Computer worm
China, Brazil and Russia have been hit hardest by a new virus outbreak

Windows worm hits 8.9m PCs in a week

'Downadup' on the rampage

Iain Thomson in San Francisco

Security researchers are reporting that a worm has infected 3.5 million Windows computers in the past four days.

The worm, known as 'Conficker', 'Downadup' or 'Kido', exploits a vulnerability that Microsoft patched in October 2008. The malware sets up an HTTP server and resets a machine's System Restore point to stop administrators deleting it.

Advertisement

"The number of Downadup infections are skyrocketing based on our calculations," said security firm F-Secure in a blog posting.

"From an estimated 2.4 million infected machines to over 8.9 million during the last four days. That's just amazing."

The worm contains the usual Trojan package that allows the controller to download new files from their own server. But, in an unusual twist, the malware generates hundreds of seemingly random domain names to scan for updates, making it much harder to track the one used by the malware writer.

"Our advice is to block all incoming and outgoing traffic on port 445 from those computers to ensure that (a) they aren't hit with exploits from the internet and (b) if they somehow are exploited, they aren't able to infect the rest of the network via file shares," said Graham Cluley, senior technology consultant at Sophos.

"Furthermore, if you have a group policy in place to lock out accounts after too many unsuccessful log-in attempts, the worm will probably cause many of these accounts to become locked out during the worm's password cracking attempts.

"This can obviously be annoying but, at the same time, it is a good indicator that you may have an infected computer on the network."

Servers in the US and Europe have had the fewest infections owing to regular updating by IT administrators. China, Brazil and Russia have been hit hardest, according to F-Secure.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Computer virus

Software developed to stop zero-day attacks

Shared information key to network protection, say students

Apple criticised for pulling anti-virus advice

Sophos argues that updating rather than removing the post would have been best course of action

Malware writers spoof Firefox plug-in

Phony add-on attack attempts to steal bank details

Related whitepapers

Related jobs

Most watched

Views from the Valley: 17 November 2009

Legal issues take centre stage this week

Schwarzenegger applauds California tech firms - part 1

Local firms recognised for tech contributions

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

t-mobile logo

V3.co.uk weekly debrief, 20 Nov 09

This week we round up the major vendor conference events,...

Apple iPhone apps

Top 10 articles, 20 Nov 2009

An App Store upset for Apple, and a scandal at...

Biz Stone

Twitter founder details commercial account plans

Biz Stone says paid-for accounts will give users access to...

Cloud computing

Enisa launches comprehensive cloud security report

EU security agency provides checklist for firms looking to vet...

Primary Navigation