Conficker worm digs in around the world

April 1, 2009 by Glenn Chapman A New York computer user

Enlarge

A New York computer user. Computer security top guns around the world watched warily as the dreaded Conficker worm squirmed deeper into infected machines with the arrival of an April 1st trigger date

Computer security top guns around the world watched warily as the dreaded Conficker worm squirmed deeper into infected machines with the arrival of an April 1st trigger date.

The evolved, as expected, from East to West, beginning in time zones first to greet April Fool's Day.

"Planes are not going to fall out of the sky and the Internet is not going to melt down," said threat analyst Paul Ferguson of Trend Micro computer in Northern California.

"The big mystery is what those behind Conficker are going to do. When they have this many machines under their control it is kind of scary. With a click of a mouse they could get thousands of machines to do whatever they want."

A task force assembled by Microsoft has been working to stamp out the worm, referred to as Conficker or DownAdUP, and the US software colossus has placed a bounty of 250,000 dollars on the heads of those responsible for the threat.

The worm was programmed to modify itself on Wednesday to become harder to stop and began doing that when infected machines got cues, some from websites with Greenwich Mean Time and others based on local clocks.

Conficker task force members tracking Internet traffic in Asia and Europe after clocks struck April 1st there said there was no sign that the worm was doing anything other than modifying itself to be harder to exterminate.

Conficker had been programmed to reach out to 250 websites daily to download commands from its masters, they said, but on Wednesday it began generating daily lists of 50,000 websites and reaching randomly to 500 of those.

The hackers behind the worm have yet to give it any specific orders. An estimated one to two million computers worldwide are infected with Conficker.

Computer security specialists warn that the Conficker threat will remain even if April 1st passes without it causing trouble.

"It doesn't seem to be doing anything right now," Ferguson said as Conficker made its way to the western United States.

"I hope April 1st comes and goes with no trouble. But, there is this loaded pistol looming large out there even if no one has pulled the trigger."

The FBI said Tuesday it is working with the Department of Homeland Security and other US agencies to "identify and mitigate" the Conficker threat.

"The public is once again reminded to employ strong security measures on their computers," FBI Cyber Division assistant director Shawn Henry said in a release.

"That includes the installation of the latest anti-virus software and having a firewall in place...Opening, responding to, or clicking on attachments contained in unsolicited e-mail is particularly harmful and should be avoided."

The worm, a self-replicating program, takes advantage of networks or computers that haven't kept up to date with security patches for Windows RPC Server Service.

It can infect machines from the Internet or by hiding on USB memory sticks carrying data from one computer to another.

Malware could be triggered to steal data or turn control of infected computers over to hackers amassing "zombie" machines into "botnet" armies.

Microsoft has modified its free Malicious Software Removal Tool to detect and get rid of Conficker.

The infection rate has slowed from a fierce pace earlier this year, but computers that are not updated with a software patch released by Microsoft remain vulnerable, according to security specialists.

Conficker was first detected in November 2008.

Among the ways one can tell if their machine is infected is that the worm will block efforts to connect with websites of security firms such as Trend Micro or Symantec where there are online tools for removing the virus.

Cyber-criminals have taken advantage of Conficker hype by using promises of information or cures to lure Internet users to websites booby-trapped with malicious software.

(c) 2009 AFP


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3 /5 (2 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • Egnite - Apr 01, 2009
    • Rank: 1 / 5 (1)
    Yeah like I'm gonna buy the latest useless version of some virus checker because some 'computer security top gun' tells me too. "We've made a super virus, u best buy our product or we'll make your computer a zombie". Yeah yeah whatever, I'll just continue using my computer safely and avoid "dangers".

    "Cyber-criminals have taken advantage of Conficker hype by using promises of information or cures to lure Internet users to websites booby-trapped with malicious software."

    Only noobs and tards fall for that shit :-P
  • Doug_Huffman - Apr 01, 2009
    • Rank: 5 / 5 (1)
    Kind'a like Sarah Brady's sockpuppet Helmke and the NRA, they're each other's worst enemy and best boogerman, "Send us money or he'll get you!"

April 1, 2009 all stories

Comments: 2

3 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • New homeland security tool to detect Conficker worm
    created Mar 30, 2009 | popularity not rated yet | comments 0
  • Conficker Worm Prepares For A New Release On April 1
    created Mar 27, 2009 | popularity not rated yet | comments 0
  • Don't fret about Conficker: Here's what to do
    created Mar 31, 2009 | popularity not rated yet | comments 0
  • Help! How to avoid fast-moving computer worm
    created Jan 28, 2009 | popularity not rated yet | comments 0
  • The Raging Windows Worm has attacked over 8.9 Million Computers
    created Jan 19, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • transient heat transfer
    created Nov 23, 2009
  • Trying to adapt a fuel gage circuit
    created Nov 22, 2009
  • Pushing the piston.
    created Nov 22, 2009
  • More from Physics Forums - General Engineering

Other News

ORNL 'deep retrofits' can cut home energy bills in half

ORNL 'deep retrofits' can cut home energy bills in half

Technology / Energy

created 8 minutes ago | popularity not rated yet | comments 0

(PhysOrg.com) -- Oak Ridge National Laboratory has announced plans to conduct a series of deep energy retrofit research projects with the potential to improve the energy efficiency in selected homes by as ...


Time Warner Cable asks help on rising program fees

Technology / Business

created 10 minutes ago | popularity not rated yet | comments 0

(AP) -- Time Warner Cable Inc. is asking the public for help as it tries to curtail increases in the programming fees it has to pay to carry cable channels and broadcast stations on its systems.


Design chosen for British 1,000 mph car

Design chosen for British 1,000 mph car (w/ Video)

Technology / Engineering

created 8 hours ago | popularity 4 / 5 (4) | comments 3

(PhysOrg.com) -- A British team hoping to be the first to get a car to 1,000 mph (1,610 km/h) has made its final design selection. The six-tonne car, known as the Bloodhound, will be powered by a Eurofighter ...


US online ad revenue down 5.4 pct in third quarter

Technology / Internet

created 2 hours ago | popularity not rated yet | comments 0

(AP) -- Online advertising revenue in the U.S. fell 5.4 percent in the third quarter from a year ago, as the sputtering economy kept its tight grip on even the fastest growing segment of industry, according to a report released ...


Taking the drudgery out of software development

Taking the drudgery out of software development

Technology / Software

created 23 hours ago | popularity 3.6 / 5 (10) | comments 12

(PhysOrg.com) -- Software developers will no longer have to reinvent the wheel when writing new programs and applications thanks to a clever new set of tools and a central repository of 'building blocks'.