Home | Contact us | Links | Archives | Search

Three Million Hit By Windows Worm

Issue 364
Front Page
News Headlines

UN Votes For Somalia Peace Force

“The British Government's Position Has Always Been To Be Sympathetic To Somaliland's Demand For Independence” Lord Malloch-Brown  

Court Rules Somali Ex-Government Official Can Be Sued In U.S. Courts For Violations Of Human Rights

Somalia And Somaliland Raised At Foreign Office Questions

Egyptian Teacher Kidnapped In Burao Released

Somali Politian Executed For 'Apostasy'

Local and Regional Affairs

Maternal Mortality In Somaliland In Decline But Still Worrying

Somaliland: A New Company To Provide Gas

Somaliland: Admas University College Opens A New Campus

Last Ethiopian Troops Leave Somalia's Capital

UN Orders Eritrea To Withdraw From Disputed Djibouti Border

Thousands Cheer Ethiopia Pull-Out

Insurgents Attack Somali Presidential Palace

Somaliland: Voter Registration Successfully Completed

Inside A Pirate Network

Somaliland: U.S. Investor Believes Ethiopia Likely To Break Apart Soon
Somali Pirate's Body Washes Ashore With $153,000
Editorial

Egypt And Piracy

Somaliland Voter Registration: What Is Next?

Features & Commentry

Miss East Africa UK 2008: Contestant Marian Fahen Samatar From Somalia

What A Black President Means To Me
Charity Worker Preparing To Visit War-Torn Sierra Leone

An Open Letter to Martin Luther King

Laying Our Hands On The Problem

By Flying Car From London To Timbuktu

Stop Babysitting Bottomless Somalia

To Reduce Piracy At Sea, Help Somalia On Land
Security Council Expresses Intention To Establish Peacekeeping Mission In Somalia, Subject To Further Decision By 1 June, Unanimously Adopting Resolution 1863

International News

 

History Links King Holiday, Obama Inauguration

Three Million Hit By Windows Worm

Airbus Crashes In New York River

Man Refuses To Drive 'No God' Bus

U.S. Navy Nears Deal with Unidentified Country to Prosecute Somali Pirates

How Birds Can Bring Down A Plane

Opinion

Government Failed To Stop School Children From Chewing Khat

Puntland Parliament Appoints New Pirate President

An Awakening For Somaliland Citizens: Somaliland Voter Registration

Indonesian Troops For Gaza?

Somalia: Talibanistan In East Africa

The Global Crisis Of Capitalism And Its Impact

Washington, January 16, 2009 – A worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is posing a growing threat to users.
The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008.
Although Microsoft released a patch, it has gone on to infect 3.5m machines.
Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft's MS08-067 patch.
According to Microsoft, the worm works by searching for a Windows executable file called "services.exe" and then becomes part of that code.
It then copies itself into the Windows system folder as a random file of a type known as a "dll". It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.

INFECTED IPs WORLDWIDE
China 38,277
Brazil 34,814
Russia 24,526
India 16,497
Ukraine 14,767
Italy 13,115
Argentina 11,675
Korea 11,117
Romania 8,861
United States 3,958
United Kingdom 1,789
Source: F-Secure


Once the worm is up and running, it creates an HTTP server, resets a machine's System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker's web site.
Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down.
But Conficker does things differently.
Anti-virus firm F-Secure says that the worm uses a complicated algorithm to generate hundreds of different domain names every day, such as mphtfrxs.net, imctaef.cc, and hcweu.org. Only one of these will actually be the site used to download the hackers' files. On the face of it, tracing this one site is almost impossible.
Speaking to the BBC, Kaspersky Lab's security analyst, Eddy Willems, said that a new strain of the worm was complicating matters.
"There was a new variant released less than two weeks ago and that's the one causing most of the problems," said Mr Willems
"The replication methods are quite good. It's using multiple mechanisms, including USB sticks, so if someone got an infection from one company and then takes his USB stick to another firm, it could infect that network too. It also downloads lots of content and creating new variants though this mechanism."
"Of course, the real problem is that people haven't patched their software. If people do patch their software, they should have little to worry about," he added.
Technicians have reverse engineered the worm so they can predict one of the possible domain names. This does not help them pinpoint those who created Downadup, but it does give them the ability to see how many machines are infected.
"Right now, we're seeing hundreds of thousands of unique IP addresses connecting to the domains we've registered," F-Secure's Toni Kovunen said in a statement.
"We can see them, but we can't disinfect them - that would be seen as unauthorised use."
Microsoft says that the malware has infected computers in many different parts of the world, with machines in China, Brazil, Russia, and India having the highest number of victims.
Source: BBC


 


 











 




 




 



 


 

 


Home | Contact us | Links | Archives | Search