Author Topic: Worm being released tomorrow:  (Read 2036 times)

0 Members and 1 Guest are viewing this topic.

Offline Rebel

  • Stick a fork in us. We're done.
  • Administrator
  • Hero Member
  • *****
  • Posts: 16808
  • Reputation: +1259/-215
Worm being released tomorrow:
« on: March 31, 2009, 07:40:27 AM »
Quote



                    National Cyber Alert System

              Technical Cyber Security Alert TA09-088A


Conficker Worm Targets Microsoft Windows Systems

   Original release date: March 29, 2009
   Last revised: March 30, 2009
   Source: US-CERT


Systems Affected

     * Microsoft Windows


Overview

   US-CERT is aware of public reports indicating a widespread
   infection of the Conficker/Downadup worm, which can infect a
   Microsoft Windows system from a thumb drive, a network share, or
   directly across a corporate network, if the network servers are not
   patched with the MS08-067 patch from Microsoft.


I. Description

   Home users can apply a simple test for the presence of a
   Conficker/Downadup infection on their home computers.  The presence
   of a Conficker/Downadup infection may be detected if a user is
   unable to surf to their security solution website or if they are
   unable to connect to the websites, by downloading detection/removal
   tools available free from those sites:
   
   *
http://www.symantec.com/norton/theme.jsp?themeid=conficker_worm&inid=us_ghp_
link_conficker_worm
   * http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
   * http://www.mcafee.com
   
   If a user is unable to reach any of these websites, it may indicate
   a Conficker/Downadup infection.  The most recent variant of
   Conficker/Downadup interferes with queries for these sites,
   preventing a user from visiting them.  If a Conficker/Downadup
   infection is suspected, the system or computer should be removed
   from the network or unplugged from the Internet - in the case for
   home users.


II. Impact

   A remote, unauthenticated attacker could execute arbitrary code on
   a vulnerable system.


III. Solution

   Instructions, support and more information on how to manually
   remove a Conficker/Downadup infection from a system have been
   published by major security vendors.  Please see below for a few of
   those sites. Each of these vendors offers free tools that can
   verify the presence of a Conficker/Downadup infection and remove
   the worm:
   
   Symantec:
 
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-01
1316-0247-99

   Microsoft:
   http://support.microsoft.com/kb/962007
   
   http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
   
   Microsoft PC Safety hotline at 1-866-PCSAFETY, for assistance.

   US-CERT encourages users to prevent a Conficker/Downadup infection by
   ensuring all systems have the MS08-067 patch (see
   http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx),
   disabling AutoRun functionality (see
   http://www.us-cert.gov/cas/techalerts/TA09-020A.html), and
   maintaining up-to-date anti-virus software.


IV. References

 * Microsoft Windows Does Not Disable AutoRun Properly -
   <http://www.us-cert.gov/cas/techalerts/TA09-020A.html>

 * Virus alert about the Win32/Conficker.B worm -
   <http://support.microsoft.com/kb/962007>

 * Microsoft Security Bulletin MS08-067 - Critical -
   <http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx>

 * MS08-067: Vulnerability in Server service could allow remote code
   execution -
   <http://support.microsoft.com/kb/958644>

 * The Conficker Worm -
   <http://www.symantec.com/norton/theme.jsp?themeid=conficker_worm>

 * W32/Conficker.worm -
   <http://us.mcafee.com/root/campaign.asp?cid=54857>

 * W32.Downadup Removal Tool -
 
<http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-0
11316-0247-99> 

 ____________________________________________________________________

   The most recent version of this document can be found at:

     <http://www.us-cert.gov/cas/techalerts/TA09-088A.html>
 ____________________________________________________________________

   Feedback can be directed to US-CERT Technical Staff. Please send
   email to <cert@cert.org> with "TA09-088A Feedback VU#827267" in
   the subject.
 ____________________________________________________________________

   For instructions on subscribing to or unsubscribing from this
   mailing list, visit <http://www.us-cert.gov/cas/signup.html>.
 ____________________________________________________________________

   Produced 2009 by US-CERT, a government organization.

   Terms of use:

     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________
« Last Edit: March 31, 2009, 07:59:49 AM by Rebel »
NAMBLA is a left-wing organization.

Quote
There's a reason why patriotism is considered a conservative value. Watch a Tea Party rally and you'll see people proudly raising the American flag and showing pride in U.S. heroes such as Thomas Jefferson. Watch an OWS rally and you'll see people burning the American flag while showing pride in communist heroes such as Che Guevera. --Bob, from some news site

Offline asdf2231

  • would like to cordially invite you to the pants party!
  • Hero Member
  • *****
  • Posts: 6562
  • Reputation: +555/-162
  • VRWC Arts And Crafts Director
Re: Worm being released tomorrow:
« Reply #1 on: March 31, 2009, 07:59:16 AM »
I checked mine yesterday.

Good idea to see if your machines need De-Worming.




Build a man a fire and he will be warm for awhile.
Set a man on fire and he will be warm for the rest of his life...

