Forum Home
PC World Chat
 
Thread ID: 98606 2009-03-31 02:12:00 Downadup SurferJoe46 (51) PC World Chat
Post ID Timestamp Content User
760915 2009-03-31 02:12:00 (US) Homeland Security Keeps Tabs On Conficker Worm


The agency's US-CERT team created worm-scanning software for federal and state government agencies, commercial vendors, and critical infrastructure owners.

As computer security firms play down the risk posed by the Conficker/Downadup worm, the Department of Homeland Security on Monday released a DHS-developed detection tool to help organizations scan for computers infected by the worm.

The DHS US-CERT team created worm-scanning software for federal and state government agencies, commercial vendors, and critical infrastructure owners. It's being made available through the Government Forum of Incident Response and Security Teams Portal and to private-sector partners through various Information Sharing and Analysis Centers.

DHS expects to continue its outreach efforts in the days to come.

US-CERT director Mischel Kwon said in a statement that while other worm-mitigation tools are available, this is the only free tool available for enterprises like government agencies.

"Our experts at US-CERT are working around the clock to increase our capabilities to address the cyber risk to our nation's critical networks and systems, both from this threat and all others," he said.

Last week, Luis Corrons, director of PandaLabs, urged Internet users not to panic, as did representatives from other security companies, many of which offer worm-mitigation tools for consumers.

But some may panic anyway and a malware group is ready to take their money. F-Secure reports that the domain remove-conficker.org was registered on Monday to sell fake security software.

The Conficker/Downadup worm attempts to exploit a Microsoft Windows vulnerability that was patched (MS08-067) last October. Since then, it has been updated several times. Now in its fourth iteration, it has developed multiple avenues of infection, including USB devices. It also uses a variety of sophisticated techniques to evade detection and to maintain its command-and-control channel, including a pseudo-random algorithm for generating the domains it uses to receive commands.

The worm is supposed to get a code update on April 1 that may make it harder to disrupt. Infected machines previously polled 250 domains daily to see whether to execute new commands. Security researchers who have analyzed the worm's code believe that on Wednesday infected machines will start scanning 500 out of 50,000 domains for update information.

It's not clear whether this will cause the botnet created by the worm to take action. Until now, the botnet has been dormant.

Somewhere between 1 million and 2 million computers are actively infected, according to F-Secure. At the worm's peak, almost 9 million computers were infected.
SurferJoe46 (51)
760916 2009-03-31 03:14:00 BitDefender have a Firefox add-in available. Unfortunately, it's in beta still, and when I tried to restart Firefox after doing the scan, FF kept crashing. Had to disable "BitDefender QuickScanner" before FF would work again. Use with caution... johcar (6283)
760917 2009-03-31 03:33:00 Just spend the last two days fighting off an outbreak of this.

Made a point of telling Head Office what a great job Symantec Endpoint/NAVCE did of keeping it out in the first place!! :p
nofam (9009)
760918 2009-03-31 04:14:00 You can get the Bitdefender removal tool here. I ran the gui windows version for a single PC on each of my PCsand it said they were clean.

http://www.bdtools.net/
Terry Porritt (14)
1