused such havoc at the start of the year? No, well maybe news headlines such as 'Virus sinks Royal Navy fleet comms' and 'Windows worm infects millions' might help jog your memory. Well hold onto your hats people, Conficker is back. And this time it comes with a new twist.

According to security specialists BitDefender the worm has not turned, but returned. Looking at the e-threat statistical report the company produces, I could hardly believe my eyes: sitting ugly on top of the most infected by charts was Conficker. In fact, of all the infected machines that BitDefender looked into during the month of August, Conficker (a.k.a Win32.Worm.Downadup) was sitting there staring back at them on a really quite staggering 43% of them. That puts it way out in front of other malware threats, with the second most prevalent infection (an Embarcadero Delphi built code injector called Win32.Induc.A) mustering a relatively meagre 15% share.

The latest Conficker variant has some new tricks up its virtual sleeve, such as not only being able to prevent access to IT security vendor websites as it always has but adding the installation of rogue security software onto the compromised machine. Highly profitable scareware scams have hit the headlines here at DaniWeb before, and Microsoft has had some success in hunting down the offenders. But the fact that Conficker is blocking access to legit software sites and leaving the door open to fake security solutions is a worrying turn of events.

The rest of the August threat list looks like this:

3. Win32.Sality.OG (polymorphic file infector)
4. Worm.Autorun.VHG (network worm)
5. Win32.Virtob.Gen (file infector written in assembly language)
6. Packer.Malware.NSAnti.1 (malware packing protection)
7. Win32.Worm.AutoIT.AC (keylogger dropper)
8. Win32.Sality.2.OE (dropped by Win32.Sality)
9. GEN:TDSS.Patched.1 (file dropper)
10. Win32.Worm.Downadup.Gen (worm exploiting MS08-67 vulnerability)

Dani AI

Generated

As and note, this thread is a good place to move from alarm to action. Below is a concise, practical containment + cleanup checklist and a short set of detection and prevention steps you can apply now — written so it still helps readers who find this thread years later.

  • Isolate suspected hosts immediately: unplug NICs or disable the interface, remove Wi‑Fi and USB access, and quarantine affected machines from backups and shared drives. (cisa.gov)
  • Preserve evidence if you need to investigate: collect memory and a network capture before doing destructive cleanup, or work from a known-clean rescue environment. (usenix.org)
  • Scan offline with reputable tools (bootable rescue media or vendor scanners) and run a full on‑demand scan from outside the infected host. If remediation is uncertain, reimage from a trusted image. (support.microsoft.com)

Signs to check quickly (good triage tasks)

  • Unexpected autorun/autorun.inf entries on removable media; newly created executables at the root of USB drives.
  • Unknown scheduled tasks, services, or random‑looking EXEs running under SYSTEM or LocalService.
  • High rates of DNS queries or repeated attempts to contact many domains in a short period — that behavior helps explain why infected hosts often generate lots of domain lookups. (usenix.org)

Hardening and follow-up

  • Apply vendor patches and OS updates promptly, disable vulnerable behavior (properly disable AutoRun/AutoPlay as documented), and deploy up‑to‑date endpoint protection and periodic offline scanning. (cisa.gov)
  • Treat confirmed infections as incidents: assume credentials that lived on infected systems may be compromised, rotate administrative passwords, and check domain controllers and backups for infection before reuse.
  • For organizations, segment endpoints, block unnecessary inbound services at the perimeter, and use application whitelisting where practical.

Helpful official references (keeps it short):

Caution: when unsure, prefer rebuilding from trusted media over manual “paper‑knife” removals; worms with persistence and anti‑analysis modules are often better eradicated by reimage than by chasing registry keys.

Jonnas_tan 0 Newbie Poster

Not Conficker again! bad memories with this one here! hardly got rid of it!

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

It's the scareware angle that worries me, you just know that's going to catch so many unsuspecting folks out.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.