Showing posts with label conficker worm. Show all posts
Showing posts with label conficker worm. Show all posts

Sunday, February 15, 2009

MICROSOFT ANNOUNCES REWARD FOR FINDING THE CULPRIT BEHIND THE DOWNADUP/CONFICKER VIRUS

Microsoft has announced a reward of $250,000 (£172,000) to find out who is behind the notorious Downadup/Conficker virus.Since it started circulating in October 2008 the Conficker worm has managed to infect millions of computers worldwide.
Do you remember the Sasser worm that created chaos in the year 2003? Microsoft then created its reward programme with $5m (£3.4m) in funding to help law enforcement agencies bring computer virus and worm authors to justice. In 2005 Microsoft paid out $250,000 (£171,000) to two individuals who helped identify the creator of the notorious Sasser worm. The author was arrested and sentenced by the German authorities.But the sheer pricing of this reward says about the danger about Conficker.

The software giant is offering the cash reward because it views the Conficker worm as a criminal attack.According to George Stathakopulos of Microsoft "the company was not prepared to sit back and let this kind of activity go unchecked.Our message is very clear - whoever wrote this caused significant pain to our customers and we are sending a message that we will do everything we can to help with your arrest," said Mr Stathakopulos.Arbor Networks said as many as 12 million computers could be affected globally by Conficker/Downadup since it began prowling the web looking for vulnerable machines to infect in October.

We at Technosquare have previously revealed about the waht and how of conficker virus which can be seen in this link http://technosquare.blogspot.com/2009/01/conficker-virus-threat-for-wndows-vista.html

Although Downadup is widespread its creators have yet to activate its payload to steal data or launch other attacks.It has caused costly headaches for network administrators dealing with users locked out of their accounts when the worm correctly guesses a password.While Microsoft says it does not know the intention of the worm's creator, it wants to ensure it does not wreak any more havoc.Keeping your antivirus software updated and frequent windows patching like KB958644 is the only option available as of now.

Microsoft has also partnered with security companies, domain name providers, academia, internet companies such as AOL and others on a co-ordinated global response to the worm. Also included is the US Department of Justice and the Department of Homeland Security."The best way to defeat potential botnets like Conficker/Downadup is by the security and Domain Name System communities working together," said Greg Rattray, chief internet security adviser at the Internet Corporation for Assigned Names and Numbers (Icann).

But the real nail in the coffin is although rewards of over $250,000 were offered to find the culprits behind the Blaster, MyDoom and Sobig worms the perpetraitors are yet to be arrested!

Thursday, January 22, 2009

CONFICKER VIRUS THREAT FOR WNDOWS VISTA AND WINDOWS 7: SECURITY EXPERTS PUZZLED

So you think that you have the latest security software to keep your pc or mac safe?well think again.The Conficker virus has opened a new can of worms for security experts , as low security networks, memory sticks, and PCs without current security updates are in grave danger of being severly damaged by the conflicker virus also known to be Downadup or Kido and was first discovered in October 2008.

Portable storage drives such as USB sticks infected with the virus trick users into installing the worm. According to security experts, a ‘social engineering trick’, which exploits the way humans think and act is said to be the biggest challenge that this virus puts before us. Even though the bogus option is marked as being in the category ‘Install or run program’, many users will see the familiar ‘Open folder to view files’ wording and icon that they click on it without thinking.

The "Autoplay" function in Vista and early versions of Windows 7 automatically searches for programs on removable drives.However, the virus hijacks this process, masquerading as a folder to be opened. When clicked, the worm installs itself.


How does the worm work? - Method of infection

Microsoft says that the worm works by searching for a Windows executable file called "services.exe" and then becomes part of that code.It then copies itself into the Windows system folder %Sysdir% as a random file of a type known as a "dll". It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.

The virus attempts connections to one or more of the websites such as getmyip.org ,getmyip.co.uk ,checkip.dyndns.org to obtain the public ip address of the affected computer.As soon as the worm is up and running, it creates a HTTP server and then resets a machine's System Restore point (very hard to recover) and then downloads files from the hacker's web site.Later variants of w32/Confickerworm are using scheduled tasks and Autorun.inf file to replicate on to non vulnerable systems or to reinfect previously infected systems after they have been cleaned.

How does Conficker differ from other virus/worms?

Most malware download files from easily detectable malicious or attack sites, making them fairly easy to spot, and immediately shut down the file download.But the worm uses a complicated algorithm based on timestamps from websites such as google.com to generate hundreds of different domain names every day. Only one of these will actually be the site used to download the hackers' files,making it extremely difficult to trace the target site .

Impact and damage caused by the worm so far

It is estimated that a whopping 9.5m PCs are infected with this virus. Once the Conficker worm is executed in a pc, the downadup virus disables essential security services such as windows automatic updates,security center, defender and error reporting to name a few.Along with downloading and installing malware on your computer and gathering your personal data, the conflcker adheres or sticks itself to key windows processes like svchost.exe, explorer.exe.


Removal

It is of paramount that one should turn off autorun and autoplay features in your pcs to prevent the worm from gaining a foothold onto your syatem.Windows users are urged to download the KB958644 Security Update from Microsoft to mitigate the risk of infection.

Microsoft's amlicious software removal tool (KB890830) and f-secure malware removal tool are some of the software that are available to keep conficker at bay.Keeping your antivirus software updated regularly to keep track of the constantly evolving virus definitions is a good preventive measure that would go a long way to ensure safety to your pc.As they say' better safe than sorry'.