ITS Alert Board
Alert: Conflicker Worm Infects Windows
Systems Affected: Unpatched Windows 2000, Windows XP and Windows Server 2003 systems.
Overview: Security experts estimate botnet numbers at 9 million PC's. This suggests that new malicious code could be delivered to these PC's for criminal purposes. The best defense still is for users to keep current with all system and application software updates including virus protection.
Description: What the infection is called: Some common names are Downadup, Conficker and Kido.
Signs of Infection:
-
Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender, and Error Reporting Services are disabled.
-
The network is congested
*** To test for possible Conficker infection, click on the following URL and follow the instructions.
A quick test to see if your machine is infected with the Conficker Worm, is to click on the link to the “Eye Chart” below. If this eye chart doesn’t display the logo’s for 6 of the top security sites in the world, you may be infected.
www.confickerworkinggroup.org/infection_test/cfeyechart.html
Infection Spreads:The infection exploits the patch released out of band in October MS08-067, which involves the Windows Server Service. If the system is already infected, it may not accept the patch. The following are other ways it spreads:
Avoid Infection: Keep systems at current patch levels. To clean infected PC’s Microsoft recommends the MSRT (Malicious Software Removal Tool) can be found on Microsoft’s site or here. The use of strong passwords is also strongly suggested along with using other available scanning software to remove infections.
Additional Information:
Countdown to conficker activation begins
Microsoft’s advice on Downadup leaves users open to attack – ComputerWorld 1/21/2009
F-Secure
Conficker sizes city’s hospital network – The Register 1/20/2009
Millions hit with windows worm as infection spreads – E-Week – Security 1/16/2009
How to protect your PC against Downadup worm – ComputerWorld – 1/20/2009
Back to Alert Board