Nov 8, 2009

Conficker Worm Update: We Have Twins

free web hosting
Open Discussion > MODERATED AREA > Computers > Computer Security Issues & Exploits

Conficker Worm Update: We Have Twins

Saint_Michael
Well it seems Conficker has a twin sister, thought about going twin brother but nah, anyway, it seems the creators of Conficker B decided to do an upgrade every since the Conficker Consortium busted this worm wide open and crack the algorithm that Conficker uses to send and recieve data. Basically the updated worm was created so it could bypass the CC attempts to keep it under control but that is only speculation, since the CC have been buying up domains Conficker has been communicating with.

However, I think this little blurb really is the heart of war on Conficker:

QUOTE
To put things in perspective: There were 297 subroutines in Conficker B; 39 new routines were added in B++ and three existing subroutines were modified, SRI wrote in a report on the new variant. B++ suggests "the malware authors may be seeking new ways to obviate the need for Internet rendezvous points altogether," the report states.


Of course, if that is the case then Conficker will definately become more dangerous, because now it might target any domain and not just the ones it communicates with. It should be a interesting 2009 and odds are it will be Confickers year as it was the Storm Worm's year, its funny its acting like Skynet from Terminator 3 laugh.gif.

SOURCE

http://www.pcworld.com/businesscenter/arti..._evil_twin.html

http://en.wikipedia.org/wiki/Conficker

 

 

 


Comment/Reply (w/o sign-up)

Echo_of_thunder
Wow thank you for that S_M. I have to say I do agree 2009 will be the year of the cornflicker. It has infected so many now, and I feel it has to be the worst virus/worm to date. Now I really understand why there is such a big bounty on the maker of the cornflicker. He or she has infected so many counties. I am just waiting for a Clean and Reboot of the whole WWW.

Comment/Reply (w/o sign-up)



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Similar Topics

Keywords :

  1. Worm_fujack 2
    (0)
  2. [ Aef ] Security Update For Aef Forum Software
    Highly recommended (1)
    For the benefit of any or all AEF Forum Software users, there has been a Security Issue found in the
    BBcode handling of the software. A Patch file is available and it is as simple as uploading a
    replacement file to overwrite an existing file in the Install. File download and further
    details are available here . The Update is highly recommended since the vulnerability is
    now public and no telling what mischief could result on your Forums. ....
  3. Iphone Update Disable Hacked Phones
    (5)
    After reading the article it is obvious what the update was for besides adding in new services and
    updates, however, it took all of what, two weeks to hack the IPhone? So I doubt it will that long
    to figure out what apple change to disable the hack phones. I found this particular quote amusing,
    "...company officials insisted they were "not proactively" trying to make hacked iPhones useless."
    Heck I would if I knew I would be losing millions of dollars a month on a phone that that was hacked
    and used by another phone provider, but like I said earlier it won't take ....
  4. Hole In Microsoft Messenger Program Requires A Immediate Update
    For Users of MSN Messenger 6.2, 7.0 and 7.5 versions of MSN Messenger (0)
    SOURCE Well it seems that Microsoft found a huge hole in MSN Messenger that was bad enough that
    they want people to upgrade to the current Messenger which is Live 8.1 or something like that. As
    for details on the problem they just said the following, "..which let hackers embed malicious code
    in Web chat invitations to users." and that they found this problem in "6.2, 7.0 and 7.5, as well as
    Windows Live Messenger 8.0." Although it was interesting to know that people were actually
    complaining about Live Messenger being a resource hog, well the last time I check msn w....
  5. Skype Worm Jumps To Icq And Msn
    (3)
    Well if you all remember a few months back I made a topic about the skype worm here , well it seems
    to have busted out two clones one for ICQ and for MSN. the new variation showed up sometime at the
    beginning of the week for these two networks and if memory serves me correctly and it usually does,
    these two messenger networks are huge. Now in order for this worm to be activated a user must click
    on a link and once they do that the worm will start sending messages to your contact list and get
    others to click on that link as well. Although security experts rate this ....
  6. Microsoft Update Program Being Used By Hackers
    (6)
    Although I am bit surprise that no one really take about way back then, but it seems the hackers and
    crackers I starting to use the microsoft update downloading to transmit there malware and torjans to
    compromised computers. The reason being is that the Microsoft update program bypasses firewall
    security protocals and so when that malware is getting download, your firewall and virus programs
    will not pick it up. I know a few people turn it off and either download them manually or don't
    download them at all. So to toss out a warning, when you get he windows update ....
  7. New Virus Called Storm Worm Or W32/nuwar@mm Is Out And About
    WINZIP/Rar be WARNED (4)
    To think the Microsoft ANI exploit and the botnet things were bad but this just top the charts, this
    new variation of the Storm virus of last year gets a new powerful punch. The virus gets sent
    through a password protected zip fil in which the password is contain in a image file in the email.
    The email subject contains either Worm Alert!" or "Trojan Detected! so do not open and just delete
    it. Also the image file will read something like UrgentNotice.gif" or "AbuseReport.gif. and the zip
    file will read something like "patch-####.zip" or "removal-####.zip.". McAfee s....
  8. Myspace.com Flash Hack
    account hijacked worm and solution (13)
    Well buffaloHELP just mention and I have confirmed it by many articles myspace accounts have been
    hacked or in hte sense that if your account was hijacked then anyone viewing your profile will also
    get infected as well. In a article by chaseandsam.com go into detail on how this happen and a
    solution to it as well Click here for more ---WARNING--- Also this hack is also a virus in
    which a person who is viewing your hacked profile will get their profile hijacked as well. Also
    Symantec mentions about it as well Nortan How it was done ---SOLUTION--- ....
  9. Worm Disguises As Windows Genuine Advantage
    be careful of the wgavn service ... (5)
    QUOTE IT security experts have warned of a worm that purports to be Microsoft's Windows
    Genuine Advantage (WGA) anti-piracy tool. WGA has recently been branded as 'spyware' in
    that it collects unnecessary hardware and software data from users' PCs. The Cuebot-K worm
    spreads via AOL Instant Messenger, registering itself as a new system driver service called
    'wgavn'. It carries the display name 'Windows Genuine Advantage Validation
    Notification', and runs automatically during system startup. Once in place the worm disables
    the Wi....
  10. Worm: W32.areses.h@mm
    (3)
    QUOTE W32.Areses.H@mm is a mass-mailing worm that opens a back door on the compromised computer
    and may download files. When W32.Areses.H@mm is executed, it performs the following actions:
    Copies itself as the following file: %Windir%\csrss.exe Note: %Windir% is a variable that refers
    to the Windows installation folder. By default, this is C:\Windows or C:\Winnt. Adds the value:
    "Debugger" = " " to the registry subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
    NT\CurrentVersion\Image File Execution Options\explorer.exe Adds the value: "Application" ....
  11. Alcra D Worm
    PLEASE HELP (10)
    I have the Alcra D worm which starts up limewire and disables regedit and other things. If anyone
    knows how to get rid of this tell me. PLEASE. I have adaware, but it never seems to find it. I cant
    use ctrl alt delete and limewire slows my computer down because it opens non stop. SO PLEASE HELP. I
    have tried other things, but they never seem to work. I found a program for the type B worm, but it
    dosnt work for D i tried. Any info on this post back. If you use limewire and it keeps opening this
    is what you have by the way. And i love how limwire's FAQ says you have a ....
  12. Nyxem E - Be Safe From This Virus/worm
    Latest Mass Mailing Worm (14)
    QUOTE Windows users are being urged to scan their computers before 3rd February 2006 to avoid
    falling victim to a destructive Worm. On that date the Nyxem E Worm is set to delete Word,
    Powerpoint, Excel and Acrobat files on infected machines! Don't get caught out... See
    complete article at http://www.updatexp.com/nyxem-e.html Better get your anti-virus updated by
    3rd Febuary before seeing your files go missing. It's kindda scary worm if not handled properly.
    The date is near so get updated fast. Edited topic title. ....
  13. Microsoft Plugs Windows Worm Holes
    14 flaws in Windows... (3)
    http://news.zdnet.com/2100-1009_22-5893344.html?tag=nl.e589 Here is another proof that the words
    'Windows' and 'Security' simply cannot go together... And yet another good reason
    for installing and start using Linux... Cheers! KoYoda....
  14. New Worm
    zotob (1)
    QUOTE The worm is a packed PE executable file 22528 bytes long. Installation to system When
    run, the worm copies under %SYSTEM% directory using the name 'botzor.exe' and creates a
    named mutex 'B-O-T-Z-O-R' for making sure that only one copy of the worm is run at the same
    time. Then it adds the following registry entries to ensure that it is started when a user logs on
    or the system is restarted: "WINDOWS SYSTEM" = "botzor.exe" The worm also adds the
    following registry key for diasabling shared access service: "Start" = "4" Spr....
  15. New Worm!
    Please note! New Worm here! (9)
    OK! Mircosoft has just discovered a new worm. I repeat! NEW WORM! The new worm is called "Zotob".
    It's a worm that can takes weeks, months, to get embeded into your system and take over. It digs
    so deep that it's very difficult to erase. So PLEASE! Listen carefully! Zotob -- The worm
    targets Windows 2000 Computers and once it's embeded, it'll try sending itself to other
    computers! The worm IS *NOT* caught by emails, websites, anything. It's a worm that opens
    itself, so you have to be really carefull now. What it does: Is simply *RANDOMLY* shutsdow....
  16. New Worm, M$ Users, Be Warned!
    WORM_ZOTOB.D and WORM_RBOT.CBQ (11)
    New Virus is emerging. Microsoft users, be alerted!. This is one of the reason why i dont really
    like M$ stuff, but still, i need it really much despite of its problems QUOTE Dear Trend Micro
    customer, As of August 16, 2005 5:12 PM (Pacific Daylight Time; GMT-7:00), TrendLabs has declared
    a Medium Risk Virus Alert to control the spread of WORM_ZOTOB.D and WORM_RBOT.CBQ. TrendLabs has
    received several infection reports indicating that this malware is spreading in Brazil and the
    U.S.A. WORM_ZOTOB.D is a memory-resident worm that drops a copy of itself in the %Sys....
  17. New Virus Kills Music Files
    Nopir.B worm wipes out all mp3 and com files (19)
    http://english.chosun.com/w21data/html/new...0504250004.html Not only does it not differentiate
    between legal and illegal mp3 files, it also doesn't let you reboot your computer. So far,
    it's been circulating only in Europe, but those in the US and Asia had better take caution as
    well. It's only a matter of time.......
  18. Another Firefox Security Update
    Firefox v1.0.3 (6)
    Yes, another update. You can read the fixes at ZDNet or here at the Mozilla Release Notes .
    Before installing v1.0.3 make sure that the directory you've chosen to install into is clean and
    doesn't contain any previous Firefox installations! (known issue) Greetz, Rik©....
  19. Windows Update Email Scam
    its a trojen horse (8)
    QUOTE A new scam by hackers has some people believing they are receiving an e-mail about a
    critical update to Windows when in actuality they are installing a Trojan horse, Sophos said on
    Friday. The e-mail directs victims to a fake version of the Windows Update site, where there are
    links to download the malicious "patches." "The email uses the Microsoft branding and style so to
    the casual observer it appears to be legitimate," Gregg Mastoras, Senior Security Analyst at Sophos,
    told BetaNews. If users download the "patches," they are actually installing the Troj/DS....
  20. Firefox Security Update (firefox 1.0.2)
    Released 23-03-2005 (14)
    Yesterday Mozilla (foundation) released another security update for Firefox. QUOTE(Mozilla
    Foundation) March 23, 2005, (Mountain View, CA). The Mozilla Foundation, a non-profit organization
    dedicated to preserving choice and promoting innovation on the Internet, today announced a security
    update for its Firefox Web browser. The update is a proactive security release to patch a bug
    identified by Internet Security Systems, a premier security research, products, and services
    company. No known exploits of the bug have been reported prior to the update's release. ....

    1. Looking for Conficker, Worm, Update:, We, Have, Twins

Searching Video's for Conficker, Worm, Update:, We, Have, Twins
See Also,
advertisement


Conficker Worm Update: We Have Twins

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com