in

Microsoft Philippines Community

A community for users, customers, and partners of Microsoft products in the Philippines :)

Conficker Worm Going Around

Last post 01-28-2009 7:24 PM by Crashoverride. 13 replies.
Page 1 of 1 (14 items)
Sort Posts: Previous Next
  • 01-08-2009 8:23 PM

    • jpaloma
    • Top 10 Contributor
      Male
    • Joined on 07-09-2004
    • Singapore
    • Posts 2,527
    • Points 25,652
    • MVP

    Conficker Worm Going Around

    Word has it that this worm is going around certain regions in Asia. 

    From the Microsoft Malware Protection Center

    As expected, we are seeing another wave of attacks exploiting the vulnerability detailed in security bulletin MS08-067.

    Early last week we blogged about MS08-067 exploits. At that time, the number of exploits in the wild was still low and they were mostly targeted attacks. However, during the weekend we started receiving customer reports for new malware that exploits this vulnerability. During the last two days that malware gained momentum and as a result we see an increased support call volume. The SHA1 hash of the malware is 0x5815B13044FC9248BF7C2DBA771F0E6496D9E536 and we detect it as Worm:Win32/Conficker.A.

    Regarding the worm Worm:Win32/Conficker.B

    Worm:Win32/Conficker.B is a worm that infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. It may also spread via removable drives and weak administrator passwords. It disables several important system services and security products.
     
    Microsoft strongly recommends that users apply the update referred to in Security Bulletin MS08-067 immediately.
    Jay Paloma
    Security is a State of Mind
  • 01-09-2009 12:40 PM In reply to

    Re: Conficker Worm Going Around

    And well it could be prevented by having the current windows update/patches in your system and checking USB/removable drives and similar before introducing such to any PC system.
    Sr. Security Analyst - RTL APAC, CEH
  • 01-09-2009 12:43 PM In reply to

    Re: Conficker Worm Going Around

    This is what we troubleshoot yesterday, the whole day and night Sleep

  • 01-09-2009 1:39 PM In reply to

    Re: Conficker Worm Going Around

    The bloody patch was released in October; an out-of-band one at that (which would have already sent an administrator worth his salt a-patching).

    I've a script which "tries" to identify the rogue services randomly generated by this worm (I didn't include any cleanup mechanism for lack of time):

    http://badzmanaois.blogspot.com/2009/01/confickervbs-conficker-wormdownad.html

  • 01-09-2009 6:21 PM In reply to

    Re: Conficker Worm Going Around

    Hmmm well you should get not only the removal for the actual file but as well as the remnant files.... Patch up dude and clog down the use of removable drives and online drives.

    rockshock_zid:

    This is what we troubleshoot yesterday, the whole day and night Sleep


    If you still have such issue buzz us we may extend some tools for you to use... for cleanup

    Sr. Security Analyst - RTL APAC, CEH
  • 01-14-2009 2:29 PM In reply to

    Re: Conficker Worm Going Around

    I sure want to keep this thread alive for reason that we found significant number of Conficker/Downad Worm variants that has evolved significantly now using the original rootkit module,brute force and dictionary attack on user password, file and registry locking sequence, autorun worm addetives, DoS capability as well as DNS poisioning package all in one - with the end product of backdoor access.

    Again PLEASE proceed to Windows Update ASAP and update your Latest Security Application to the most recent pattern, as well as locking down external storages alien to your infrastructure or home PC's.

    Just yesterday we found 2 unique variant in South East asia.

    Sr. Security Analyst - RTL APAC, CEH
  • 01-14-2009 5:35 PM In reply to

    • jpaloma
    • Top 10 Contributor
      Male
    • Joined on 07-09-2004
    • Singapore
    • Posts 2,527
    • Points 25,652
    • MVP

    Re: Conficker Worm Going Around

    The Jan 2009 MSRT includes the removal for Conficker.

    Jay Paloma
    Security is a State of Mind
  • 01-14-2009 6:03 PM In reply to

    Re: Conficker Worm Going Around

    is it possible that we have already applied the patches but there are still damages done to the computers infected?

     because from our experience after applying the patch our anti-virus stopped its autoprotect against the downadup(also known as conficker worm)

    points is, is applying the patch enough or there are further steps to be done?

  • 01-14-2009 6:17 PM In reply to

    Re: Conficker Worm Going Around

    aside patch from microsoft, what we did is we also run removal tool from our anti virus.

  • 01-14-2009 7:24 PM In reply to

    • jasperjugan
    • Top 10 Contributor
      Male
    • Joined on 07-10-2003
    • Feel the LOVE Generation!
    • Posts 9,397
    • Points 87,858

    Re: Conficker Worm Going Around

    FYI guys, patching alone is not a guarantee. You need to make sure that the whole network is clean. As mentioned in the articles it spreads via 4 ways generally:

    1. removal drives

    2. network shares

    3. MS08-067 exploit

    4. trying to run itself using a weak admin password list

    So meaning, even if you deployed the patch, if one of these symptoms are still present, chances are it will spread out (especially if it exploits as admin account).

     

    Also, we DO NOT recommend logging in using domain account especially domain admin accounts when cleaning up. use the local user accounts as much as possible.

    Jasper Jugan
    Technical Account Manager
  • 01-15-2009 4:23 PM In reply to

    • jpaloma
    • Top 10 Contributor
      Male
    • Joined on 07-09-2004
    • Singapore
    • Posts 2,527
    • Points 25,652
    • MVP

    Re: Conficker Worm Going Around

    Jay Paloma
    Security is a State of Mind
  • 01-21-2009 3:01 PM In reply to

    Re: Conficker Worm Going Around

    Bump...

     

    "Widespread Confickr/Downadup Worm Hard To Kill - Attack more dangerous in the potential of its scope and the way it was waged than the worm itself": Their biggest victims have been the enterprise, not the typical home user, experts note. And that could mean millions of enterprise bots. "There's still no botnet activity. But that could easily change at any given moment," says Patrik Runald, chief security advisor for F-Secure, which has been watching the worm closely. "These millions of PCs try to connect to hundreds of Websites daily, and the people behind this could easily change the behavior of an infected computer if they wanted to."  

    How did enterprises fall for a worm? Security experts say poor patch management, antivirus software shortcomings, and lack of detection of outbound command and control traffic contributed to the worm's success.

    http://www.darkreading.com/story/showArticle.jhtml?articleID=212901489
  • 01-28-2009 3:13 PM In reply to

    Re: Conficker Worm Going Around

    sirs,

     are both downadup and downadup.b covered by MS08-067 patch?

     

  • 01-28-2009 7:24 PM In reply to

    Re: Conficker Worm Going Around

    those are just variants or so different naming convention for conficker ( as detected by other AV products ), and MS08-067 exploit is the one its using and recently other avenues as well.

    Just an update there is now are 2 new variant Conficker.c and conficker.D

    This would help

    http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx

    Sr. Security Analyst - RTL APAC, CEH
Page 1 of 1 (14 items)
Copyright © 2008 Microsoft Philippines Community

Powered by Community Server (Commercial Edition), by Telligent Systems