Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Computer Security News
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Computer Security News The Latest Computer Security News

Reply
 
LinkBack Thread Tools
Old 04-28-2009, 03:05 AM   #1 (permalink)
Analyst, Security Team
 
sjb007's Avatar
 
Join Date: Dec 2007
Location: Lincoln UK
Posts: 2,290
OS: Windows 7 Premium x64

My System

Conficker.E set to self-destruct next week

The latest version of Conficker is set to self-destruct next week according to security researchers.

F-Secure, Trend Micro and SecureWorks are among those that believe Conficker.E - first spotted this April and probably created by the same attackers that since last fall let loose the Conficker.A through Conficker.C variants - has been designed to simply self-detonate on 5 May.

"It will simply self-destruct," said Mikko Hypponen, chief research officer at F-Secure, pointing out that researchers, who had been arguing over name for variants, agreed to skip past the name "Conficker.D" entirely to settle on the name "Conficker.E."

But even if Conficker.E does simply self-destruct as expected, that still leaves millions of Windows-based computers around the work infected with Conficker.C, which has become active this month in terms of beginning to try and lure victims to fake anti-virus sites - some dub it "fraudware" - to get victims to pay US$50 or so to get rid of Conficker.C.

"We're starting to see some revenue generation," said Phillip Porras, programme director in the computer sciences laboratory at SRI International, in a presentation at the RSA Conference. "We're starting to see some business models come out of it."

Security researchers in industry and government are using various means to monitor Conficker.C behaviour (which can block over 114 legitimate anti-virus sites and now works in conjunction with the botnet Waledec).

Porras said Conficker.C was involved in an elaborate process to sell fake anti-malware software. When it gets into infected machines, it can direct victims toward webites believed to be selling fraudware.

One of those sites appears to be registered in the Ukraine selling the SpywareProtect portfolio, associated with "Ukraine Bastion Trade Group," for example, he said. But Conficker was not necessarily created by this group and researchers are still in the dark about who originates and controls the complex Conficker command-and-control system.

Despite the efforts of the Conficker Working Group, a group which now has 300 experts from industry and government dedicated to do what they can to identity the source of Conficker and stop it, efforts so far have not been successful.

"They've gotten around blocks to shut it down," said Porras, noting the complexity of the Conficker effort suggests a gang, rather than one individual, sharing expertise.

As for the anticipated self-destruction of the Conficker.E variant, researchers say there are strange aspects of it.

"Conficker.E has two parts of it," said Joe Stewart, director of malware research at SecureWorks, describing it basically as breaking up what were earlier combined functions of scanning/spreading and getting downloads, such as through peer-to-peer rendezvous.

But Conficker.E, seen only since mid-April, never seemed to work that well - which was a surprise to researchers since the upgrade path so far for Conficker has been quite impressive technically.

"Some of the functionality in .E doesn't work," said Stewart. Conficker.E may be a new anti-malware attempt that simply wasn't good enough, or it may be a deliberate "distraction" by attackers to throw a little dust in the eyes of researchers. "They may be working on a more advanced version," he added.

http://www.techworld.com/news/index....&NewsID=114914
__________________
If we have helped you then please consider donating

Proud Member of ASAP & UNITE Since 2007
sjb007 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:10 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85