Conficker spreads as Waledec delivers mal-entine

By Elinor Mills, CNET News.com
Friday, January 30, 2009 10:59 AM

Security experts are tracking two computer worms that have infected millions of PCs and are creating botnets that can be awakened at any time.

More than 9 million computers have already been infected with the Conficker, or Downadup, worm that spreads via a hole on unpatched Windows machines (Microsoft issued an emergency patch to plug the hole in October), by USB devices and other removable storage devices, and can use a built-in password cracker to guess weak network passwords.

Infected machines send an alert back to a host machine, providing location and other information about the infected machine, and attempt to find other IP addresses to continue spreading. It blocks access to domains where antivirus tools are located and has other programming that makes it difficult to disinfect, Paul Ferguson, an advanced threats researcher for Trend Micro, said on Thursday.

Conficker is rated as a critical threat for Windows 2000, XP, and Windows Server 2003. But beyond spreading, Conficker so far hasn't done much--which has experts worried.

"There may be another boot that's going to drop," Ferguson said. "It's purely speculation, but to have that many PCs out there infected and not doing anything with them doesn't make sense."

And now there is another botnet surfacing from computers that are being infected with a worm called Waledac that attracts victims with a Valentine's Day-related e-mail.

The e-mail contains a link to a page with images of about a dozen hearts on it and asks "Guess which one is for you?" Once an image is clicked on the visitor is prompted to download an executable file which can install malicious code, according to a an advisory issued on Thursday by the U.S. Computer Emergency Readiness Team. The worm spreads by spamming e-mail addresses on the infected machine.

"Waledec is the new Storm," Ferguson said, referring to the prolific e-mail worm that has been cropping up since at least 2007. "The same people wrote it; it's almost identical to Storm."

In fact, there could be one group behind both Conficker and Waledec/Storm, he speculated. "My suspicions are that they are (the same creators) because there are some hints (in the coding) that indicate that it is being developed by the same organization."

This article was first published as a blog post on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Avoiding Conficker
Notice that Conficker does not affect Linux based machines, because it can't. The malware could never get the poers to run, unless the user was incautoius to the point of stupidity.

So hurry up and replace you Windows system with free Ubuntu Linux and never worry aboy security again
Posted by Charles Norrie on Tuesday, February 03 2009 03:34 AM


Tech Jobs Now!

Search for your ideal tech job:

3 lessons a CIO can learn from Windows 7

Tech Management

Microsoft's missteps with Vista, and attempts at redemption with Windows 7, offers firms valuable lessons in IT, be it in rolling out a new corporate application or delivering millions of copies of a new OS.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web