Tuesday, March 31, 2009

So will you be online and playing SMT when Conficker/Downandup virus supposedly hits?

I've been debating this last night as I reread multiple warning e-mails from friends as to whether I should log on at midnight tonight as April Fool's looms closer to the countdown kicks off on this supposedly massive and potently harmful virus will begin.

I say supposedly since electronic doomsayers say it's affected 10 to 12 million computers and even Microsoft themselves have offered a quarter of a million dollars to anti-hackers and independent computer tech teams to stop this virus.

But this is not the first time it's happened. 5 years ago in 2004 a similar even took place with the Mydoom worm virus. The virus' primary role was to simply infect millions of computers and all start attacking sco.com and microsoft.com by having them all log on to their respective sites and pretty much cause traffic bandwidth overload. And of course all premeditated attacks against the said companies in protest.

This new gem that's been gradually and discreetly "worm"-ing it's way (pardon the pun) into our computers since 2008 according to the experts is a quite nasty piece of work. Version A (yes this bugger has 3 versions of itself) embeds and copies itself by exploiting a vulnerability in Windows Server Service and acts like a harmless background service application. Version B will attach itself to Admin access points and copies itself over a network. And version B will infect removable media like USB's and use the Autorun feature to upload itself in another computer.

And the supposed initial result when April Fool's kicks in:
-Resets System Restore Points
-Disables important Windows system services like Windows Automatic update/error reporting, Windows Defender and Windows Security Center
-Prevents access to antivirus sites
-Account lockout being reset
-Large amount of traffic on LAN's

Well that's a lot of info to summarize, but if you're interested in more and take on preventative measures here's a wiki link that's keeping tabs on the current situation

http://en.wikipedia.org/wiki/Conficker

As for me, I'm still double checking my laptop and hopefully find myself worm free and be able to enjoy Megaten later after the initial virus launch. Good luck all and start checking your computers.

3 comments:

  1. nuthing hapend to me. i did not do the up date

    ReplyDelete
  2. Of course not. We're updated but the US Feds beg to differ:

    US federal agencies

    The United States Computer Emergency Readiness Team (CERT) recommends disabling AutoRun to prevent Variant B of the worm from spreading through removable media, but describes Microsoft's guidelines on disabling Autorun as being "not fully effective". CERT has instead provided its own guide for disabling AutoRun. CERT has also made a network-based tool for detecting Conficker-infected hosts available to federal and state agencies.

    ReplyDelete
  3. Just because nothing happened Curtis doesn't mean you have to be lax on your preventative measures. Remember this thing has 3 versions of itself, for all you know a friend or family may be bringing a USB drive or an MP3 player that could be carrying that bug.

    ReplyDelete