Billps Tudios

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Downadup. Show all posts
Showing posts with label Downadup. Show all posts

Sunday, 29 March 2009

Conficker Threat: Fact or Fiction

Posted on 10:26 by Unknown

I’ve been writing about the Conficker worm all week and I’m pleased that nobody has accused me of over blowing the situation. My main goal has been to encourage folks to take the same steps to protect themselves as they should be doing every other day of the year.


Most of Conficker stories late in the week have been discussions on if the media has over sold the story and created an atmosphere of fear. According to The Last WatchDog on Internet Security…

“Many security experts are downplaying the significance of  millions of Conficker-infected PCs initiating an elaborate calling home sequence on April 1.

Still, concerns are growing  about the much firmer grip the bad guys are on the cusp of securing on the corrupted PCs, whether or not they choose to do anything with them on April Fools Day.”


Here are some facts I believe to be true.

USA TODAY: On that date (April 1st) all Conficker-infected PCs will begin trying to connect to 50,000 web domains to receive further instructions.

F-Secure: “The worm has some peer-to-peer functionality which means that infected computers can communicate with each other without the need for a server. This enables the worm to update itself without the need for any of the 250 or 50,000 domains.”


So, what’s it going to do?  Will the Internet be taken down?  Will a cyberterror attack be launched?  I doubt it.  What people will notice the most are news stories about Conficker. For most of the world, it will be March 31st when computers in China think it’s April 1st. So by Tuesday night malware researchers will be able to provide more information.

SRI Internationals Paul Porras has been quoted in many articles as saying...

“April 1 is what Conficker researchers are calling a trigger date, when the worm will switch the way it looks for software updates. The worm has already had several such trigger dates, including Jan. 1, none of which had any direct impact on IT operations…”


This evaluation makes the most sense and fits with the typical behavior of the sophisticated malware that I’ve been researching. The trend lately has been to create massive botnets or what F-Secure reports as GhostNets. The big news today is how “Canadian research uncovers cyber espionage network”. Go Canada!


Bottom line, your computer is a powerful device. Just like your automobile you need to keep your doors locked, provide regular maintenance and don’t put yourself into dangerous situations.

Security Garden: Conficker Information for the Home Computer User  March 27th, 2009

 

Read More
Posted in conficker, Downadup | No comments

Wednesday, 25 March 2009

Real Conficker Danger is on March 31st

Posted on 06:52 by Unknown

Yesterday, I wrote about the Conficker worm and how it was expected to launch a new attack on April 1st.  I showed you the reverse engineered code which included a specific date stamp of April 1st, 2009.


What I forgot, and what everyone else missed is the real danger begins on March 31st. I woke up this morning remembering that sometime in the world, it’s already tomorrow.


Many years ago I distributed my free WinPatrol program as something called Birthdayware.  On  my birthday each year a message would pop up inviting folks to thank me by wishing me a happy birthday.


Old WinPatrol Birthdayware message
Birthdayware Easter Egg


To my surprise, the day before my birthday Emails started to flood my inbox. At first I thought a lot of people had their PC clocks screwed up. Then I looked at the Emails and saw they came from Philippines, Australia, Japan and other countries across the international date line.


It will be March 31st in most parts of the world when it turns April 1st across the Pacific. Most reports have indicated a majority of machines currently infected with Conficker are in China. 


Forget April Fools Day and make sure you take steps to protect yourself before March 31st. Somewhere in the world it will be April 1st for nearly 48 hours.



Read More
Posted in Birthdayware, conficker, Downadup, WinPatrol | No comments

Tuesday, 24 March 2009

Conficker Judgement Day on April 1st

Posted on 16:49 by Unknown

I would never want to be labeled as an “Alarmist’ but I hope my post today will make some folks take some reasonable steps to protect themselves.  After a lot of research and debate I have been convinced that April 1st is not going to be a good day for the Internet.


