|
|||||||
| Register | Blogs | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Technical Discussion Formerly the Basement - Hardware and software nerds, unite! Who needs sunlight anyway?! |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
General
Join Date: Mar 2008
Location: Somewhere over the rainbo
Thanks: 0
Thanked 0 Times in 0 Posts
Character: Akaris
Class: Spiritmaster
Legion: Order of the Umbral Sanctum
Race: Asmodians
|
ATTN: Downadup Virus
VERY IMPORTANT: READ EVERYTHING IN THIS POST.
Detailed in this post is extremely important information regarding your PC's security. Recently, a very potent, and malicious worm [a type of virus] has been discovered. This worm goes by several aliases, including Downadup, Conficker, or Kido; most commonly known as Downadup or Conficker. This isn't your typical virus or worm. It can mask itself as anything it sees fit, and can go directly into Root directories. Method of infection can be anything from an infected file you downloaded such as a WMV or MP3, or as sinister as plugging in your USB drive (if it was infected from a public location like the library or school/work) and Windows auto running the device. Disabling AUTO RUN is not effective in stopping Downadup. You ARE AT RISK if you use Windows XP or Windows Vista, especially if you do not have Auto Updates on, or update frequently via manual updating. Downadup can mask itself and you may not even know you are infected. Once it infiltrates your system, it will edit your Windows Registry. After this is completed, the worm begins to override your firewall settings, allowing it to download malware from any number of hosts. This malware will only increase the damage to the PC. However, the creators of Downadup have yet to activate the second stage of the worm. Once they do, Downadup will do one of two things: 1). It will retrieve all your confidential files, personal information, passwords (online banking especially), and logins and send them to any numbers of hosts. 2). It will combine your PC into its botnet and attempt to hack (by brute force) anything it is targeted to. This is the fear of the Department of Homeland Security. With the current infection rate, it has the capability of hacking some of the most important data centers in the country if given the chance and enough time. This worm is now being monitored by US-CERT [U.S. Computer Emergency Readiness Team, in conjunction with the Department of Homeland Security] as well as the FBI Cyber Crimes unit. They have moved this into a possible cyberterror attack, and they are quite serious about it. According to newly released figures, 1 in every 16 Windows XP/Vista PCs are infected with Downadup. If you are not concerned about this virus, and do not take efforts to mitigate your risk of infection or to remove the worm if you are already infected, you may not only endanger your PC, but many others. The virus has a very advanced code, and can "mutate" to adapt to threats and increase its potency. The worm will spread from your PC to your friends, and it has a very high potential to destroy your life, enjoyment, and safety on the internet. Here is information taken directly from Symantec regarding the method of infection of the worm (thanks to Symantec for the info): http://www.symantec.com/security_res...408-99&tabid=2 (the threat level is listed as low, because the article is dated from November when the first variations of the worm were spotted. Do not be fooled, it is not a minor threat anymore) Symptoms of infection * Account lockout policies being reset automatically. * Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services are automatically disabled. * Domain controllers respond slowly to client requests. * System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager. * On websites related with Antivirus software, Windows system updates cannot be accessed.[15] How can you stop this worm from affecting you? Good question, and here are the best methods. * Update your Windows install immediately. Do it manually. The worm actually disables Auto Updates, so, this will prevent reinfection. * Update your Anti Virus software, and be sure you are using a good antiviral software. Do this manually as well. * Run a FULL SYSTEM SCAN on your PC after updating your Anti Virus software library. * Disable System Restore (Windows XP users) NOTE: Renable System Restore after testing and ensuring you are virus free!! Very important. * To do this follow these steps: 1. Click Start, right-click My Computer, and then click Properties. 2. In the System Properties dialog box, click the System Restore tab. 3. Click to select the Turn off System Restore check box. Or, click to select the Turn off System Restore on all drives check box. 4. Click OK. 5. When you receive the following message, click Yes to confirm that you want to turn off System Restore:You have chosen to turn off System Restore. If you continue, all existing restore points will be deleted, and you will not be able to track or undo changes to your computer. Do you want to turn off System Restore? After a few moments, the System Properties dialog box closes. You can also check your registry for the worm's entries: 1. Click Start > Run. 2. Type regedit 3. Click OK. 4. Navigate to and delete the following registry entry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\netsvcs\Parameters\"ServiceDll" = "[PATH OF WORM EXECUTABLE]" 5. Exit the Registry Editor Just because you do not have the registry key above, doesn't mean you are not infected. Keep that in mind. It may just not have reached that stage yet. You still need to do a FULL DEEP SCAN of your computer, including all your hard drives and your USB media.F-Secure has developed a tool to remove Downadup, but the above should also be used in conjunction with the tool. There is no one thing that makes you secure. It is using your logic, a good software suite, and even a router firewall to protect yourself. HERE IS THE REMOVAL TOOL FROM F-SECURE For additional reading see these articles or Google search "Downadup" or "Conficker": Downadup Worm Eats into 1 of Every 16 PCs - Business Center - PC World Microsoft's advice on Downadup leaves users open to attack, says US-CERT |
|
|
|
|
|
#5 (permalink) |
|
Star Officer
Join Date: Jan 2009
Thanks: 0
Thanked 0 Times in 0 Posts
Class: Spiritmaster
Race: Elyos
|
Cheers, Akaris!
This puppy has been particularly nasty, so yes... please be vigilant about keeping your system and your AV software up to date! Don't let that lull you into a false sense of security, Killer. Having Windows 7 in and of itself is no guarantee of safety. |
|
|
|
|
|
#6 (permalink) |
|
Dark Lord
Join Date: Apr 2007
Location: Mastering my Little One
Blog Entries: 10
Thanks: 0
Thanked 1 Time in 1 Post
Character: Lord and Master
Class: Templar
Legion: Don't click this
Race: Asmodians
Server: Undecided
|
It is if auto update is turned on as the fix for Vista and 7 would be already applied. XP OTOH needs a manual one.
|
|
|
|
|
|
#7 (permalink) | |||
|
Website Maintenance
Join Date: Jan 2009
Location: New Zealand
Thanks: 0
Thanked 301 Times in 100 Posts
Character: Cynic
Class: Sorcerer
Legion: PirateLords - o_O
Race: Asmodians
Server: Siel
|
For all its malicious nature the recommended countermeasures are pretty much standard.
Wouldn't loose too much sleep over it though an excuse to run a full pc scan is always good. __________________ ![]() Quote:
Quote:
Quote:
|
|||
|
|
|
|
|
#9 (permalink) |
|
Commander
Join Date: May 2008
Location: Seattle, WA.
Thanks: 0
Thanked 6 Times in 6 Posts
Character: Sign & JNee
Class: Gladiator
Legion: EpicFail
Race: Asmodians
Server: Ariel
|
A mod from darkfall forum site came on mmorpg.com today and started a thread called " Downadup", He seemed to be very upset at the time. I found out later that the forumfall site was down had has been down for quit some time now. I did not know what Downadup was at the time but now I do.
Thank you for the post. |
|
|
|



















Linear Mode
