The Cherubim Knights
Would you like to react to this message? Create an account in a few clicks or log in to continue.

Immediate Warning and Notice [Downadup Worm]

4 posters

Go down

Immediate Warning and Notice [Downadup Worm] Empty Immediate Warning and Notice [Downadup Worm]

Post by Godzuki Thu 22 Jan - 6:19

For those of you who do not regularly check the Guild Wars Guru forum, there is an important notice about a dangerous worm that is estimated to have infected 1 out of every 16 Windows XP/Vista computers. The full thread can be found here:

http://www.guildwarsguru.com/forum/showthread.php?t=10351098

I suggest everyone read the first post thoroughly and clean their computers as soon as possible if they are using Windows XP/Vista. Please notify any family or friends that you may think are also at risk. Here is a copy/paste of the first post:

VERY IMPORTANT: READ EVERYTHING IN THIS POST.

Detailed in this post is extremely important regarding your PC's security. Recently, a very potent, and malicious worm [a type of virus] has been discovered. This worm goes by several aliases, including Downadup, Conficker, or Kido; most commonly known as Downadup or Conficker.

This isn't your typical virus or worm. It can mask itself as anything it sees fit, and can go directly into Root directories. Method of infection can be anything from an infected file you downloaded such as a WMV or MP3, or as sinister as plugging in your USB drive (if it was infected from a public location like the library or school/work) and Windows auto running the device. Disabling AUTO RUN is not effective in stopping Downadup.

You ARE AT RISK if you use Windows XP or Windows Vista. Downadup can mask itself and you may not even know you are infected. Once it infiltrates your system, it will edit your Windows Registry. After this is completed, the worm begins to override your firewall settings, allowing it to download malware from any number of hosts. This malware will only increase the damage to the PC. However, the creators of Downadup have yet to activate the second stage of the worm. Once they do, Downadup will do one of two things:

1). It will retrieve all your confidential files, personal information, passwords (online banking especially), and logins and send them to any numbers of hosts.

2). It will combine your PC into its botnet and attempt to hack (by brute force) anything it is targeted to.
This is the fear of the Department of Homeland Security. With the current infection rate, it has the capability of hacking some of the most important data centers in the country if given the chance and enough time.

This worm is now being monitored by US-CERT [U.S. Computer Emergency Readiness Team, in conjunction with the Department of Homeland Security] as well as the FBI Cyber Crimes unit. They have moved this into a possible cyberterror attack, and they are quite serious about it. According to newly released figures, 1 in every 16 Windows XP/Vista PCs are infected with Downadup.

If you are not concerned about this virus, and do not take efforts to mitigate your risk of infection or to remove the worm if you are already infected, you may not only endanger your PC, but many others. The virus has a very advanced code, and can "mutate" to adapt to threats and increase its potency. The worm will spread from your PC to your friends, and it has a very high potential to destroy your life, enjoyment, and safety on the internet.

Here is information taken directly from Symantec regarding the method of infection of the worm (thanks to Symantec for the info):

http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99&tabid=2

(the threat level is listed as low, because the article is dated from November when the first variations of the worm were spotted. Do not be fooled, it is not a minor threat anymore)


How can you stop this worm from affecting you? Good question, and here are the best methods.

  • Update your Windows install immediately. Do it manually. The worm actually disables Auto Updates, so, this will prevent reinfection.

  • Update your Anti Virus software, and be sure you are using a good antiviral software. Do this manually as well.

  • Run a FULL SYSTEM SCAN on your PC after updating your Anti Virus software library.

  • Disable System Restore (Windows XP users)
  • To do this follow these steps:



  1. Click Start, right-click My Computer, and then click Properties.
  2. In the System Properties dialog box, click the System Restore tab.
  3. Click to select the Turn off System Restore check box. Or, click to select the Turn off System Restore on all drives check box.
  4. Click OK.
  5. When you receive the following message, click Yes to confirm that you want to turn off System Restore:You have chosen to turn off System Restore. If you continue, all existing restore points will be deleted, and you will not be able to track or undo changes to your computer.

    Do you want to turn off System Restore?