I’ve written about the Conficker worm (alias Downadup) a number of times and this may not be the last time I mention it.  There are well over a million Windows PC’s which are currently infected with Conficker.  On April 1st the infected machines will be reaching out to number of web domains to download an additional component which will contain new instructions. How Conficker will mutate is anyones guess. It could be anything from turning a machine into a spam-bot or launching a widespread cyberterror attack. My guess it will be something designed to make money.


Reverse engineering Conficker exposes April 1st
Reverse Engineering Conficker

Complements of Zarestel Ferrer


April 1st will be a day that shows us who's winning the battle against malware.  If your machine doesn't already have all the Windows security patches installed ,I'd unplug from the Internet on April Fools Day. Getting a new computer?  If a new un-patched computer arrives on that day I'd wait until the 2nd before connecting it to the Internet.


So, if you’ve been planning on running the Windows Update service, this would be a good week to do it. If you don’t have a routine back-up plan you might want to back up your important data by the end of the month.


I’m really not trying to be Chicken Little and freak people out. I’m not predicting any kind of global outage. I’m just suggesting that a properly patched Window system is good idea. I’m also not trying to scare you into upgrading to my WinPatrol PLUS to protect yourself. The free version offers just as much protection against this threat.  The key point here is to make sure you have all the security patches available for free from Microsoft.

I’m actually flying to Washington Dulles Airport on April 1st so I really hope that United Airlines has all their systems protected. 

Update: Real Conficker Danger is on March 31st
It's important to point out that April 1st begins earlier in other parts of the world.  We'll be watching for activity to begin on March 31st from Austrailia, China, Japan, etc...

Update 3/29: Conficker Fact or Fiction


References:


SRI International Conficker C Analysis March 19th, 2009

CA Security Research Blog

The Last Watch: Countdown to Conficker...

Internet Storm Center: Third party info on conficker

Microsoft: Virus alert about the Win32/Conficker.B worm

Microsoft’s Malicious Software Removal Tool

Microsoft Security Bulletin MS08–067  October 23rd, 2008

F-Secure WebLog Conficker Q&A  March 26,2009

Leaked Memo says Conficker Pwns Parliament

 

Read More
Posted in autoupdates, conficker, Downadup | No comments

Monday, 19 January 2009

Remove "Downadup" aka Win32/Conficker Infection

Posted on 18:09 by Unknown

Today, Microsoft notified a number of security experts about a known vulnerability and exploitation of Windows Server service (SVCHOST.EXE). Even though Microsoft provided a fix for this vulnerability in October 2008, they say reports of the exploit are on the rise.

In October, Microsoft warned users of a critical Microsoft Security Bulletin MS08-067.

Executive Summary

This security update resolves a privately reported vulnerability in the Server service. The vulnerability could allow remote code execution if an affected system received a specially crafted RPC request. On Microsoft Windows 2000, Windows XP, and Windows Server 2003 systems, an attacker could exploit this vulnerability without authentication to run arbitrary code. It is possible that this vulnerability could be used in the crafting of a wormable exploit. Firewall best practices and standard default firewall configurations can help protect network resources from attacks that originate outside the enterprise perimeter.

This security update is rated Critical for all supported editions of Microsoft Windows 2000, Windows XP, Windows Server 2003, and rated Important for all supported editions of Windows Vista and Windows Server 2008.

Unfortunately, there seems to be too many unprotected users out in the real world. Microsoft provided details on this infection at its Malware Protection Center.

The following system changes may indicate the presence of this malware:
  • The following services are disabled or fail to run:
    Windows Update Service
    Background Intelligent Transfer Service
    Windows Defender
    Windows Error Reporting Services

  • Some accounts may be locked out due to the following registry modification, which may flood the network with connections:
    HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
    "TcpNumConnections" = "0x00FFFFFE"

  • Users may not be able to connect to websites or online services that contain following strings:
    virus, spyware, malware, rootkit, defender, microsoft, symantec, norton, mcafee, trendmicro, sophos, panda, etrust, networkassociates, computerassociates, f-secure, kaspersky, jotti, f-prot, nod32, eset, grisoft, drweb, centralcommand, ahnlab, esafe, avast, avira, quickheal, comodo, clamav, ewido, fortinet, gdata, hacksoft, hauri, ikarus, k7computing, norman, pctools, prevx, rising, securecomputing, sunbelt, emsisoft, arcabit, cpsecure, spamhaus, castlecops, threatexpert, wilderssecurity, windowsupdate

    Hmmm, should I feel bad that WinPatrol isn’t included in this list?

