Content

Showing posts with label conficker. Show all posts
Showing posts with label conficker. Show all posts

Conficker Virus Started Sending Spam From Infected PCs

0 comments
ONE of the world's biggest computer worms has activated and is now sending spam from personal computers.

The malicious software known as Conficker is slowly starting weeks after being dismissed as a false alarm, security experts said.

Conficker, also known as Downadup or Kido, is quietly turning thousands of PCs into servers of email spam and installing spyware, they said.

The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote machine that controls an army of computers known as a botnet.

Many feared it would wreak havoc on April 1, but instead the worm mutated to make it harder to catch.

Its unidentified creators started using infected machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response.

"Expect this to be long-term, slowly changing," he said. "It's not going to be fast, aggressive."



What the worm does ?

Conficker installs a second virus, known as Waledac, that sends out email spam without knowledge of the PC's owner, Mr Weafer said.

It also installs a fake anti-spyware program so users would be led to believe their computer's safe.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7. The worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow.

"We expect to see a different component or a whole new twist to the way this botnet does business," said Mr Ferguson.

Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.

The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.



What you can do ? 

First of all, make sure your PC has the latest patch from Microsoft and update your security software. If you cannot access your anti-virus maker's website, your PC may already be infected.

In general, you should always be careful when clicking on unknown links. Use LinkScanner to find out if a link leads to dangerous content, and be wary of pop-up windows prompting you to install software such as antivirus or video player updates.

You may also read the US Department of Homeland Security's recommendations at www.dhs.gov, or find out more on Wikipedia


Visit 13above For More Fun

Read more »

Largest Virus Threat Awaited (9 Million +)

0 comments
MILLIONS of computers around the world could go into meltdown on April 1 because of a deadly virus.

The Windows worm called Conficker could give a hacker unrestricted access to every infected machine on the planet.

And the aggressive bug could be hiding on your PC at home right now, waiting to kick in.

For the hackers, it’s like having a virtual army at their fingertips.

The criminals behind it have the power to launch a tidal wave of junk emails, bringing computers grinding to a halt.

They could also plunder information, including your bank details.

But the truth is that the best techie brains in the business just don’t know exactly what the hackers have in mind.

Infected:

Virus expert Mikko Hypponen, from the firm F-Secure, said: “It is scary thinking about how much control a hacker could have over all these computers. They would have access to millions of machines.”

Microsoft, who developed the Windows computer operating system, have slapped a £175,000 bounty on whoever is responsible, so far without success.

The sophisticated Conficker bug — also known as Downadup or Kido — targets systems via the web and can be spread on memory sticks.

More than nine million computers were infected at the bug’s peak last month.

And if Conficker is still on your system come Wednesday, you could be in trouble.

Once inside your PC, it sets up files and starts downloading information from a controlling “boss” server.

Finding that website and the mastermind behind it all is like looking for a needle in a haystack.

That is because the bug creates hundreds of bogus addresses every day to put investigators off the scent.

The infected PCs then form a network and “talk” to each other, updating and evolving.

The bug even attacks anti-virus software and other files on your computer to strengthen its position.

And it resets “restore” points, making recovery of your old system even harder.

The first of three Conficker strains was discovered in November last year.

A second, more aggressive strain followed in December and a third this month. This contains the all-important April 1 trigger.

Trigger :

To avoid infection, Windows users must download a special free update “patch” from the Microsoft website. But that isn’t enough — you also need good anti-virus software too.

Many businesses around the world are thought also to be at risk after failing to update systems.

Graham Cluley, from computer security firm Sophos, warned: “Microsoft did a good job of updating people’s home computers.

“But the virus continues to infect businesses that have ignored the update.”

He also stressed the need for strong passwords on your computer, adding: “If users are using weak passwords — 12345, QWERTY etc — then the virus can crack them.”

F-Secure’s Mikko warned potential problems with Conficker would be highlighted wildly before April 1.

But he said he didn’t foresee an attack, despite the fears and mystery surrounding the problem.

He said: “There’s always hype — just think of previous cases.

“There is not going to be a ‘global virus attack’. We don’t know what they are planning to do, if anything.

“I think the machines that are already infected might do something new on April 1.”

Let’s hope, for everyone’s sake, that it turns out to be an April Fools’ Day hoax.


TEST your system’s safety for free by attempting to go to f-secure.com. If you can’t, you can download the patch at microsoft.com to disinfect your PC.



Read more »

Top 10 Biggest Computer Viruses Ever

0 comments
Jerusalem (1987) ... one of the earliest and most successful viruses activated each year on Friday the 13th — either displaying a message or deleting any programs that ran on the day. The virus, dubbed Jerusalem, installed itself in the target computer's memory when an infected file was opened.

Early versions of Jerusalem — one instance of which was found in a military office in Israel — repeatedly infected files until the computer became overwhelmed by their size. It remained active throughout the 1990s, infecting many computers in enterprises and government offices and becoming a popular template for future viruses due to its simple code.

Stoned (1987) ... old viruses never die — that was the warning from anti-virus experts after the Stoned virus resurfaced in 2007, a full 13 years after it was written. The Stoned — or Marijuana — virus became widespread in the early 1990s. It was the most successful virus in terms of number of infections, infiltrating hard drives and the boot sector of floppy disks.

The most common effect of Stoned was to display a message on the screen when the computer started up that read: "Your PC is now stoned. Legalise marijuana." There are more than 90 variants of the virus — and last year it resurfaced to infect a number of laptops running Microsoft Windows after anti-virus programs detected the virus but failed to remove it.

Tequila (1991) ... one of the first widespread viruses to use stealth techniques in order to avoid detection, Tequila was particularly dangerous as it couldn't be removed from the infected computer's memory.

Tequila infected computers by writing an unencrypted copy of itself to sectors of the system hard disk and modifying the master boot record. It used a scrambling method to avoid disassembly, changing itself from one infection to the next.

Michelangelo (1991) ... the Michelangelo virus sparked a media frenzy in 1992, one year after its discovery. After spreading quietly for months, the virus activated on March 6, 1991 — the birth date of its namesake — destroying data on tens of thousands of computers by overwriting parts of the hard disk with random data.

In the weeks before March 6, 1992, the Michelangelo virus became a major news event with constant warnings about its destructive potential. The media coverage descended into hysteria with predictions Michelangelo would wipe out millions of computers. However when March 6 finally arrived only around 10,000 computers were infected, and anti-virus companies were accused of creating hype about the virus to increase sales.

ILOVEYOU (2000) ... as the internet became more popular virus creators turned to programs such as worms — pieces of malicious code that, unlike viruses, are not attached to a "host" file and can reproduce themselves.

The most destructive worm of all time was ILOVEYOU, also known as LoveLetter, which spread by email and disguised itself as a romantic message to the recipient. If opened, it would send itself to everyone in the user's address book, clogging email systems around the world.

ILOVEYOU reached up to 45 million people in one day, causing more than $5 billion of damage with large corporations including the Pentagon and British Parliament forced to shut down their email systems.

Monopoly (2000) ... working in a similar way to ILOVEYOU, the Monopoly worm sent itself by email boasting "proof" that Microsoft boss Bill Gates was guilty of monopoly. At the time, Microsoft was immersed in a legal battle over its attempts to bundle Internet Explorer with its Windows operating system which led to accusations of abusing monopoly power.

The worm was delivered through an attachment called "Monopoly.vbs" that, when opened, displayed an humorous image of Bill Gates on a Monopoly game board. It then attempted to mass-mail itself to all of the user's Outlook contacts.

AnnaKournikova (2001) ... more a nuisance than a threat, this worm masqueraded as a picture of tennis star Anna Kournikova and relied on the public's fondness for the blonde pin-up in order to spread itself.

AnnaKournikova was short-lived and spread via Outlook email with the subject line "Here you have, ;o)", with an attachment called AnnaKournikova.jpg.vbs. Once opened, the worm copied itself to the Windows directory and sent the file to all contacts in the user's Outlook address book.

AnnaKournikova scourged numerous Australian Federal Government Departments and large companies, with some receiving thousands of emails per hour. The worm's creator said he wanted to pay homage to Anna Kournikova as she "deserves some attention". He succeeded spectacularly.

Nimda (2001) ... before Nimda, worms were spread simply by copying or emailing themselves. Nimda used this method but also moved via server-to-server web traffic, infecting shared network hard drives and downloading itself to users who were browsing websites hosted on infected servers.

The result was hundreds of thousands of infections on servers and home computers and a slowdown in internet traffic as Nimda searched for vulnerable servers to attack. Some media reports suggested there may be a link between the virus and Al-Qaeda, as the worm was released in September 2001 — though this was proven to be false .

Sasser (2004) ... a German teenager boasted about becoming the hero of his class after writing the potent Sasser worm that could spread without user intervention. Sasser exploited a operating system flaw, prompting some computers using Windows XP and Windows 2000 systems to continually crash and reboot. However it was easily stopped by a well-configured firewall or by Windows Update downloads.

Sasser caused disruption worldwide, halting Australia's Railcorp trains as operators couldn't communicate with signalmen and forcing the cancellation of 40 Delta Air Lines trans-Atlantic flights. Over 400 post office branches in Taiwan had to revert to using pen and paper after more than a thousand of its machines were hit by the virus.

Storm (2007) ... the worst virus to hit computers in recent times, Storm is classed as a "superworm". It has become well-known for the way it constantly morphs into new forms and finds ways to exploit people's weaknesses. In 2007 it infected thousands of computers by masquerading as an email about a weather disaster, and then mutated and spread with another fake attachment infecting 10 million computers.

Storm continues to infect unsuspecting users today, with subject lines focusing on a range of topics from Facebook to love interests. Recent versions can disguise themselves from virus scans and even shut down security programs. A warning has been issued about emails claiming the Beijing Olympics will be delayed or cancelled due to earthquake damage, which appear to contain a link to a video but in fact are the Storm worm in disguise.



Visit 13above For More Fun
Read more »
My Ping in TotalPing.com My Zimbio