Offline thundley4

  • Hero Member
  • *****
  • Posts: 40571
  • Reputation: +2222/-127
Re: Worm being released tomorrow:
« Reply #2 on: March 31, 2009, 08:04:55 AM »
All four of our computers have protection.


Offline NHSparky

  • Hero Member
  • *****
  • Posts: 24431
  • Reputation: +1278/-617
  • Where are you going? I was gonna make espresso!
Re: Worm being released tomorrow:
« Reply #3 on: March 31, 2009, 09:28:26 AM »
Put anti-virus on mine before it ever saw the Net.
“Any man who thinks he can be happy and prosperous by letting the government take care of him better take a closer look at the American Indian.”  -Henry Ford

Offline Toastedturningtidelegs

  • Holy Crap! Look at my
  • Hero Member
  • *****
  • Posts: 3759
  • Reputation: +218/-69
  • OBAMA PHONE!
Re: Worm being released tomorrow:
« Reply #4 on: March 31, 2009, 10:46:11 AM »
Can we start putting the ****ers who create this shit to death! :censored:
Call me "Asshole" One more time!

Offline AllosaursRus

  • Hero Member
  • *****
  • Posts: 11672
  • Reputation: +424/-293
  • Skip Tracing by Contract Only!
Re: Worm being released tomorrow:
« Reply #5 on: April 01, 2009, 07:29:25 PM »
Can we start putting the ****ers who create this shit to death! :censored:

I WISH! I have no idea what in the world posseses these fools to do this!
I'm the guy your mother warned you about!
 

Offline rich_t

  • Hero Member
  • *****
  • Posts: 7942
  • Reputation: +386/-429
  • TANSTAAFL
Re: Worm being released tomorrow:
« Reply #6 on: April 01, 2009, 07:32:26 PM »
I WISH! I have no idea what in the world posseses these fools to do this!

It's the same "let's **** with people" attitude that causes folks to run for Congress.

 :rotf:
"The American people will never knowingly adopt socialism. But, under the name of 'liberalism,' they will adopt every fragment of the socialist program, until one day America will be a socialist nation, without knowing how it happened." --Norman Thomas, 1944

Offline DixieBelle

  • Administrator
  • Hero Member
  • *****
  • Posts: 12143
  • Reputation: +512/-49
  • Still looking for my pony.....
Re: Worm being released tomorrow:
« Reply #7 on: April 01, 2009, 08:45:19 PM »
well my email went nuts today. (Apologies to some of you!!)
I can see November 2 from my house!!!

Spread my work ethic, not my wealth.

Forget change, bring back common sense.
-------------------------------------------------

No, my friends, there’s only one really progressive idea. And that is the idea of legally limiting the power of the government. That one genuinely liberal, genuinely progressive idea — the Why in 1776, the How in 1787 — is what needs to be conserved. We need to conserve that fundamentally liberal idea. That is why we are conservatives. --Bill Whittle

Offline TheSarge

  • Platoon Sergeant
  • Hero Member
  • *****
  • Posts: 9557
  • Reputation: +411/-252
Re: Worm being released tomorrow:
« Reply #8 on: April 01, 2009, 08:54:52 PM »
The hackers didn't seem interested in tangling with Mac.
Liberalism Is The Philosophy Of The Stupid

The libs/dems of today are the Quislings of former years.  The cowards who would vote a fraud into office in exchange for handouts from the devil.

If it walks like a donkey and brays like a donkey and smells like a donkey - it's Cold Warrior.  - PoliCon



Palin has run a state, a town and a commercial fishing operation. Obama ain't run nothin' but his mouth. - Mark Steyn

Offline 5412

  • Hero Member
  • *****
  • Posts: 2062
  • Reputation: +220/-78
Re: Worm being released tomorrow:
« Reply #9 on: April 02, 2009, 09:42:53 PM »
The hackers didn't seem interested in tangling with Mac.

Hi,

Well the son-of-a-bitch got one of my computers too.  I had a blank screen, restarted the computer and it started deleting files like you would not believe.  I re-loaded Vista and can get the computer open but cannot get on the internet to download the fix.

Went to Best Buy and they wanted $300 to fix it, and it is about four years old.  I can buy a new, faster one for $600 so that decision became a no-brainer.  Fortunately I have the data backed up and there is only one bit of data I would like to see if I can recover.  My son has been with EDS now for 20+ years and he will try to get the data for me on Saturday, then he will reboot the entire hard drive, reload Vista and the computer will go home with him.

I agree with finding a way to bust the idiot who has too much time on their hands to disrupt the lives of so many people.  My wife thinks it is someone who benefits from selling programs or hardware an if she is right, then the death penalty is not quite enough.....

regards,
5412

Offline EastFacingNorth

  • Math Geek
  • Full Member
  • ***
  • Posts: 250
  • Reputation: +32/-22
Re: Worm being released tomorrow:
« Reply #10 on: April 03, 2009, 12:26:20 AM »
The hackers didn't seem interested in tangling with Mac.

Meh.

Write completely different code that would infect, at maximum, 3% of all computers in the world?  Especially with a worm, why bother?
Taxation if and only if Representation.

The Founding Fathers only got it half right.