    After a few moments, the System Properties dialog box closes.

You can also check your registry for the worm's entries:



  1. Click Start > Run.
  2. Type regedit
  3. Click OK.
  4. Navigate to and delete the following registry entry:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters"ServiceDll" = "[PATH OF WORM EXECUTABLE]"


  5. Exit the Registry Editor


F-Secure has developed a tool to remove Downadup, but the above should also be used in conjunction with the tool. There is no one thing that makes you secure. It is using your logic, a good software suite, and even a router firewall to protect yourself.

HERE IS THE REMOVAL TOOL FROM F-SECURE

For additional reading see these articles or Google search "Downadup" or "Conficker":

http://www.pcworld.com/businesscenter/article/158085/downadup_worm_eats_into_1_of_every_16_pcs.html

http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9126478


We at Guild Wars Guru take your PC security seriously, and this warning is not intended to scare you, but make you knowledgeable about a very serious situation. I am taking personal responsibility to inform as many guru users of this threat as possible. I would encourage you to inform your family and friends of this threat, and to direct them in testing and removing if necessary, Downadup from their systems and home networks.


Last edited by Curatio Animus on Thu 22 Jan - 18:34; edited 1 time in total
Godzuki
Godzuki
Knight

Male
Number of posts : 118
Location : California
Registration date : 2008-04-27

Back to top Go down

Immediate Warning and Notice [Downadup Worm] Empty Re: Immediate Warning and Notice [Downadup Worm]

Post by Scion Thu 22 Jan - 11:40

I'm reading this and I'm like oh neat, sure, whatever.

Then I got to the part where it's also called Conficker, and I said oh, that's interesting, because I just took Conficker off my wife's laptop twice in this past month.

Scion
Scion
Scion
Lord

Male
Number of posts : 271
Location : Syracuse, New York
Registration date : 2008-03-15

Back to top Go down

Immediate Warning and Notice [Downadup Worm] Empty Re: Immediate Warning and Notice [Downadup Worm]

Post by Godzuki Thu 22 Jan - 18:12

I had a similar experience. I wasn't too worried about my own computer and ended up finding nothing. My mom's and sister's laptop, on the other hand, were a different story. Those two laptops interact with each other pretty often so I'm guessing one infected the other.
Godzuki
Godzuki
Knight

Male
Number of posts : 118
Location : California
Registration date : 2008-04-27

Back to top Go down

Immediate Warning and Notice [Downadup Worm] Empty Re: Immediate Warning and Notice [Downadup Worm]

Post by Lady Herodias Fri 23 Jan - 1:58

Yeah this is a pretty prevalent virus. It spread through the network at my job and infected several of the computers. Basically, it is capable of running some kind of software that detects passwords and disables computers. Many of the users couldn't log into their computers since it changed the passwords. I had it on my computer...but didnt find mine so I was find. The virus scan was instrusive and kept telling me it found it and deleted it. Lucky me...though it came back...the IT folks said for me not to worry they found an update to make sure it was cleaned off the systems.
Lady Herodias
Lady Herodias
Administrator

Female
Number of posts : 506
Location : Oregon
Other games played : 2 Moons, Lineage 2
Registration date : 2008-02-24

http://gunterandann.blogspot.com/

Back to top Go down

Immediate Warning and Notice [Downadup Worm] Empty Re: Immediate Warning and Notice [Downadup Worm]

Post by Pampered One Fri 23 Jan - 15:57

Finally installed my McAfee on my 2 gaming rigs and scanned them both. It was not there. Yay. But on my main comp I found 3 keyloggers called xxmmorpgx.xxx and on my other two xxxxxxx.pup's.

All in All not bad for 2 comps that have been unprotected for over 6 months. Bad boy.

Pampered
Pampered One
Pampered One
King

Male
Number of posts : 556
Location : Klamath Falls Oregon
Other games played : Lineage 2, 2 moons, CoH, CoV
Registration date : 2008-02-24

Back to top Go down

Immediate Warning and Notice [Downadup Worm] Empty Re: Immediate Warning and Notice [Downadup Worm]

Post by Sponsored content


Sponsored content


Back to top Go down

Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum