Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Forums > System Security

Vista - Prolific worm infects 3.5m Windows PCs

Reply
 
Old 01-15-2009   #1 (permalink)


Microsoft® Windows Vista™ Ultimate x64 SP2 Windows 7 7127 x64
 
 

Prolific worm infects 3.5m Windows PCs

A prolific new worm has spread to infect more than 3.5m Windows PCs, according to net security firm F-secure. The success of the Conficker (AKA Downadup) worm is explained by its use of multiple attack vectors and new social engineering ruses, designed to hoodwink the unwary into getting infected.
The worm uses a complex algorithm to develop a changing daily list of domains which infected machines attempt to establish contact with. Hackers need only register one of these possible names to establish contact with the botnet established by Conficker. The tactic is designed to frustrate attempts by security watchers to dismantle the command and control network associated with compromised machines.
But the approach also made it possible for F-secure to register a domain infected machines were due to contact and monitor what happened. Analysis by the firm, based on data from this experiment, suggests that 3.5m machines or more are under the control of unidentified hackers.

By comparison, the Storm worm was made up of somewhere between 500,000 and 1m zombie drones at its September 2007 peak, according to one recent estimate.
Conficker began circulating in late November. As well as exploiting the MS08-067 vulnerability patched by Microsoft last October, brute forces administrator passwords in an attempt to spread across machines on the same local area network. The malware also infects removable devices and network shares using a special autorun.inf file.
Analysis of the code by security watchers at the Internet Storm Centre has revealed its use of clever social engineering ruses that means users plugging an infected drive into a Windows machine might be fooled into thinking they are only opening a folder when they are actually clicking to run the worm's viral payload.
Security experts suggest that users may want to disable Autorun, or even prohibit the use of USB devices, as a precaution. ®

Prolific worm infects 3.5m Windows PCs • The Register

My System SpecsSystem Spec
Old 01-19-2009   #2 (permalink)


Vista Home Premium 32-bit & Vista Ultimate 64-bit both Service Pack 2 W7 Pro RTM 7600 32 & 64
 
 

Re: Prolific worm infects 3.5m Windows PCs

More information on this can be found here: BBC NEWS | Technology | Windows worm numbers 'skyrocket'
My System SpecsSystem Spec
Old 01-22-2009   #3 (permalink)


Vista Home Premium 32bit
 
 

Re: Prolific worm infects 3.5m Windows PCs

Hi there.

Thanks a lot echrada for this detailed description.

Regarding conficker or however you call that little bugger, assuming a user using not the admin account, but just a user account with no admin rights (as it should be) falls for the trick you described and runs conficker in the autostart menu, is conficker blocked by the UAC of Vista to prevent conficker of doing whatever it wants to do? I read some infos that conficker is writing something in the registry as well as in the system32 folder and will download code after the next install onto the system, but can it do so without the admin access?

I have tried to get this information searching like for 2 hours now in the news and some forums. Of course it could be that I am just really stupid (I admit this is not totally unlikely) and I have overlooked this little detail in the news.

Thanks a lot for your answers!


Elsevier
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Prolific USB-to Serial help Drivers
Prolific PL2303 driver Drivers
worm? Vista performance & maintenance
Windows Live Messenger worm Live Messenger
Vista photo gallery infects files, Trend Micro says Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46