SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Downadup’s calm before the storm

Downadup’s calm before the storm

By:  Kathleen Lau  On: 22 Jan 2009 For: ComputerWorld Canada Creator

One security expert said Downadup/Conficker is merely “dormant”, probably undergoing a test run before being unleashed at full force. What IT managers should be scouring for on the networks

The Downadup worm may have already created havoc with the estimated nine million PCs it’s infected, but one security expert warns the worm is only dormant, perhaps to be unleashed at a later date with an even greater vengeance.

Jason Miller, manager of security and data at St. Paul, Minn.-based security technology vendor Shavlik Technologies LLC, said Downadup (also referred to as Conficker) may well be undergoing a test run, during which its makers are learning of what works best.

If that’s the case, there’s a more malicious version in store for everyone, predicts Miller. “It’s a blessing in disguise,” he said, and organizations and individual users can take advantage of this lull to ensure their systems are secure. “This worm is not going to go away.”

Nor does Miller think the estimate of infected PCs at nine million by Finland-based security firm F-Secure Corp. is a mere scare tactic. “Whoever wrote this virus has a lot of information tucked in their head,” he said, referring to the sophisticated techniques employed by Downadup.

 

Shane Schick's ComputerWorld

The Conficker Conflagration

There’s a complexity with this one, said Miller, that’s replacing a virus or worm’s usual one-dimensional approach, which is either to set up spam or download an application on a victim PC. Upon closer inspection, Downadup assumes a multi-vector strategy employing brand new techniques not previously seen “and they’re pretty scary,” he said.

 

Among those, the worm takes advantage of a previous file-sharing vulnerability in Microsoft Windows Server, and also proliferates itself by infecting USB devices.

Users of Windows 2000, Windows XP and Windows Server 2003 systems are most at risk, according to Microsoft Corp., which last October released a patch, MS08-067, intended to protect systems from Downadup, and has also advised users to download the Malicious Software Removal Tool (MSRT), updated last week to detect and remove the worm.

Organizations should scour their network for all physical and virtual machines that exist, such as the one “buried in the basement somewhere,” said Miller. “Look for those systems that you can’t find. Don’t worry about the main PCs and the servers on the floor. All it takes is one.”


Sign up for our Newsletters












Print |  Views: 1217   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Related Content

Worms spur new protection methods
Worms spur new protection methods In light of myriad malicious code crawling across the Web, security software vendors are devising new methods to protect PCs. But industry observers say the problem won’t be solved by technology alone.
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof

Comments (1)

Beat Downadup/Conficker like a pro
by Extremesecurity 1/26/2009 12:00:00 AMDid Downadup/conficker attack your network? I've created a batch file for system administrators to clean/patch/cure infected systems in their networks. check it out here: http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.