Downadup Worm Currently Infecting Millions of PCs   - 1,337 Views, 1 Comment

Summary: A new computer worm called Downadup - also known as the Conficker worm - is spreading like wildfire across personal computers, even though it has only been on the scene for a relatively short time. First spotted just weeks ago, in November, the Downadup worm is estimated to already be resident on at least 3 1/2 million PCs.

Previous Article « The Paypal Dispute and Claim Gotcha - Escalating Your Claim Gets It Dismissed
Read Next Article » France to Ban Cell Phones for Children

  Follow Anne on Twitter     Friend Anne on Facebook

A new computer worm called Downadup - also known as the Conficker worm - is spreading like wildfire across personal computers, even though it has only been on the scene for a relatively short time. First spotted just weeks ago, in November, the Downadup worm is estimated to already be resident on at least 3 1/2 million PCs.

In addition to taking advantage of computers that have not had the MS08-067 remote execution vulnerability patch applied, the Downadup Conficker worm also will attempt to replicate itself on neighboring networked PCs through brute force password guessing attacks.

But most insidious - and what makes Downadup unique for at least the time being - is that it will attempt to call home every day to a variety of domains that have not yet been registered, but will be - just in time - by the hackers. This means that the domains can’t be detected and whacked because they don’t even exist until just moments before the Downadup worm is ready to connect to them to get their next payload of malware.

Fiendish.

Explains security firm F-Secure’s CFO, Mikko Hyppönen, “The bad guys only need to predetermine one possible domain for tomorrow, register it, and set up a website, and they then gain access to all of the infected machines — pretty clever.”

Sean Sullivan, another researcher at F-Secure, said that the estimate of 3.5 million infected PCs currently harbouring the Downadup worm was “a conservative estimate.”

This would be a very good time to run your anti-virus software and, if you are running Windows, to be sure that you have applied that MS08-067 patch.

Downadup Worm Currently Infecting Millions of PCs

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « The Paypal Dispute and Claim Gotcha - Escalating Your Claim Gets It Dismissed
Read Next Article » France to Ban Cell Phones for Children

Read more:

»  The Conficker Worm - What it Is, How to Know if You Have it, and How to Get Rid of It

»  Osama Bin Laden Internet Worm a Dud

»  Newest AIM Opanki Worm says “LOL Look at Him”

»  AIM Gpic.aol Worm Says “damn this looks just like me lol”

For additional similar stories check out our archives on Virus & AntiVirus, Worms

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

1 Comment »

  1. There may be 3-1/2 million infected pcs but I’ve not seen one yet. One worried customer called me to arrange a scan as he’d read about Conficker in his daily paper. This could turn out to be as big a money-spinner as the year 2k compliance bubble. Long may it continue…

    Comment by Scotty — 4/6/2009 @ 6:54 pm

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 1/15/2009
The Internet Patrol
Patrolling the Internet for You!