Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 2nd, 2009, 08:32 GMT · By

April 1st Passes, Conficker Stays Put

SHARE:

Adjust text size:


Conficker hype condemned by IT security professionals
Enlarge picture
April 1st, the date depicted by some of the media in the past week as being the Internet's doomsday brought forth by the infamous Conficker computer worm, has passed and nothing really significant has happened. Many IT security professionals condemn the hype created and explain how it has actually caused more real damage than the worm.

The fact that an update mechanism in the Internet's largest botnet, Conficker, has been set to come into full action on April 1st has created a lot of fuss in the days leading to this event. Probably in an attempt to raise awareness, many news agencies and media outlets have really blown this out of proportion, creating an overall state of panic in the minds of the average consumers.

Now that the much-anticipated date has passed without anything major happening, the security researchers who have advised them to calm down and have said that the worm will most certainly not bring chaos on the Internet are condemning the hype created and draw conclusions.

"[...] In my own experience, it has been some of the newspapers and media organisations who have been guilty of dreaming up apocalyptic headlines and the security vendors who have been pouring the cold water," Graham Cluley, senior technology consultant at Sophos, says. "As I've been saying all along, the people behind Conficker could choose any day to instruct it to do something malicious – there was nothing which made it more likely on April 1st. So the need for you to remove Conficker is just as necessary today as it was yesterday, and will be tomorrow," the security expert concludes.

Roger Thompson, AVG's chief research officer, is much more sarcastic about it. "Human nature being what it is, some folks are fixating on the worst possible outcome. It'd be pretty bad if you got hit by a meteor too, but no one is building meteor shelters," he writes. He suggests that, if something really bad was to happen to the computers/networks of those affected, they would have no excuse."The worm probably grabbed millions of users right out of the box in December 2008, but any gov/ corp/ edu user who is still infected after five months, deserves it."

PandaLabs' Technical Director, Luis Corrons, notes that, "The melodramatic Conficker countdown is starting to resemble one of those never-ending TV soap operas; everyone is talking about it, but it never draws to an end." He also points out that, "Bearing in mind the number of domains that are downloading malware by exploiting the interest in Conficker, without actually having any connection with it, […] there may still be users who have downloaded other Trojans simply by searching for news about Conficker… Ironic really."

The Conficker botnet may have not received malicious instructions from its creators on April Fool's Day, but the hype created around it has certainly helped other cybercriminal gangs. As we reported on 31 March, search results for "Conficker" had been poisoned with malicious links, leading to malware and scareware. Spam analysts at Trend Micro warn that fake e-mail alerts advising users to scan their computers for Conficker have also been in circulation. These have had, most likely, the purpose of increasing the number of search queries for removal tools, which has had a good chance to lead to other malicious applications.

TELL US WHAT YOU THINK:

1,088 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Cybercrooks Profit from the Conficker Hype

Security Researchers Find Weakness in Conficker

Conficker Hits the UK Parliamentary Network

Conficker Authors Push First Update

Conficker to Hit Legit Websites

READER COMMENTS:


Comment #1 by: James on 03 Apr 2009, 10:27 UTC reply to this comment

Hi,

Good article. Sophos' Conficker removal tool can detect and remove all variants of the worm/virus.

As long as people run these tools it should stop any serious outbreak.

James


Comment #2 by: Lucian Constantin on 03 Apr 2009, 12:44 UTC reply to this comment

Hello James,

Thank you for commenting. I'm glad you liked the article.

Indeed, Sophos' tool is able to remove all variants of the worm. However, most of the AV vendors currently offer similar free tools for removing Conficker.

A lot of them can also be downloaded from our secure servers. I've compiled a list of the ones we currently host at the end of this article: http://news.softpedia.com/news/Cybercrooks-Profit-from-the-Conficker-Hype-108240.shtml

Best regards and be safe,
Lucian

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM