

Worm infections spreading through computers, networks, pin drives are reaching in millions due to low profile security measures. In October 2008, different malicious computer programs like conficker, downadup and kido were discovered; these are the most common known malicious software attacking our computers. Antivirus firm F-secure estimated the amount of infected machines have reached the figure of 8-9 million. There has been several warning by experts about this figure that it can go far higher and they should install Microsoft MS08-067 patch and keep anti-virus software updated.
While in Interview with BBC, Graham Cluley, senior technology consultant told that the situation has never been this bad and outbreak on this scale had not been seen for quite some time. He also told that :
"Microsoft did a good job of updating people's home computers, but the virus continues to infect business who have ignored the patch update.
"A shortage of IT staff during the holiday break didn't help and rolling out a patch over a large number of computers isn't easy.
"What's more, if your users are using weak passwords - 12345, QWERTY, etc - then the virus can crack them in short order," he added.
"But as the virus can be spread with USB memory sticks, even having the Windows patch won't keep you safe. You need anti-virus software for that."
How worm spread in windows?
Microsoft has release the information about the working of worm spreading in the windows platform. First of all it searched for executable file called “services.exe” and gets embedded into it. “Services.exe” is windows file which performs important functions in windows. It then copy itself into window system folder “system32” with random file name but in extension of DLL file, it can be something like piftoc.dll etc, it normally named itself from 5 to 8 character, after naming it modifies the registry entries, listing important windows settings so that it could run infected ..DLL file as window default system file. When worm is up and running it creates HTTP server, it resets machine system restore point and starts to download files from different hacking sites and or start uploading crucial and personal information like name, password etc. Most malware uses predictable ways to download and upload files which are easy to locate and shut down. Whereas Conficker makes things way more complicated for finding and terminating its actions. According to antivirus firm F-secure this worn is programmed very complicated algorithm which in result generate hundreds of fake domain names such as abed.com,hturp.net etc. Out of which only one domain is used to download or upload data. Finding the site out of so many sites makes detection almost impossible procedure.
Alternatives
Interviewed by BBC, Kaspersky Lab's security analyst, Eddy Willems, said that a new strain of the worm was complicating matters.
"There was a new variant released less than two weeks ago and that's the one causing most of the problems," said Mr Willems
"The replication methods are quite good. It's using multiple mechanisms, including USB sticks, so if someone got an infection from one company and then takes his USB stick to another firm, it could infect that network too. It also downloads lots of content and creating new variants though this mechanism."
"Of course, the real problem is that people haven't patched their software," he mentioned.
According to Microsoft malware has infected millions of computers in almost of every parts of the world including in China, Brazil, Russia, and India having the highest number of victims.
Recommendations: We have good chances for protecting our computers by making sure that we update crucial security updates at any cost, and we use antivirus programs and keep its signature file updated for maximum protection.
Worm infections in Laptops/Notebooks
Posted by Muhammad | 9:33 AM | Computer Troubleshooting, Laptop Troubleshooting, Performance Boosting, Top Threats | 0 comments »Conficker: Protect Yourself! Win32/Conficker.C Virus Triggers April 1st, 2009
Posted by Muhammad | 10:17 AM | Antivirus, Top Threats | 2 comments »Win32/Conficker.C Virus Triggers April 1st, 2009.
Conficker, also know as Downup, Downadup and Downadup is a computer worm that exploits a known vulnerability in the Windows Server System installed in Windows 2000, XP, Server 2003, and Server 2008.
Symptoms of infection:
- Account lockout policies are automatically reset.
- Microsoft Windows Services, such as Background Intelligent Transfer Service, Windows Defender, and Error Reporting Services are automatically Disabled.
- Domain controllers respond very slowly to their client requests.
- System networks usually get congested. This can be checked by network traffic chart on the windows task manager.
- Windows systems updates cannot be accessed.
- Launches a brute force dictionary attack against administrator passwords to help it spread through ADMIN$
Experts say that this is the WORST attacker after SQL Spammer. In recent years, a range of 9 - 15 million computers across the globe were infected by this worm.
Patching and Removal
On 15 October 2008 Microsoft released a patch (MS08-067) to fix the vulnerability.[30] Removal tools are available from Microsoft,[31] BitDefender,[32] ESET, Symantec,[33] Sophos,[34] and Kaspersky Lab,[35] while McAfee and AVG can remove it with an on-demand scan.[36][37] While Microsoft has released patches for the later Windows XP Service Packs 2 and 3 and Windows 2000 SP4 and Vista, it has not released any patch for Windows XP Service Pack 1 or earlier versions (excluding Windows 2000 SP4), as the support period for these service packs has expired. Since the virus can spread via USB drives that trigger AutoRun, disabling the AutoRun feature for external media (through modifying the Windows Registry) is recommended.[38] However the United States Computer Emergency Readiness Team describe Microsoft's guidelines on disabling Autorun as being "not fully effective," and they provide their own guides.[39] Microsoft has released a removal guide for the worm via the Microsoft website.
Also, on March 16, 2009, BitDefender released an updated tool to remove the already famous Downadup/Conficker worm on a new domain that has not been blocked by the malicious computer code at a website called "bdtools.net".
Apart from the fact that the BitDefender tool removes the latest and most resilient to disinfection release of the virus, it also comes as a separate installer dedicated to network administrators. In this way, the scanner can be dispatched throughout networks in order to remotely scan and disinfect workstations.
Read More......