-
Conficker update
A week ago, my Top Story in Windows Secrets Newsletter discussed what was known about the Conficker worm, how to protect your PC, and how to get disinfected. (Some vendors call the Conficker worm “Downadup” but they’re just two different names for the same thing.)
Much has happened since then. If you’re concerned about Conficker – and with many millions, if not tens of millions, infected, you should be – here’s what researchers have learned, and what you need to know.
CERT issued a Technical Cyber Security Alert that contradicts Microsoft’s advice about disabling Autorun. Since Conficker seems to be spreading rapidly via infected USB drives, and even camera memory cards, it would be well to heed CERT’s advice.
Eric Chien at Symantec has posted a series of blogs with many details about the worm. In order:
Downadup Peer to Peer Payload Distribution
Downadup: Small Improvements Yield Big Returns
Downadup: Attempts at Smart Network Scanning
Downadup: Playing with Universal Plug and Play
SANS Internet Storm Center reports that Conficker has successfully infected Windows Embedded machines.
And lest you think some of the press is losing its perspective, drop by Rob Rosenberger’s Vmyths site for a hilarious, dead-on look at truth and fiction in the Conficker/Downadup milieu. Good on ya, Rob.