conficker virus explosion supposed to begin april 1

Stella_Omega

No Gentleman
Joined
Jul 14, 2005
Posts
39,700
for our windows users, I have copy-and-pasted from a friends blog;

computer security circles are rumbling a bit about a big virus already embedded in millions of machines and set to receive new instructions on April 1. I don't know enough to say whether this is a real issue or just sky-is-falling stuff, but practising good computer hygiene is very important anyway. Read this.
http://unixronin.livejournal.com/651277.html
(Yes, I checked snopes.com before posting this: it pointed to this cnet article.)
http://news.cnet.com/8301-1009_3-10204590-83.html

One reassuring point about is that, if "Eastern bloc country" hackers out to make money are behind this, they don't want the networks to go *down*. They are in it for business purposes. They make the actual money by selling more messages going outward for spammers.
They want the networks working.
They may not want servers already in use to do some of the jobs they're supposed to, however, such as filter your spam.

*eyeroll*

As the cnet article notes:
..The Canadian Internet Registration Authority is taking steps to block domains generated in Conficker code that fall in the .ca top-level domain from being used in the botnet, the nonprofit agency said. "If other domain registries were able to do the same thing it would go a long way toward helping mitigate some of the ability for the botnet to breathe," Ferguson said.

Conficker has proved to be such a nuisance that Microsoft has even offered a $250,000 reward for information leading to an arrest in the Conficker case...

http://news.cnet.com/microsoft-offers-$250000-reward-for-conficker-arrest/

What can I do?
Computer users should apply the Microsoft patch and update their antivirus and other security software.
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

Windows users should also apply a Microsoft update
http://www.microsoft.com/technet/security/advisory/967940.mspx

for the AutoRun feature in Windows that was released in February. The patch allows people to selectively disable the Autorun functionality for drives on a system or network to provide more security, to ensure that it is truly disabled. In addition to putting USB drive users
http://news.cnet.com/8301-1009_3-10104496-83.html
at risk of Conficker and other viruses, the Autorun functionality has been blamed for infections from digital photo frames and other storage types.
http://news.cnet.com/8301-1009_3-10104496-83.html
Panda also has released a free "vaccine" tool for blocking viruses that spread through USB drives.
http://news.cnet.com/8301-1009_3-10137032-83.html
Microsoft has a Conficker removal tool.
http://support.microsoft.com/kb/962007

More botnet information and removal resources are on the Shadowserver Web site.
http://www.shadowserver.org/wiki/pmwiki.php?n=Main.HomePage
 
Linux and Mac should be OK. Winblows is fucked as usual. Especially those that use IE (Ignorant Exploder) which is the source of 65%+ of all Windows vulnerabilities.
 
So if you don't open your PC at all on April 1st, does it just skip over you? Or does it sit there waiting for you to open the machine the next day?
 
This has proved to be more hype than danger so far. Here is a link to the most unbelievably simple diagnosis tool I have ever seen. Really makes you wonder if this might have been the biggest April Fools joke ever?

http://www.confickerworkinggroup.org/infection_test/cfeyechart.html
yeah, good thing too! But no, I don't think it's an april fools joke, honest-- this virus has real nasty potential, and it did activate yesterday, just not lethally.

And i bet you the writers close up that weakness next iteration.
 
The expert I heard discuss the virus, said the problem is not necessarily immediate, but the virus checks up to 50,000 web sites for commands. If the creator decides to put in a command next week, next month, or next year, people won't know about it until it's too late. I only use Firefox for passwords because of all the vulnerabilities in Explorer, but people who had all the IE patches up to date would have been protected from the virus anyway. A lot of people who are going to be at risk are the ones who use pirated copies so they don't update.
 
The expert I heard discuss the virus, said the problem is not necessarily immediate, but the virus checks up to 50,000 web sites for commands. If the creator decides to put in a command next week, next month, or next year, people won't know about it until it's too late. I only use Firefox for passwords because of all the vulnerabilities in Explorer, but people who had all the IE patches up to date would have been protected from the virus anyway. A lot of people who are going to be at risk are the ones who use pirated copies so they don't update.

I'm lower tech...pirated copies of Windows?
 
The expert I heard discuss the virus, said the problem is not necessarily immediate, but the virus checks up to 50,000 web sites for commands. If the creator decides to put in a command next week, next month, or next year, people won't know about it until it's too late. I only use Firefox for passwords because of all the vulnerabilities in Explorer, but people who had all the IE patches up to date would have been protected from the virus anyway. A lot of people who are going to be at risk are the ones who use pirated copies so they don't update.

M$ released a patch in October that prevents this. Last count I saw said anywhere from 3 - 12 Million infected machines. Proves the point that some folks are to stupid to own a computer.

Why is it so hard to run update when it comes up every month and also keep an up to date Anti-Virus program?
 
I'm lower tech...pirated copies of Windows?
When I got my computer built for me, the tech used an unlicensed copy of Windows. It used to be no big deal, but a couple of years ago they changed their updates and started adding nasty little reminders if you updated with an unlicensed copy (and the reminders that you were illegal showed up every time you turned on the computer). It made people avoid the updates. Now I just buy laptops because they're almost as good as home computers, plus portable (and always have the licensed software pre-installed), but Vista is such a crap program it makes me want to rethink that decision. However, do I really want to wipe it out and pay an extra $100 for a copy of XP? Seriously, I hate Bill Gates. :(
 
When I got my computer built for me, the tech used an unlicensed copy of Windows. It used to be no big deal, but a couple of years ago they changed their updates and started adding nasty little reminders if you updated with an unlicensed copy (and the reminders that you were illegal showed up every time you turned on the computer). It made people avoid the updates. Now I just buy laptops because they're almost as good as home computers, plus portable (and always have the licensed software pre-installed), but Vista is such a crap program it makes me want to rethink that decision. However, do I really want to wipe it out and pay an extra $100 for a copy of XP? Seriously, I hate Bill Gates. :(

I'm no fan if MS and if I hadn't been locked in with software and such would have gone with a Mac when I bought a new one. But I bought a Lenovo laptop and had XP Pro installed instead of Vista. I probably would have paid a hundred to get a licensed version to make sure the computer didn't explode at the wrong time. I WAS aggravated, however, to pay extra to get XP instead of Vista! I'll assume that money went to the Bill Gates Foundation and write it off on taxes. :rolleyes:
 
I'm no fan if MS and if I hadn't been locked in with software and such would have gone with a Mac when I bought a new one. But I bought a Lenovo laptop and had XP Pro installed instead of Vista. I probably would have paid a hundred to get a licensed version to make sure the computer didn't explode at the wrong time. I WAS aggravated, however, to pay extra to get XP instead of Vista! I'll assume that money went to the Bill Gates Foundation and write it off on taxes. :rolleyes:

You pay the M$ tax on any computer with any version of Windows and/or Office on it. :(
 
Yes, but what I mean is that they're pushing Vista by charging extra to install XP instead.

In spite of what M$ says, XP is an upgrade from ME2(oops, I mean Vista)! :D
Guess that's how they justify the price! :D
 
Back
Top