Members Login
Username 
 
Password 
    Remember Me  
 

Topic: Three million hit by Windows worm

Page 1 of 1  sorted by
Wide (rest of width)
Narrow (200px)
MZ Life Time Member
Status: Offline
Posts: 8335
Date:

Three million hit by Windows worm

Three million hit by Windows worm

USB drives, BBC
The worm can also spread via USB flash drives.

A worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is posing a growing threat to users.

The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008.

Although Microsoft released a patch, it has gone on to infect 3.5m machines.

Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft's MS08-067 patch.

o.gif
start_quote_rb.gifRight now, we're seeing hundreds of thousands of [infected]unique IP addresses end_quote_rb.gif
Toni Koivunen, F-Secure

According to Microsoft, the worm works by searching for a Windows executable file called "services.exe" and then becomes part of that code.

It then copies itself into the Windows system folder as a random file of a type known as a "dll". It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.

Once the worm is up and running, it creates an HTTP server, resets a machine's System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker's web site.

o.gif
INFECTED IPs WORLDWIDE
China 38,277
Brazil 34,814
Russia 24,526
India 16,497
Ukraine 14,767
Italy 13,115
Argentina 11,675
Korea 11,117
Romania 8,861
United States 3,958
United Kingdom 1,789
Source: F-Secure

Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down.

But Conficker does things differently.

Anti-virus firm F-Secure says that the worm uses a complicated algorithm to generate hundreds of different domain names every day, such as mphtfrxs.net, imctaef.cc, and hcweu.org. Only one of these will actually be the site used to download the hackers' files. On the face of it, tracing this one site is almost impossible.

Speaking to the BBC, Kaspersky Lab's security analyst, Eddy Willems, said that a new strain of the worm was complicating matters.

"There was a new variant released less than two weeks ago and that's the one causing most of the problems," said Mr Willems

"The replication methods are quite good. It's using multiple mechanisms, including USB sticks, so if someone got an infection from one company and then takes his USB stick to another firm, it could infect that network too. It also downloads lots of content and creating new variants though this mechanism."

"Of course, the real problem is that people haven't patched their software. If people do patch their software, they should have little to worry about," he added.

Technicians have reverse engineered the worm so they can predict one of the possible domain names. This does not help them pinpoint those who created Downadup, but it does give them the ability to see how many machines are infected.

"Right now, we're seeing hundreds of thousands of unique IP addresses connecting to the domains we've registered," F-Secure's Toni Kovunen said in a statement.

"We can see them, but we can't disinfect them - that would be seen as unauthorised use."

Microsoft says that the malware has infected computers in many different parts of the world, with machines in China, Brazil, Russia, and India having the highest number of victims.

__________________
For Pictures...Flyers and Posters and any other design link me up at

rhn_roberts@yahoo.com...rrDesignZ

jamaicaadverts.com
Status: Offline
Posts: 10001
Date:
that *u*ks

__________________

mediabanner.gif


MZ Guru
Status: Offline
Posts: 1810
Date:
GUESS I'L BE NEXT..............

__________________
GAZA 
4492.gif

4057.gif

Breaking Out Type
Status: Offline
Posts: 434
Date:
thanks fi the info


__________________
DIGI NEIL
MZ Super Veteran
Status: Offline
Posts: 6973
Date:
SMH

__________________
5
▀▄▀▄★♫ Admin ♫★▀▄▀▄
Status: Offline
Posts: 11336
Date:
Breaking Out Type
Status: Offline
Posts: 355
Date:
lc

__________________

banner433.jpg

Silent Type
Status: Offline
Posts: 145
Date:
wat should i do????????????????????|

__________________
MZ Teacha
Status: Offline
Posts: 770
Date:
bless


__________________
Teacha
Status: Offline
Posts: 4475
Date:
oo zeeet

__________________
Its better to Have plans and Schemes than Hopes and Dreams.........Hard Work is the Key to Sucsess..doah
GAZA MI SEY

avrh4m.gif


MZ Super Diplomat
Status: Offline
Posts: 7701
Date:
Ohh damm... Thnx for the info

__________________
Super Member
Status: Offline
Posts: 2167
Date:
If any of unuh hit di WORM dis can mayb helpfull to remove it
Di comments see positive so... Try it if anyting happen
http://anything2fix.wordpress.com/2009/01/06/new-virus-detected-win32confickera-worm/

__________________

24zbuwp.jpg

8xvjoz.jpg

Equal Rights & Justice 4 all

MZ Life Time Super Member
Status: Offline
Posts: 11559
Date:
wowpity

__________________
Page 1 of 1  sorted by
Quick Reply

Please log in to post quick replies.