Downadup Worm — When Will the Next Shoe Drop?
alphadogg writes "The Downadup worm — also called Conflicker — has now infected an estimated 10 million PCs worldwide, and security experts say they expect to see a dangerous second-stage payload dropped soon. 'It has the potential to infect about 30% of Windows systems online, a potential 300 to 350 million PCs,' says Don Jackson, director of threat intelligence in the counter threat unit at SecureWorks. The worm, first identified in November and suspected to have originated in the Ukraine, is quickly ramping up, and while Downadup today is not malicious in the sense of destroying files — its main trick is to block users from accessing antivirus sites to obtain updates to protect against it — the worm is capable of downloading second-stage code for darker purposes."
the worm is capable of downloading second-stage code for darker purposes."
So it might download vista?
And now we rediscover why monocultures don't work (and are generally not found) in nature.
It is a miracle that curiosity survives formal education. - Einstein
Use a hardware router, use a real anti-virus program that actually publishes updates everyday (Nod32 for me), and use a browser where you can kill anything that tries to auto install itself (firefox, chrome, etc).
And don't forward or respond to chain emails!
You'll all thank me when I deploy the second stage to install and run SETI@home and discover alien intelligence.
-Virus Author
Windows is actually far more secure than Linux. Get the facts, people.
There's a more technical examination of the virus at https://forums.symantec.com/t5/Malicious-Code/Downadup-Small-Improvements-Yield-Big-Returns/ba-p/381717
"Politicians and diapers must be changed often, and for the same reason."
".. that I can't get windows apps to do what i want without crashing, but it runs teh evil viruses perfectly?"
Because there is a 100% correlation between a virus crashing and a virus writer's lost profit. With most legitimate software, a crash leaves only one practical option: keep using the crapware and hope it doesn't crash again.