SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Conficker.E self-destructs but other variants remain

Conficker.E self-destructs but other variants remain

By:  Howard Solomon and Ellen Messmer  On: 06 May 2009 For: Network World Canada Creator

An F-Secure security expert said if your computer was rebooted May 3 or later, you would no longer have Conficker.E. Find out why Conficker.C could still be a threat

The evolution of the multi-faceted Conficker worm took another turn this month when the latest version, Conficker.E, erased itself on infected machines.

Several vendors noted Conficker.E – first spotted in April and probably created by the same attackers that since last fall let loose the Conficker.A through Conficker.C variants – was designed to simply self-destruct on May 3rd.

On Wednesday, that was confirmed by Patrik Runald, chief security advisor at F-Secure.

“If your computer was rebooted on May 3 or later you would no longer have Conficker.E,” he said.

“However, considering that Conficker.E was mostly downloaded through already infected Conficker.C machines, Conficker.C will remain on the PCs and any other malware that has been downloaded [with it] will remain as well.”

It is believed millions of Windows-based computers around the world are infected with Conficker.C, which tries to lure victims to fake anti-virus sites – some dub it “fraudware” – and get victims to pay US$50 or so to get rid of the infection.

“We’re starting to see some revenue generation,” said Phillip Porras, program director in the computer sciences laboratory at SRI International, in a presentation at the recent RSA Conference concerning Conficker. “We’re starting to see some business models come out of it.” Security researchers in industry and government are using various means to monitor Conficker.C behavior (which can block over 114 legitimate anti-virus sites and now works in conjunction with the botnet Waledec).

Porras said Conficker.C is involved in an elaborate process to sell fake anti-malware software. When it gets into infected machines, it can direct victims toward Web sites believed to be selling fraudware.

One of those sites appears to be registered in the Ukraine selling the SpywareProtect portfolio, associated with “Ukraine Bastion Trade Group,” for example, he said. But Conficker was not necessarily created by this group and researchers are still in the dark about who originates and controls the complex Conficker command-and-control system. Despite the efforts of the Conficker Working Group, a group which now has 300 experts from industry and government dedicated to do what they can to identify the source of Conficker and stop it, efforts so far have not been successful.


Sign up for our Newsletters
Tags:












Print |  Views: 2078   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Howard Solomon and Ellen Messmer Howard Solomon and Ellen Messmer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.