Press Releases

Conficker worm begins stealthy update

   Share        

Apr 16th, 2009

The Conficker worm, present on millions of PCs around the world, has started to update infected machines with a mystery package of data.
Computer security firms watching the malicious program noticed that it sprang into life on 8 April.
The activity on its update system delivered encrypted software to compromised machines. It is not yet clear what the payload contains.

The updating activity has begun about a week later than expected. Analysis of the "C" variant of Conficker (aka Downadup) revealed that its updating mechanism was due to go live on 1 April.
The belated updates were spotted by researchers for Trend Micro following the arrival of a new file in one of the directories in so-called "honeypot" machines deliberately seeded with Conficker C.

Analysis showed that the file had arrived via the peer-to-peer file transfer system that infected machines use to communicate.

In a bid to avoid alerting people to its activity, the update is slowly being trickled across the population of machines harbouring the C variant. Exact figures for the number of Conficker-infected machines are hard to determine, but the minimum is widely believed to be three million.

"The Conficker/Downad P2P communications is now running in full swing," wrote Ivan Macalintal from Trend Research on the company's security blog.

Once it arrives on a machine, the package of data randomly checks one of five different websites - MySpace, MSN, eBay, CNN and AOL - to ensure its host still has net access and to confirm the current time and date.

Following this check the data package removes all traces of its installation.

The strong encryption on the payload has, so far, prevented detailed analysis of what it actually does. However, security experts speculate that it is a "rootkit" that will bury itself deep in Windows in order to steal saleable data such as bank website login details.

Visitor Comments
There are no comments to this article yet.
Be the first to add a comment...
Add your Comment
Before you are able to 'add your comment'
you need to login into your 2SPACE® PASSPORT.
If you don't have a 2SPACE® PASSPORT you
can create one for free.
Go to 2SPACE PASSPORT

Support us

Follow 2Space.net on twitter

Join 2Space on Facebook

Also Visit...

How to start internet advertising ?
Find the most pupular links to all your advertising questions

Search Engine Marketing
All famous links about Search Engine Marketing

Madonna : News Images
Madonna : News and images about Madonna. Web syndication possibilities

Submit-your-website.com
Website marketing, tools and tricks. Start promoting your website, today!

Ecademy: Connecting Business People
Successful people grow their business on Ecademy - Social Business Network

All Popular Downloads
Find all popular downloads. Freeware and Shareware.

Add Your link Only US$ 4,-