27 Mar 2009
Security experts are downplaying much of the speculation surrounding an expected 1 April update for the notorious Conficker malware.
Also known as 'downadup', the malware has been spreading throughout 2009 and is believed to have infected millions of PCs.
Analysis of the Conficker code suggests that the latest version will instruct infected machines on 1 April to contact an unknown domain and await further instructions. The possibility has led to reports of a possible "doomsday" infection, or a huge attack from the Conficker botnet.
These worries, however, are little more than uninformed hysteria, according to security experts. Many security researchers believe that Conficker's April Fool's Day event may in fact be laughably minor.
F-Secure researchers reassured users in a special guide posted to the company blog that in all likelihood Conficker's 1 April update would be a non-event.
"The Conficker worm is going to change its operation a bit, but that's unlikely to cause anything visible on 1 April," F-Secure said.
The company also noted that only the latest version of the malware, known as 'Conficker C', which constitutes a small percentage of total infections, would be carrying out any instructions on 1 April.
Researchers from other security firms agree. "Some people have got rather confused as to what the 1 April deadline really means," wrote Sophos senior technology consultant Graham Cluley in a blog post.
"The truth is that Conficker is not set to activate a specific payload on 1 April. Rather, Conficker will begin to attempt to contact the 50,000-a-day potential call-home web servers from which it may receive updates."
Memories of past malware infections are further stoking worries about Conficker. This week marks the 10th anniversary of the Melissa virus, which created headlines by crashing email servers across the globe.
Malware creation has evolved into a lucrative business since Melissa, and most experts believe that Conficker's update will be the first step in a spam run or other money-making activity, rather than an old-fashioned attempt at internet mayhem.
"The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment," wrote Trend Micro senior security advisor Rik Ferguson in a blog post.
"Making so much noise that every victim knows they're infected will have entirely the opposite effect."
Users are advised to protect against becoming part of the Conficker botnet by installing the latest security patches from Microsoft, and keeping all security and anti-virus tools installed and up to date.
Sophos is offering a free Conficker removal tool to users who believe that their Windows PCs may already be infected. Other operating systems are not believed to be vulnerable.
Latest stories from Web
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Position:Oracle Applications eBusiness Suite Suport...
Software Developer A leading UK Software Application...
I am looking for a permanent senior Drupal Developer...
Retail Consultant - Data Transformation and Migration...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Dont be biting off your nose
Saying that there is not to much to worry about could be detramental to any one who becomes layed back on this matter, after all i have read over the last few hours better be safe than sorry.
Posted by: Seanie 31 Mar 2009
Hype / Sensationalism? Probably, but...
I think in general this promotes awareness.... You'd be surprised how many people think they are "protected" by using a program like Symantec / Norton AV. Unfortunately, many people get a new computer that comes with a free version of Norton with it, the free period expires, and they don't bother to pay for the subscription...assuming this is some sort of way for Symantec to milk money from them. Without paying for the software, virus definitions aren't updated and the software is useless. I know a lot of people that fit into that boat. Stuff like Conficker stresses the need to get your virus software straight. A few bucks now to protect your personal information / credit cards / identity / data / bank accounts etc us a small price to pay. I think a lot of people think they are protected, when they actually aren't. See http://confickerc.info for removal instructions.
Posted by: jerron2 29 Mar 2009