New homeland security tool to detect Conficker worm

March 30, 2009 The US Department of Homeland Security released a tool to detect whether a computer is infected by the Conficker worm

Enlarge

The US Department of Homeland Security released a tool to detect whether a computer is infected by the Conficker worm

The US Department of Homeland Security released a tool on Monday to detect whether a computer is infected by the Conficker worm.

The department, in a statement, said the detection tool for the Conficker worm, also known as DownAdUP, had been developed by the US Computer Emergency Readiness Team (US-CERT).

"While tools have existed for individual users, this is the only free tool -- and the most comprehensive one -- available for enterprises like federal and state government and private sector networks to determine the extent to which their systems are infected by this worm," said US-CERT director Mischel Kwon.

"Our experts at US-CERT are working around the clock to increase our capabilities to address the cyber risk to our nation's critical networks and systems, both from this threat and all others," he added.

The worm is suspected to have infected million of computers running the and Windows maker Microsoft has offered a 250,000 dollar bounty for those responsible for the worm.

US-CERT recommended that Windows users apply Microsoft security patch MS08-067 to help provide protection against the worm.

The patch is designed to prevent an attacker from remotely taking control of an infected computer system and installing additional .

Malware could be triggered to steal data, generate spam attacks or turn control of infected computers over to hackers amassing "zombie" machines into "botnet" armies.

The worm is programmed to modify itself on Wednesday, April Fool's Day, according to specialists.

Conficker had been programmed to reach out to 250 websites daily to download commands from its masters, they said, but on Wednesday it will begin connecting with 50,000 websites daily for instructions.

The hackers behind the worm have yet to give it any specific orders.

"That's the interesting thing. The only thing the worm is being asked to do is to ask for further instructions," Steve Trilling, vice president of security firm Symantec, told the CBS program "60 Minutes" in a story aired on Sunday.

More information:
-- US-CERT recommends that Windows Operating Systems users apply Microsoft security patch MS08-067 (http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx) as quickly as possible to help protect themselves from the worm.

-- Instructions, support and more information on how to manually remove a Conficker/Downadup infection from a system have been published by major security vendors. Each of these vendors offers free tools that can verify the presence of a Conficker/Downadup infection and remove the worm:

Symantec:
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99
Microsoft:
http://support.microsoft.com/kb/962007
http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx

(c) 2009 AFP


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4 /5 (6 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • atphan - Mar 30, 2009
    • Rank: 5 / 5 (2)
    Hopefully as our populace becomes more internet and computer savvy, things like this will have less impact.



    http://blog.benchside.com
  • atarikg - Mar 30, 2009
    • Rank: 1 / 5 (1)
    I hate that kinda hackers and I hate why those Anti-Virus Softwares are too expensive. They are not affordable...
  • shyataroo - Mar 31, 2009
    • Rank: 3.5 / 5 (2)
    Its probably just going to continue asking for instructions until it has enough computers to do whatever it needs. (hacking the CIA database?)
  • Doug_Huffman - Mar 31, 2009
    • Rank: 2.3 / 5 (3)
    Yeah, right, I'm going to load a free government provided snoop-my-computer program, this after Echelon and Carnivore and all. Right. Fools.

    Prepare to be assimilated by the BOG Obongo. Resistance to Obamination is futile. BOG Brother is watching - OBEY!
  • RayCherry - Mar 31, 2009
    • Rank: not rated yet
    Hopefully as our populace becomes more internet and computer savvy, things like this will have less impact.


    The only current solution is to disconnect, but like social isolation, this is only part of the solution.

    With the government providing a response to this virus, it is an indication of the threat posed by millions of interconnected computing devices under only partial control of their owners. Operating system developers, software distributors and retailers are currently ineffective in limiting the opportunities for large scale computing under corrupt or criminal control. The end users are insufficiently educated, and the commercial market can not afford to deter new consumers with a steep obligatory learning curve about Internet security. Hence, none exists apart from annoying and completely evadable pop-up warnings, (if anything at all), and the eventual disfunctionality of the computer due to viruses 'contracted'.

    The virus writers are not going to stop. It is subversive science, but science none the less. Trial and error, measured success, progress and evolution. Organic and openly available to any inquisitive mind.

    More, it has a commercial value that was recognised many years back by software companies ... the more viruses, the more anti-virus market. Worse, organised crime will use viruses, and the authors of them, to make money estimated to be far in excess of the profits of anti-virus software. Last, (if conspiracy like), we have only to imagine what governments world-wide are doing with this portal into our lives - and into each others national boundaries.

    The fact is, most computer users are playing and socialising with a tool that can, if used correctly, bring a country/economy temporarily to its knees.

    Who knows? Perhaps it is happening right now.

    Paranoia is not going to help. Is the Internet, (and all that available raw computer processing power), as much a risk as a benefit? That is the question.

March 30, 2009 all stories

Comments: 5

4 /5 (6 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • The Raging Windows Worm has attacked over 8.9 Million Computers
    created Jan 19, 2009 | popularity not rated yet | comments 0
  • Conficker Worm Prepares For A New Release On April 1
    created Mar 27, 2009 | popularity not rated yet | comments 0
  • Downadup Worm Hits Over 3.5 Million Computers
    created Jan 16, 2009 | popularity not rated yet | comments 0
  • Help! How to avoid fast-moving computer worm
    created Jan 28, 2009 | popularity not rated yet | comments 0
  • No foolproof way to beat virus attack for now
    created Aug 17, 2005 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • transient heat transfer
    created Nov 23, 2009
  • More from Physics Forums - General Engineering

Other News

US online ad revenue down 5.4 pct in third quarter

Technology / Internet

created 32 minutes ago | popularity not rated yet | comments 0

(AP) -- Online advertising revenue in the U.S. fell 5.4 percent in the third quarter from a year ago, as the sputtering economy kept its tight grip on even the fastest growing segment of industry, according to a report released ...


Wikileaks

Wikileaks releases pager intercepts from 9/11

Technology / Internet

created 33 minutes ago | popularity not rated yet | comments 0

Whistleblower website Wikileaks began publishing on Wednesday what it said were hundreds of thousands of pager messages from the day of the September 11, 2001 attacks on New York and Washington.


Design chosen for British 1,000 mph car

Design chosen for British 1,000 mph car (w/ Video)

Technology / Engineering

created 6 hours ago | popularity 5 / 5 (2) | comments 1

(PhysOrg.com) -- A British team hoping to be the first to get a car to 1,000 mph (1,610 km/h) has made its final design selection. The six-tonne car, known as the Bloodhound, will be powered by a Eurofighter ...


EU assembly adopts Internet, phone user rights

Technology / Telecom

created 2 hours ago | popularity not rated yet | comments 0

(AP) -- The European Parliament has endorsed new telecom rules that would give phone and Internet users more rights and allow them to appeal to national courts if they are cut off for illegal file-sharing.


Taking the drudgery out of software development

Taking the drudgery out of software development

Technology / Software

created 21 hours ago | popularity 3.6 / 5 (10) | comments 8

(PhysOrg.com) -- Software developers will no longer have to reinvent the wheel when writing new programs and applications thanks to a clever new set of tools and a central repository of 'building blocks'.