Colucci Norman
Digg icon reddit icon Stumbleupon icon
Print Email     Print Edition Stories

Tuesday, March 31, 2009

Worried about Conficker worm? Experts say, 'Don’t panic'

By Mass High Tech staff

The latest tool in the hackers’ attack on corporate computing is the so-called Conficker worm, which is set to be triggered in any infected computer tomorrow, April Fool’s Day. While the media has latched onto it as possibly the next Y2K, the reality is, it is not panic-worthy.

While the worm — also known as W32.Downadup — is considered a medium-level threat according to Sophos PLC’s website, it could possibly open up any Windows-based computer running Windows 95 through Vista to infection by other, possibly more serious problems, including making the computer a slave in a bot net, making it send out spam and malware to other computers to become infected.

The worm has been known about for at least six months, and all of the major PC security software firms — Sophos, Symantec Corp. and Kaspersky Lab Inc., among others — have removal tools easily available for download from their websites. There is even an official “Conficker Cabal” created to counter the effects of the worm. Among its founding members are Microsoft Corp., AOL LLC, Symantec and Lexington’s own Arbor Networks Inc.

Most security experts believe Conficker is an elaborate April Fool’s prank, said Roel Schouwenberg, senior research engineer at Kaspersky — an explanation the virus researcher finds doubtful.

“There is potential for these guys to do anything, pretty much,” Schouwenberg said. “They will use (their bot net), otherwise, they wouldn’t have gone to the trouble of getting part of it back.”

Kaspersky, with its U.S. headquarters in Woburn, was part of the Conficker Working Group, which stymied an original version of the worm’s bot net earlier this year. Conficker attackers worked hard to create a second version of the virus that would partially circumvent the working group’s tactics, Schouwenberg said. However, because of how well-known the worm is, experts say it is not a bigger threat than what most people face daily on a PC.

“People don’t need to be much more concerned about this than they need to be about any other viruses,” said Richard Wang, the Burlington-based manager of SophosLabs U.S., the research division of Sophos PLC.

And tomorrow isn’t really the day to be worried about, Wang said. “The date of April 1 is not necessarily the day that Conficker will do anything — it is the first day on which it might do anything. The criminals behind it may update it on the 10th of April, or the 1st of May.”

“Conficker itself is pretty well-known to the security community, so if you have security tools installed you are probably safe. If you want to go to a site and get a free removal tool, by all means do so but make sure your are going to a reputable site,” Wang said. “Go to one of the major (anti-virus) vendors — our own site or one of the others.”

For the latest tools and techniques to combat the worm, go to www.downadup.com.


 

Digg icon reddit icon Stumbleupon icon
Contact Editor Latest News

Comments

Please Login/Register to post comments.

No comments have been added or approved.

On the MHT blog now

Flagsuit wins another NASA Astronaut Glove Challenge

Southwest Harbor, Maine's Peter Homer won $450,000 in NASA's Astronaut Glove Challenge yesterday. This is Homer's second time winning the contest. Homer's first win in 2007 launched his startup, Flagsuit. Flagsuit is developing pressure suits using the same technology as Homer's prizewinning gloves -- for use as a wearable substitute for hyperbaric chambers used to treat conditions such as ...

Read More

Most Popular Stories
EmailedViewed
Stay Informed
Check which newsletter you'd like to receive.
TechFlash (Daily)
FinanceFlash (Daily)
BioFlash (Daily)
GreenFlash (Weekly)
Startup Report (Weekly)
Breaking news, MHT events, local announcements
RSS feeds
Your email:

Affiliate publications: ACBJ.com, Boston Business Journal, Bizjournals.com, Portfolio.com, Wired.com

Web Site Developed by Neptune Web, Inc.

Use of, registration on, this site constitutes acceptance of our User Agreement. Please read our Privacy Policy (updated) A publishing partner with Portfolio