I recommend, as does Microsoft to keep your system updated with necessary security patches and updates. At the very least you should download the Microsoft Malicious Software Remove Tool. 


 

Read More
Posted in Downadup, Malware, Microsoft | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Support for Downloads without Surprises
    Last week I posted a message about the  packaging of ad supported programs along with popular software. It appears to be a common practice t...
  • Employee Manual to Prevent Cryptolocker and More
    A common way computers are infected or compromised has always been a simple yet well thought out deception. It can happen to anyone and the ...
  • What on Earth is “Cloud” Computing
    The new big buzz word in the computing world is “Cloud” computing. In the past I’ve been critical of the concept and even poked fun at Cloud...
  • SQLite C Code to Read Cookies
    While most of the technology leaking from my brain is for a wide audience, today’s post is very technical in nature. I expected the informat...
  • WinPatrol Cloud Edition Public Beta
    WinPatrol Adds the Newest Technology Available. You’ll now have access the knowledge of thousands of WinPatrol users shared in real-tim...
  • Four Secret Reasons Why Win7 is Ten Times Better
    It’s no secret that I’ve never been a fan of Windows Vista. I really wanted to love it but even as a designated Microsoft MVP I couldn’t dri...
  • Free #1 Tweak to Improve Windows Performance
    Every year billions of dollars are spent by folks just trying to improve the performance of their computers. Over the last couple years ther...
  • Forget the DVD & Save on your New Laptop
    I’ve written before about the coming death of the CD/DVD ’s for data storage.  While that time hasn’t come yet for desktop there is one real...
  • Can Facebook be Trusted?
    Last week Facebook rolled out another round of what they consider easy to use privacy settings. What they’re really doing is trying to appea...
  • TWITTER ALERT
    Anyone who uses Twitter, DO NOT use the Twitter web interface until further notice. There is a code injection vulnerability being used tha...

