Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Conficker virus begins to attack PCs: experts

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Joanne98 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 10:47 AM
Original message
Conficker virus begins to attack PCs: experts

BOSTON (Reuters) - A malicious software program known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.

Conficker, also known as Downadup or Kido, is quietly turning thousands of personal computers into servers of e-mail spam and installing spyware, they said.

The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.

Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.

"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."

Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said.

The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.

He said the worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow.

"We expect to see a different component or a whole new twist to the way this botnet does business," said Ferguson, a member of The Conficker Working Group, an international alliance of companies fighting the worm.

Researchers had feared the network controlled by the Conficker worm might be deployed on April 1 since the worm surfaced last year because it was programed to increase communication attempts from that date.

The security industry formed the task force to fight the worm, bringing widespread attention that experts said probably scared off the criminals who command the slave computers.

The task force initially thwarted the worm using the Internet's traffic control system to block access to servers that control the slave computers.

Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC. Continued...

http://www.reuters.com/article/technologyNews/idUSTRE53N5I820090424
Printer Friendly | Permalink |  | Top
goclark Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 10:54 AM
Response to Original message
1. So what can we do?
Printer Friendly | Permalink |  | Top
 
Joanne98 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 10:57 AM
Response to Reply #1
2. I don't know. My computer just got fixed.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:02 AM
Response to Reply #1
4. Keep your security software up to date
Stay away from P2P like Limewire, don't go to the "free" porn sites and avoid all the free" game sites.
Run scans frequently, don't open suspicious email. All anyone can do is take reasonable precautions. Keep your data backed up so if you have to do a reinstall you won't lose anything.
Printer Friendly | Permalink |  | Top
 
Inspired Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:06 AM
Response to Reply #1
6. That is the question.
This is all bad and scary and all. But what is the average user supposed to do about it? I'm very confused by this whole thing.

Printer Friendly | Permalink |  | Top
 
-..__... Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:00 AM
Response to Original message
3. This is why we should always listen to the "experts"...
"weeks after being dismissed as a false alarm".

The fucking thing has been residing on millions of computers awaiting instructions to be sent on April 1st.

Just because the creators didn't carry out any sinister plans on that date doesn't mean it should have been dismissed as a "false alarm".

They simply changed the time table for activation.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:05 AM
Response to Reply #3
5. And people who didn't scan their systems have no one to blame.
Printer Friendly | Permalink |  | Top
 
stray cat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:18 AM
Response to Reply #5
9. Some viruses prevent screens or hide from them - this is one of them
Edited on Sat Apr-25-09 11:18 AM by stray cat
in fact the way to screen for it I think is to see if you can go to screening software sites. I think if you have it your computer is toast but I'm not sure. My antiviral software was up to date and it did no good.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:31 AM
Response to Reply #9
11. What were you using?
AVG detects it.
Printer Friendly | Permalink |  | Top
 
stray cat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:04 PM
Response to Reply #11
12. MacAfee - after the computer acted funny I tried to download AVG
but it would't activate any more on my computer.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:07 PM
Response to Reply #12
13. MacAfee is a hair better than Norton
but both of them, IMO, are about as useful as a screen door on a submarine.
Printer Friendly | Permalink |  | Top
 
stray cat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:34 PM
Response to Reply #13
16. Thanks for the info - love the analogy!
Edited on Sat Apr-25-09 12:43 PM by stray cat
Printer Friendly | Permalink |  | Top
 
NYC_SKP Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:35 PM
Response to Reply #16
18. Here...
Printer Friendly | Permalink |  | Top
 
HCE SuiGeneris Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:09 PM
Response to Reply #12
14. Use "Avast"
Printer Friendly | Permalink |  | Top
 
stray cat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:34 PM
Response to Reply #14
17. Thanks!
Printer Friendly | Permalink |  | Top
 
HCE SuiGeneris Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:36 PM
Response to Reply #17
19. You are quite welcome.
:hi:
Printer Friendly | Permalink |  | Top
 
Amonester Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:11 AM
Response to Original message
7. "Microsoft offers 250,000 dollars to catch Conficker worm creator"
http://www.monstersandcritics.com/tech/news/article_1459461.php/Microsoft_offers_250000_dollars_to_catch_Conficker_worm_creator_

I'd sure NOT hesitate one sec. (i wish i knew who) (or hope "one of them, silly crackers" or "one who hears them brag" needs some cash)

Printer Friendly | Permalink |  | Top
 
NYC_SKP Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:11 AM
Response to Original message
8. Use this Conficker Test. Use it! It's not a download. USE IT NOW!
I use macs, so I'm not worried, but there's a nice webpage test that every PC user should check out:

My thread on it:
http://www.democraticunderground.com/discuss/duboard.php?az=show_mesg&forum=389&topic_id=5451421&mesg_id=5451421

If you see three images below, you're probably OK:







If you don't see three images, be sure to check again at the test site:


http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

If your PC fails the test, go to the McAfee site here:

http://www.mcafee.com/us/enterprise/confickertest.html

:patriot:







Printer Friendly | Permalink |  | Top
 
HCE SuiGeneris Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 11:20 AM
Response to Reply #8
10. K & R Thanks n/t
Printer Friendly | Permalink |  | Top
 
DeepBlueC Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Apr-25-09 12:26 PM
Response to Reply #10
15. This is so useful
Thank you for continuing to put it out there. :)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun May 05th 2024, 10:57 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC