Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 9th, 2011, 13:54 GMT · By

Microsoft Moves to Kill AutoRun Malware Propagation Vector

SHARE:

Adjust text size:


Microsoft pushes AutoRun-limiting update
Enlarge picture
Microsoft has released an optional software update yesterday which restricts the AutoRun functionality on older Windows operating systems, therefore blocking a common malware propagation vector.

AutoRun is the feature responsible for automatically parsing autorun.inf files found on removable media devices, such as USB memory sticks, external HDDs, portable audio players, mobile phones, optical discs and so on.

For years security experts have camaigned against it, because it poses more security risks than usability benefits and is constantly abused by malware.

Microsoft recognized the dangers and limited the functionality by default in Windows 7 and Windows Server 2008 R2.

However, for older versions of Windows, such as XP, Vista, Server 2003 and Server 2008, the company only provided a fix that needed to be manually downloaded and installed.

That changed yesterday, when KB971029 was released as optional through Windows Update.

"We feel like now is the right time across the industry to be able to push this change out and have a pretty substantial impact on how malware spreads. This is really something that will help to further protect the ecosystem," Jerry Bryant, manager of response communications at Microsoft, told The Register.

The most prominent threat taking advantage of AutoRun to spread is the Conficker worm which took the world by storm in early 2009 and infected millions of computers.

Despite being abandoned by its creators, the huge botnet created by Conficker still exists today and infections with the worm still appear around the top in monthly statistics released by antivirus vendors.

BitDefender's report for January puts Conficker in the third position by number of detections. The first place is even more relevant as it's a generic detection for AutoRun worms, which shows that malware abusing this functionality is still very much active.

TELL US WHAT YOU THINK:

1,899 hits · 3 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


AutoRun-Based Malware Attacks on the Rise

USB Devices Harbor 25% of All New Worms

AutoRun Malware Dominates the Threat Landscape in 2010

READER COMMENTS:


Comment #1 by: EP on 09 Feb 2011, 19:22 UTC reply to this comment

Lucian, KB971029 was released at the Microsoft Download Center in late August 2009 and recently made available through Microsoft Update/Windows Update on Feb. 8, 2011. This is really not a new update. I'm not sure why Microsoft took so long to post KB971029 on Windows Update when they could have made it available much sooner.


Comment #2 by: Beach Bum on 11 Feb 2011, 10:31 UTC reply to this comment

About ******g time! It's been some 16 years since the exploit first appeared in Windows 95 - before many hackers were born. No wonder the world is so infested with botnets. And no thanks to Microsoft's arrogance/ignorance of the problem that **THEY** helped to create. Autorun is by-design flaw that had millions buying Apple computers instead. Thank you IconS for letting us know :-)


Comment #3 by: Beach Bum on 11 Feb 2011, 10:38 UTC reply to this comment

IconS - Just had a look at the update...

Microsoft says, "This update disables AutoRun entries in AutoPlay, and displays only entries that are populated from CD and DVD drives. Effectively, this prevents AutoPlay from working with USB media."

Yes but we recently found ConfickerD written to a data DVD!!!!!

The only way to kill Autorun forever, is to zap it in the registry. Google for 'disable autorun.inf'

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM