NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

Security


$250.000 Worm Targeting Windows 7, Vista and XP Evolves

Introducing Worm:Win32/Conficker.C (Conficker.B++)

By Marius Oiaga, Technology News Editor

24th of February 2009, 13:57 GMT

Adjust text size:


Windows PC Concept
Enlarge picture
A nasty piece of malicious code worth no less than $250,000 to Microsoft, has evolved to a new stage, and is now enjoying additional functionality. Microsoft has confirmed that it detected new samples of Win32/Conficker in the wild, and that it has updated the antivirus definitions consequently. The new version of the worm, which is capable of infecting all Windows client and server operating systems, including Windows XP SP3, Windows Vista SP1 and Windows 7 Beta, now also comes in the Conficker.B++ or Worm:Win32/Conficker.C flavor, in addition to the existing Worm:Win32/Conficker.A and Worm:Win32/Conficker.B.

“The new sample has modifications which introduce new backdoor functionality. Previous versions of Conficker patched netapi32.dll in memory to prevent further exploitation of the vulnerability addressed by bulletin MS08-067. We’ve discovered that the new variant no longer patches netapi32.dll against all attempts to exploit it. Instead it now checks for a specific pattern in the incoming shellcode and for a URL to an updated payload. The payload only executes if it is successfully validated by the malware. However, there doesn’t appear to be an easy way for the authors to upgrade the existing Conficker network to the new variant,” revealed Microsoft's Tareq Saade and Ziv Mador.

Microsoft revealed that, despite the update, the definitions for Worm:Win32/Conficker.B were also capable of detecting Worm:Win32/Conficker.C. However, because of the updated functionality, the Redmond company acknowledged the need to bring definitions on par. In this regard, the upcoming Malware Removal Tool will identify and remove Worm:Win32/Conficker.C.

“This change may allow the author to distribute malware to machines infected with this new variant. This might be a response to the fact that they no longer have the ability to register many of the Conficker domains. For our fellow researchers who may be trying to locate a sample, one such SHA1 is 0e24424f5dfbe391e2e834e7f22c758a63eab6ba. However, note that this is a polymorphic threat,” Mador and Saade added.

Also dubbed Downadup, Conficker was initially associated with a Critical vulnerability in Server Service patched by Microsoft in October 2008. The worm spreads itself not only via the security flaw, but also through removable media via Autorun, and unprotected network shares. Last week, the software giant announced that it would pay no less than $250,000 as a reward for the persons that would supply information leading to the arrest and conviction of Conficker's authors. The reward is valid internationally and is not claimed as of yet.


TAGS:

Conficker | Worm:Win32/Conficker.C | Conficker.B++ | Downloadup
Read by 2,854 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


IIS 6 (Windows 2003) Servers Infected with the Downadup/Conflicker

$250,000 Reward for the Author of Nasty Worm Affecting Windows 7, Vista and XP

Microsoft Tackles Password Stealing Trojans

Nasty Conficker Worm Lurking Windows 7, Vista SP1 and XP SP3 Machines

Malicious Autoplay in Windows 7 Can Trick Users into Getting Infected with Malware

Free Microsoft Security Tool Kills Worm Targeting Critical Windows Flaw

New Malware Targets Windows 7, Vista SP1 and XP SP3 Vulnerability

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM