Background
The first samples for the Conficker/Kido/DownadUp (detected by
Trend Micro as
WORM_DOWNAD.A) were discovered in November 2008 with new
samples (detected as
WORM_DOWNAD.AD and
WORM_DOWNAD.KK) arriving in early 2009. DOWNAD
exploits a vulnerability in Windows that Microsoft patched
(MS08-067) in October.
DOWNAD.AD added the ability to spread through network shares
and removable storage devices (e.g. USB drives) using the
AutoRun function in Windows.
DOWNAD.KK shuts down security services, blocks infected
computers from connecting to security websites, and downloads a
Trojan. It also reaches out to other infected computers via
peer-to-peer communications services, and includes an algorithm
to update infected PCs.
What’s the goal of this worm?
It appears that the goal of this worm is to create a large
botnet of infected PCs so that its creators may at some point
send spam, steal personal information (user IDs, passwords,
credit card info, etc.) and direct users to malicious websites
used for phishing or downloading additional malware.
What’s happening on April 1st?
On April 1st, 2009, the latest variant (WORM_DOWNAD.KK) will
begin to modify the way in which it communicates with other
infected botnet nodes (PCs, servers), and will also increase the
number of machines it attempts to contact in order to infect
them. There is no evidence that the worm will do anything
beyond modifying its communications methods.
How
do I know whether my PC is infected?
Scan your PC using your Trend Micro product or
HouseCall to see
whether you are infected. If you discover that you are
infected, find instructions for removal below:
How do I protect my PC from being infected?
- Immediately install patches/updates for
MS08067 and other vulnerabilities as soon as vendors
release these patches. Configure your PC to receive
automatic updates and patches from Microsoft and software
vendors.
- Make sure your security software is
up to date.
- Disable the “Drive Auto-run” feature to avoid infections
from USB drives.
- Employ secure passwords using a combination of letters,
numbers and symbols and frequently change them.
- Take caution when searching online for
DOWNAD and Conficker information. There are reports of
rogue antivirus packages that are taking advantage of the
situation. They will tell you that you are infected and ask
you to pay money to download their application, which in
many cases turns out to be malware.
Additional Information:
Additionally, this threat is an example of the new breed of
Web threats being developed by cybercriminals who use multiple
techniques and protocols to infect and propagate their attacks.
The Trend Micro Smart Protection Network blocks threats before
they can enter your network and our correlated in-the-cloud web,
email and file reputation databases allow us to quickly analyze
and block new threats as they appear. Smart Protection
Network powers many of our consumer, SMB and Enterprise
solutions today.
Learn more.