Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts

Monday, March 30, 2009

Conficker worm on it's way



I was reading a story this morning from Yahoo about the Conficker worm that comes out every year on April 1st. The first Conficker worm was sent out in 2008 and infected over 9 million computers. Now it's on its third version, Conficker C, and is "incredibly complicated, powerful, and virulent".

Microsoft has offered a quarter million dollar bounty on the writer of the worm and are trying to find a solution before April 1st gets here. They say:

"What's known so far is that on April 1, all infected computers will come under the control of a master machine located somewhere across the web, at which point anything's possible. Will the zombie machines become denial of service attack pawns, steal personal information, wipe hard drives, or simply manifest more traditional malware pop-ups and extortion-like come-ons designed to sell you phony security software? No one knows.

Conficker is clever in the way it hides its tracks because it uses an enormous number of URLs to communicate with HQ. The first version of Conficker used just 250 addresses each day -- which security researchers and ICANN simply bought and/or disabled -- but Conficker C will up the ante to 50,000 addresses a day when it goes active, a number which simply can't be tracked and disabled by hand.

At this point, you should be extra vigilant about protecting your PC: Patch Windows completely through Windows Update and update your anti-malware software as well. Make sure your antivirus software is actually running too, as Conficker may have disabled it.

Microsoft also offers a free online safety scan here, which should be able to detect all Conficker versions."

And from the Windows Live OneCare website:

How do I know if my computer is infected?

System Changes
The following system changes may indicate the presence of this malware:

  • The following services are disabled or fail to run:
  • Windows Update Service
    Background Intelligent Transfer Service
    Windows Defender
    Windows Error Reporting Services
  • Some accounts may be locked out due to the following registry modification, which may flood the network with connections:
  • HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    "TcpNumConnections" = "0x00FFFFFE"
  • Users may not be able to connect to websites or online services that contain the following strings:
  • virus
    spyware
    malware
    rootkit
    defender
    microsoft
    symantec
    norton
    mcafee
    trendmicro
    sophos
    panda
    etrust
    networkassociates
    computerassociates
    f-secure
    kaspersky
    jotti
    f-prot
    nod32
    eset
    grisoft
    drweb
    centralcommand
    ahnlab
    esafe
    avast
    avira
    quickheal
    comodo
    clamav
    ewido
    fortinet
    gdata
    hacksoft
    hauri
    ikarus
    k7computing
    norman
    pctools
    prevx
    rising
    securecomputing
    sunbelt
    emsisoft
    arcabit
    cpsecure
    spamhaus
    castlecops
    threatexpert
    wilderssecurity
    windowsupdate

So I thought, well, I'm safe, I have McAfee...I have Spyzooka...I automatically update and have my firewall and Windows Defender set up to run automatically...I'm good right?

Then I looked in my system tray and NOTHING WAS THERE! Windows Defender had been turned off; McAfee off; Spyzooka off. Ack! I immediately stopped what I was doing and ran every kind of scan I have. I found several viruses.

I'm glad I came across the story and checked into my own PC. I hope y'all check yours too. This could be bad, bad, bad.


Saturday, March 7, 2009

Oh Facebook, why?



Let me first start out by saying I obviously can't read a calendar. TODAY is the Saturday to change your clocks, not the 14th like I told you in yesterday's post, Change. I changed it though. :)

Now on to Facebook. The social networking program has seen five different security threats in the past week.

These hoax applications attempt to trick Facebook members into divulging their usernames and passwords. And there is a worm running rampant on the site, installing malware on the computers of victims who click on a link to a fake YouTube video. It's called the Koobface worm.

According to a Yahoo news story, the Koobface worm searches for cookies on your computer, then makes a DNS query to check IP addresses that correspond to remote domains. They can then send and receive information about the affected machine. Once connected, they can remotely perform commands on the victim's machine.

Then the Koobface worm composes a message and sends it to the user's friends. The message contains a link to a website where a copy of the worm can be downloaded by unsuspecting friends. And the cycle repeats itself.

How crazy is that? Some people just have too much time on their hands. Combine that with a malicious attitude and you have trouble. Trouble for you. And trouble for your PC. My advice? Don't play on Facebook... No. I'm just kidding. Just be careful about how you play and pay attention. If something doesn't look right, get out of there. Never enter your password unless it's the normal log in screen. There is no place, no application, no "extra" on Facebook that requires you to reenter your username and password. I promise. I'm there all the time.

As far as the fake YouTube video link, don't click on any links unless you are 100% positive about where they originated. My PC is loaded down with anti-spyware programs that won't allow me to visit links until they've been scanned and approved. It definitely slows my computer down but, to me, it's better to be safe than sorry. Today's news reaffirmed that.