<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Making IT Easy &#187; virus</title>
	<atom:link href="http://www.gunthy.net/blog/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gunthy.net/blog</link>
	<description>IT for normal people...</description>
	<lastBuildDate>Mon, 30 Jan 2012 10:49:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
<link>http://www.gunthy.net/blog</link>
<url>http://gunthy.m0nk3y.com/blog/wp-content/mbp-favicon/monitor.ico</url>
<title>Making IT Easy</title>
</image>
		<item>
		<title>Downadup/Conflicker spreading havoc</title>
		<link>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/</link>
		<comments>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 09:04:05 +0000</pubDate>
		<dc:creator>Gunthy</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conflicker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://gunthy.m0nk3y.com/blog/?p=186</guid>
		<description><![CDATA[It&#8217;s been a while now that this worm has been spreading around on the Net, but apparently after all this time, it&#8217;s still out there, alive and kicking more than ever before. Downadup is one of the nastiest worms I&#8217;ve seen in my professional history. Having quite the amount of hands-on experience with it myself, [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while now that this worm has been spreading around on the Net, but apparently after all this time, it&#8217;s still out there, alive and kicking more than ever before.</p>
<p>Downadup is one of the nastiest worms I&#8217;ve seen in my professional history. Having quite the amount of hands-on experience with it myself, I can say that I haven&#8217;t seen such a persistent one before. And I&#8217;m not alone&#8230; F-Secure reported Friday in a <a href="http://www.f-secure.com/weblog/archives/00001584.html" target="_new">blog-post</a> that they estimate the number of affected machines to be over 8 million. <em>EIGHT MILLION!!!</em> My god&#8230;</p>
<p>So what happened? Well the worm seems to be detected first late September, using a flaw in one of Windows&#8217; services which allowed it to brute-force account passwords it spread rapidly. Once successful, it starts spreading itself through network shares, USB-sticks and other computers affected by the same security hole. Late October, Microsoft released an emergency patch to fix the hole, but a lot of machines still remain unpatched, thus very vulnerable.</p>
<p>A lot of corporate networks got infected as the worm spread havoc using the exploit. It locked users out of their accounts by keeping on guessing the password. Once on the machine, it starts securing the places it uses by removing all access rights to parts of the file system and registry, making it very hard to remove. Once your network is infected, it feels like your efforts to wipe out the worm are like carrying water to the sea. Counter-measures like installing the MS-patch and updating your anti-virus solution do help, but seem to only slow down the spreading. Use of USB sticks should definitely be heavily restricted, or if possible be banned completely.</p>
<p>To make things worse, the worm in some cases renders the infected computer useless, using methods like stopping services or using excessive bandwidth. It&#8217;s ability to install third-party malware such as trojans and other viruses, which gives full control over the machine to the worm author(s), doesn&#8217;t help either.</p>
<p>I think we haven&#8217;t seen the last of this one yet. The biggest question I think is, if you ever get your network clean again, how can you be sure no remnants are left behind. After all, as with any virus or malware, can you ever be sure you are completely safe? I guess only time will tell&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.gunthy.net/blog/2009/01/downadupconflicker-spreading-havoc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