Categories

  • 2007
  • 3G
  • AAPL
  • ABC
  • accelerometer
  • Achilles
  • Acrobat
  • Activex
  • adobe
  • Ads
  • advertising
  • Adware
  • Adwords
  • Airlines
  • Albany Medical Center
  • algorithm
  • Amazon
  • amber alert
  • AMUST
  • Animation
  • antimalware
  • Antivirus 2009
  • antivirus2008
  • AOL
  • Apple
  • applets
  • AQuantive
  • archive
  • Aruba
  • ASC
  • Ask.com
  • ATI
  • Audio
  • Autorun
  • AutoUpdate
  • autoupdates
  • AVG
  • Azure
  • backup
  • badware
  • Bakugan
  • Baseball
  • battery
  • Ben Edelman
  • Beta
  • BillP
  • Birthdayware
  • Bitlocker
  • Blackberry
  • BlackViper
  • bloatware
  • Blogger
  • Blogs
  • Blogspot
  • Blu-ray
  • Bluehoo
  • bluetooth
  • boinc
  • Bonjour
  • Brazil
  • break
  • Breakaway games
  • Brookman
  • Browser wars
  • C64
  • camera
  • Carpal Tunnel
  • CBS News
  • cell phone
  • CES
  • charity
  • Child Safety
  • chinese
  • Chris Cook
  • Christmas
  • Chrome
  • CIPAV
  • clampi
  • Cloud
  • CNet
  • codec
  • comodo
  • conficker
  • Control Panel
  • copy
  • coupon
  • craplets
  • crapware
  • Crawford
  • credit
  • credit card
  • credit cards
  • ctfmon
  • daylight savings time
  • Dell
  • demo
  • Discount
  • Disney
  • DNS
  • Dollar
  • Domain
  • Donna
  • Doubleclick
  • Downadup
  • Dreamscene
  • droid
  • DVD
  • Dvorak
  • Easter egg
  • eclipse
  • Ed Bott
  • Edelman
  • egreeting
  • Email
  • Environment
  • Epilepsy
  • EU
  • eWeek
  • explorer
  • facebook
  • false positive
  • false-positive
  • FBI
  • file types
  • finnish
  • FiOS
  • Firefox
  • fireworks
  • fix
  • flash
  • Flashpix
  • Fort Drum
  • foxit
  • fraud
  • FTC
  • games
  • garmin
  • Gateway
  • GE
  • George Bush
  • Germany
  • global
  • Godmode
  • Google
  • Google Research
  • GotoMyPC
  • gps
  • green
  • Groceries
  • Habitat
  • Hacks
  • hallmark
  • Halo
  • hard drive
  • Harry McCracken
  • Harry Potter
  • Harvard
  • HD-DVD
  • help
  • hidden files
  • Hijack
  • History
  • Hiton
  • homeland security
  • Honor Flight
  • hosts
  • Hubble
  • IAC
  • ICANN
  • IE
  • IE6
  • IE7
  • IE8
  • installers
  • interface
  • Internet
  • IPAddress
  • iPhone
  • iPod
  • Iraq
  • iTouch
  • iTunes
  • java
  • Kaspersky
  • Kazaa
  • kenmore
  • key logger
  • keygen
  • Keylogger
  • Kosovo
  • LA
  • lady chalupa
  • langa
  • Laptop
  • lawsuit
  • Legoland
  • Levar Burton
  • Linksys
  • Little League
  • Live Writer
  • Live.com
  • localize
  • Logo
  • London
  • LOP
  • lottery
  • Lucasfilm
  • Macintosh
  • Malware
  • Marie Domingo
  • Mary
  • McCracken
  • Media
  • Memorial Day
  • mgrs.exe
  • Micosoft
  • Microsoft
  • Microsoft Surface
  • MiFi
  • mit
  • moon
  • Mossberg
  • Mothers Day
  • MPack
  • MSFT
  • msn
  • MTV
  • Multicore
  • Music
  • MVP
  • MVP09
  • nasa
  • NBC
  • Nero
  • Netbook
  • Network
  • network solution
  • New York
  • newsletter
  • Nintendo
  • Nintendo Wii
  • NNEDV
  • Norton
  • NYAG
  • OAuth
  • obama
  • Office
  • OLPC
  • Olympics
  • OpenDNS
  • oprah
  • optimize
  • optout
  • Paperghost
  • passwords
  • Patch
  • Patriot Flight
  • PC Guy
  • pc pitstop
  • PC World
  • pcmag
  • PCWorld
  • PDC
  • PDF
  • pedipaws
  • performance
  • phishing
  • photos
  • Photoshop
  • Pinnacle
  • Piracy
  • Pirillo
  • pogue
  • Porn
  • pornware
  • postcard
  • prediction
  • prefetch
  • Preview
  • Price
  • privacy
  • Prodigy
  • Programming
  • PSP
  • Public Relations
  • Pytlovany
  • Q-Link
  • Quicktime
  • quotes
  • radio
  • realnetworks
  • realplayer
  • RegCleaner
  • RegCure
  • regedit
  • Registry
  • registry cleaner
  • Release
  • remove
  • Research
  • return policy
  • review
  • RIAA
  • Rivera
  • RMS
  • Road Runner
  • rogue
  • router
  • RTM
  • Rumor
  • safari
  • safety
  • sale
  • Sales
  • Santa Monica
  • scam
  • Schenectady
  • Scoble
  • Scott Dunn
  • Scotty
  • sd
  • Search
  • Sears
  • Security
  • Services
  • seti
  • ShellExecute
  • Shirt
  • SimCity
  • site advisor
  • slingbox
  • snopes
  • social engineering
  • social network
  • solid state disk
  • Sounds
  • Sp3
  • space station
  • SPAM
  • spamhaus
  • Special
  • speedtest
  • Spyware
  • SSD
  • Startup
  • Stats
  • Steve Bass
  • stopbadware
  • storm
  • STS-125
  • Sugar
  • Sunbelt
  • support
  • Symantec
  • tagged
  • Task Catcher
  • Task Scheduler
  • taskbar
  • Tax
  • Techorati
  • techwatch
  • teens
  • temp
  • Thinkpad
  • Thurrott
  • tinyurl
  • Tips
  • TiVo
  • TLD
  • Today Show
  • Toolbar
  • toolbars
  • top ten
  • topten
  • toys
  • Translator
  • transunion
  • Tree
  • Trend Micro
  • tricks
  • trillian
  • Trojan
  • tweaks
  • twitter
  • UAC
  • UI
  • Ultimate
  • Unbox
  • Unboxed
  • update
  • Updates
  • upgrade
  • url
  • USB
  • Utility
  • Valentine
  • Verizon
  • versions
  • Veteran
  • Video Games
  • Vista
  • Vulnerability
  • wall-e
  • war
  • Washington
  • web2.0
  • Webslice
  • WGA
  • Widget
  • WiFi
  • Wii
  • WiiItis
  • wiimote
  • Win7
  • Windows 7
  • Windows Secrets
  • Windows Update
  • Windows7
  • WinPartrol
  • WinPatrol
  • winpatrolflash
  • WinPatrolToGo
  • Winter
  • Wireless
  • Wristband
  • WSJ
  • WWII
  • x64
  • Xbox
  • XO
  • XO Laptop
  • XOActivity
  • Xobni
  • xolaptop
  • XP
  • XP SP3
  • xp3
  • Yahoo
  • Zero Day
  • Zone Alarm
  • Zwinky

Blog Archive

  • ▼  2013 (31)
    • ▼  November (2)
      • Employee Manual to Prevent Cryptolocker and More
      • My First State-Sponsored Attack
    • ►  October (1)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (5)
    • ►  May (2)
    • ►  April (3)
    • ►  March (2)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (30)
    • ►  December (3)
    • ►  November (3)
    • ►  October (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (3)
    • ►  June (2)
    • ►  May (1)
    • ►  April (4)
    • ►  March (4)
    • ►  February (2)
    • ►  January (2)
  • ►  2011 (28)
    • ►  December (4)
    • ►  November (2)
    • ►  October (4)
    • ►  September (2)
    • ►  August (2)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (3)
    • ►  January (1)
  • ►  2010 (44)
    • ►  December (2)
    • ►  November (3)
    • ►  October (3)
    • ►  September (4)
    • ►  August (3)
    • ►  July (3)
    • ►  June (3)
    • ►  May (4)
    • ►  April (4)
    • ►  March (3)
    • ►  February (3)
    • ►  January (9)
  • ►  2009 (90)
    • ►  December (6)
    • ►  November (8)
    • ►  October (6)
    • ►  September (4)
    • ►  August (4)
    • ►  July (12)
    • ►  June (6)
    • ►  May (11)
    • ►  April (7)
    • ►  March (9)
    • ►  February (9)
    • ►  January (8)
  • ►  2008 (122)
    • ►  December (9)
    • ►  November (11)
    • ►  October (14)
    • ►  September (6)
    • ►  August (9)
    • ►  July (9)
    • ►  June (10)
    • ►  May (13)
    • ►  April (8)
    • ►  March (10)
    • ►  February (10)
    • ►  January (13)
  • ►  2007 (155)
    • ►  December (15)
    • ►  November (14)
    • ►  October (12)
    • ►  September (14)
    • ►  August (12)
    • ►  July (13)
    • ►  June (11)
    • ►  May (19)
    • ►  April (17)
    • ►  March (21)
    • ►  February (7)
Powered by Blogger.

About Me

Unknown
View my complete profile