All the latest UK technology news, reviews and analysis

Windows worm hits 8.9m PCs in a week

by Iain Thomson

More from this author

17 Jan 2009

Comments: 4

  • Tweet this
Computer worm
China, Brazil and Russia have been hit hardest by a new virus outbreak

Security researchers are reporting that a worm has infected 3.5 million Windows computers in the past four days.

The worm, known as 'Conficker', 'Downadup' or 'Kido', exploits a vulnerability that Microsoft patched in October 2008. The malware sets up an HTTP server and resets a machine's System Restore point to stop administrators deleting it.

"The number of Downadup infections are skyrocketing based on our calculations," said security firm F-Secure in a blog posting.

"From an estimated 2.4 million infected machines to over 8.9 million during the last four days. That's just amazing."

The worm contains the usual Trojan package that allows the controller to download new files from their own server. But, in an unusual twist, the malware generates hundreds of seemingly random domain names to scan for updates, making it much harder to track the one used by the malware writer.

"Our advice is to block all incoming and outgoing traffic on port 445 from those computers to ensure that (a) they aren't hit with exploits from the internet and (b) if they somehow are exploited, they aren't able to infect the rest of the network via file shares," said Graham Cluley, senior technology consultant at Sophos.

"Furthermore, if you have a group policy in place to lock out accounts after too many unsuccessful log-in attempts, the worm will probably cause many of these accounts to become locked out during the worm's password cracking attempts.

"This can obviously be annoying but, at the same time, it is a good indicator that you may have an infected computer on the network."

Servers in the US and Europe have had the fewest infections owing to regular updating by IT administrators. China, Brazil and Russia have been hit hardest, according to F-Secure.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Desktop Deployment Support Analyst (Worksite, SQL)

Desktop Deployment Support Analyst (Worksite, SQL...

Project Manager

Project Manager is required by Bank in Germany Suitable...

Web Developer / Web Designer Mobile & Social Media Application

Mobile & Social Media Application Web Developer...

CCVP Consultant

CCVP Consultant - Telecoms Cisco Certified Voice Professional...

To send to more than one email address, simply separate each address with a comma.