View Full Version : April 1st Worm.... Keep a look out!
Altis1 03-30-2009, 08:32 PM Most of you know about this Conflicker virus that has been the talk in the PC security world as of lately. Sadly most don't. As a precaution all PC users should check to see if your system and anti-virus system are up to date and to run the March 09 version of the Malicious Software Removal Tool (http://www.microsoft.com/security/malwareremove/default.mspx).
Also here is some info about the worm (http://www.dhs.gov/ynews/releases/pr_1238443907751.shtm) from the Department of Homeland Security.
Vexrog 03-30-2009, 08:41 PM Man, saw this in the paper this morning. Wonder what will happen... guess we will wait and see.
Diortem 03-30-2009, 09:17 PM Ive been watching this story... admittedly not as closely over the last month, but then that happens when you are pretty sure you locked down your own home network.
Basically, there was a patch released in October for Windows that kills the internet/network way in. Now, however, it can also use autorun to get in, regardless of if the media has an autorun feature or not.
If you want to know if you COULD have it or not, open up IE and go to www.mcafee.com and www.microsoft.com. If you cant go to either, you may well be infected. If you can get to both, chances are you are clean. If you still have doubts, run that damn tool! (I just did to be safe on this machine... my office is still running it.)
Diortem 03-30-2009, 09:54 PM sooo..., what kind of stuff can it do?
edit: 2 files infected on my system so far, it been running for 5 minutes. doesnt look good.
right now, it blocks off sites that can help you clean it, and waits for further instructions. If you could go download the tool on the system you are scanning, what is infecting those files is likely something else.
Typhoon 03-31-2009, 08:11 AM well as far as my computer anti virus and so on protection my CA internet is out of date and windows firewall is off and im clean of all viruses
Diortem 03-31-2009, 09:37 AM well as far as my computer anti virus and so on protection my CA internet is out of date and windows firewall is off and im clean of all viruses
How do you know with an out of date AV?
Cheese 03-31-2009, 09:52 AM How exactly do you get this virus? Is it just from downloading infected files or is there another way?
Diortem 03-31-2009, 09:58 AM 1) Internet vulnerability (fixed back in October if you take updates from MS).
2) Autorun function. If you put ANY kind of writable media into an infected computer, the worm will write an autorun file and copy itself to the disc so that any machine that reads the disc without autorun turned off in a rather special way, it WILL infect the new machine. This includes CD-Rs, writable DVDs, disks, thumb drives, SD cards... literally ANYthing.
1) Internet vulnerability (fixed back in October if you take updates from MS).
2) Autorun function. If you put ANY kind of writable media into an infected computer, the worm will write an autorun file and copy itself to the disc so that any machine that reads the disc without autorun turned off in a rather special way, it WILL infect the new machine. This includes CD-Rs, writable DVDs, disks, thumb drives, SD cards... literally ANYthing.
So this could even infect things like my zune or camera? Thanks for warning me about this.
Artemas 03-31-2009, 11:37 AM Don't these people have any constructive activities? Like basketball or something?
Diortem 03-31-2009, 11:39 AM So this could even infect things like my zune or camera? Thanks for warning me about this.
Yep. Best advice, dont plug these things into other machines....
Second best advice, go online with the machine in question first and in IE, go to www.microsoft.com. If it can go, it "should" be safe. If it cant reach the page, do NOT plug it in.
LEGEND 03-31-2009, 12:06 PM The only way to protect yourself from this.
http://content.ytmnd.com/content/f/b/6/fb6ca75f026ad47322c5c7466905b539.jpg
Diortem 03-31-2009, 12:30 PM The only way to protect yourself from this.
http://content.ytmnd.com/content/f/b/6/fb6ca75f026ad47322c5c7466905b539.jpg
:lol::lol::lol:
Simply amazing!
Pixleh 03-31-2009, 01:27 PM So what if I am using Firefox? Is this just an IE thing?
Diortem 03-31-2009, 01:49 PM So what if I am using Firefox? Is this just an IE thing?
It may well stop you with Firefox as well, but it WILL with IE, so I would use that as my marker to be safe...
However, do NOT make the mistake of thinking this is just a browser issue. All this is, is the virus' front line defense. It's trying to prevent you from getting to a site with programs to wipe it out.
What it will actually do, we frankly dont know yet. It's only other known function right now is to dial out onto the network for more machines to spread to, and to currently about 500 sites, one of which could give it instructions on what to do next. Tomorrow, that list goes up to 50,000 sites.
The current theory is this is going to be part of a massive hack-job with infected machines marching to command, but we just dont know yet.
LEGEND 03-31-2009, 02:01 PM So what if I am using Firefox? Is this just an IE thing?
As Dio said a browser is only the first line of defence against viruses etc. There are many other ways you could catch it. A friend could have lent you his USB stick, which the virus could have copied itself onto from his computer.
As soon as you insert it into your PC it will copy itself onto yours and you will be infected as well.
halokilla2008 03-31-2009, 11:56 PM i have 2 firewalls and 2 anti virus things running so if somethign happens im ready
Vault Dweller 04-01-2009, 12:58 AM Legend: awesome picture. Truly awesome.
I thought I read something on Yahoo! news that it was, among other things, a keystroke logger. Or had some other way of nabbing credit card numbers and the like.
I got an April Fool's joke for the people who create and spread this crap. It goes something like this:
Me: "Knock, knock"
Internet @$$hat: "Who's there?"
Me: "Brained"
Internet @$$hat: "Brained who?"
Me: "Brained you, with this baseball bat"
Joke's over. I win.
FinalWhiteDove 04-01-2009, 03:05 AM Thank goodness I have autorun turned off, I see it as pointless...
I have a firewall in my router and no antivirus and haven't got anything yet.
However, I'm planning on moving this computer to Linux sometime in the near future, due to being fed up with having to deal with crap like this because Microsoft can't make a secure OS, infact the only thing that's stopping me from moving full time is that I want to be able to play any and all games on Linux.
-FWD
Typhoon 04-01-2009, 04:19 AM How do you know with an out of date AV?
because i run a virus scan every few months and then get rid of the program for extra space
FinalWhiteDove 04-01-2009, 01:35 PM because i run a virus scan every few months and then get rid of the program for extra space
Why don't you just use clamwin, smallest AV for Windows, no real time scanning but small and ALWAYS knows about the latest viruses.
Diortem 04-01-2009, 02:31 PM because i run a virus scan every few months and then get rid of the program for extra space
....how big is your HD that you cant spare 150MB max for security tools?
Why don't you just use clamwin, smallest AV for Windows, no real time scanning but small and ALWAYS knows about the latest viruses.
....real time = mandatory these days.
slik1000 04-01-2009, 03:09 PM ....how big is your HD that you cant spare 150MB max for security tools?
....real time = mandatory these days.
maybe he means processing power. McAffee owns my CPU
FinalWhiteDove 04-01-2009, 04:17 PM ....real time = mandatory these days.
Why because people are lazy?
Diortem 04-01-2009, 04:45 PM Why because people are lazy?
No... how many games do you have that autoupdate? How many utilities? Your files CHANGE now, just matter of fact... so to play it safe and make sure something didnt sneak in on even your trusted stuff... you SHOULD have one.
FinalWhiteDove 04-02-2009, 03:53 AM No... how many games do you have that autoupdate? How many utilities? Your files CHANGE now, just matter of fact... so to play it safe and make sure something didnt sneak in on even your trusted stuff... you SHOULD have one.
Okay, fair enough for most people, however, why should I trust my computer to some antivirus company, or firewall company? Fact is, some of them make the threats in the first place just so you HAVE to buy their product.
Fact is I KNOW my computer, I am paranoid enough to lock down every part of windows that I can and have enough free/open source apps to keep me going but the fact is that I just can't bring myself to trust the applications from the "bigger" companies and IMHO they use too many resources for me to bother with them and protect against too little threats, they also do horrible things to your computer like patching the kernel *cough* Norton *cough*.
With the exception of nod32 and kaspersky, which do not take up many resources and are updated regularly (like every hour). But I still don't see a need, for myself at least or people that never visit any websites that they shouldn't, always check they have the latest updates and know their computer enough to lock it down, then what is the problem?
Diortem 04-02-2009, 10:25 AM Okay, fair enough for most people, however, why should I trust my computer to some antivirus company, or firewall company?
Are you alone on your network? Do you trust the others on your network to do as you have? If so, then by all means, you have the right idea... if not, you do want barriers between you and them. Trust me, I should know. I have 2 brothers with me....
1 has a mac, so I frankly dont give a damn what he does, he cant infect me with anything he gets, but the other.... windows XP, goes to pron sites... and has broken his system down with viruses so bad it didnt boot half the time till I reset it.
I doubt he learned his lesson aside from "computers suck."
I dont have that luxury to trust the others on my network to do the right thing enough to not worry about it, and I know Im more likely in the majority here.
Fact is, some of them make the threats in the first place just so you HAVE to buy their product.
Proof? That's quite the charge to bring down on a professional software security company.
Fact is I KNOW my computer, I am paranoid enough to lock down every part of windows that I can and have enough free/open source apps to keep me going but the fact is that I just can't bring myself to trust the applications from the "bigger" companies and IMHO they use too many resources for me to bother with them and protect against too little threats, they also do horrible things to your computer like patching the kernel *cough* Norton *cough*.
I dont trust Norton either... first thing I did when I got my office system home was uninstall Norton and replace it with McAfee.
With the exception of nod32 and kaspersky, which do not take up many resources and are updated regularly (like every hour). But I still don't see a need, for myself at least or people that never visit any websites that they shouldn't, always check they have the latest updates and know their computer enough to lock it down, then what is the problem?
As I said, we now live in a time where if someone else doesnt do the right thing on your network, you can suffer, too. This new worm is the first to really press that home.
FinalWhiteDove 04-02-2009, 11:12 AM Are you alone on your network? Do you trust the others on your network to do as you have? If so, then by all means, you have the right idea... if not, you do want barriers between you and them. Trust me, I should know. I have 2 brothers with me....
1 has a mac, so I frankly dont give a damn what he does, he cant infect me with anything he gets, but the other.... windows XP, goes to pron sites... and has broken his system down with viruses so bad it didnt boot half the time till I reset it.
I doubt he learned his lesson aside from "computers suck."
No, I'm not alone on my network, I live with my Girlfriend :), and I'm teaching her everything I know, and she knows better than to install something just because it looks "cute".
I dont have that luxury to trust the others on my network to do the right thing enough to not worry about it, and I know Im more likely in the majority here.
Yeah, I know what you mean, which is why I'd always lock down anything on my network and when I get serious money, I plan on setting up a more advanced security network with in the network, in the mean time, I lock down everything and make sure I'm the only one that can do any real changes to anything!
Proof? That's quite the charge to bring down on a professional software security company.
Fair enough, I don't actually have any proof, but it's something I heard a while ago from someone (I can't remember who).
I dont trust Norton either... first thing I did when I got my office system home was uninstall Norton and replace it with McAfee.
McAfee, ugh, that's even worse, AFAIK it detects less than Norton.
As I said, we now live in a time where if someone else doesnt do the right thing on your network, you can suffer, too. This new worm is the first to really press that home.
Anyone that wants to get on my network has to abide by my rules and also I make sure that the computer on the network can't talk to each other, only the router.
-FWD
Diortem 04-02-2009, 01:11 PM No, I'm not alone on my network, I live with my Girlfriend :), and I'm teaching her everything I know, and she knows better than to install something just because it looks "cute".
I WISH I could get away with only having people on my network who will listen. Sadly, both these guys think too much like Master Shake to learn anything in these regards.
Yeah, I know what you mean, which is why I'd always lock down anything on my network and when I get serious money, I plan on setting up a more advanced security network with in the network, in the mean time, I lock down everything and make sure I'm the only one that can do any real changes to anything!
Again... brother bitch. I really am kinda strapped here.
Fair enough, I don't actually have any proof, but it's something I heard a while ago from someone (I can't remember who).
That tends to be what I hear as a response, why I cant take it seriously.
McAfee, ugh, that's even worse, AFAIK it detects less than Norton.
Actually, no...
http://www.av-comparatives.org does independant tests... Mcafee did better.
Anyone that wants to get on my network has to abide by my rules and also I make sure that the computer on the network can't talk to each other, only the router.
-FWD
You mean you keep sharing disable? Or something else? (THIS I would love to know the secrets of, actually.... I dont care so much if my gaming rig can talk or be talked to... it's for games... but if I can keep others from talking with my office laptop....)
Typhoon 04-02-2009, 02:31 PM ....how big is your HD that you cant spare 150MB max for security tools?
500gb... its just full .. and i mean full
FinalWhiteDove 04-02-2009, 03:49 PM I WISH I could get away with only having people on my network who will listen. Sadly, both these guys think too much like Master Shake to learn anything in these regards.
Again... brother bitch. I really am kinda strapped here.
Who is Master Shake? Yeah, I know what that's like, on my old network my sister would constantly shout at me, lol.
That tends to be what I hear as a response, why I cant take it seriously.
Yeah, okay :)
Actually, no...
http://www.av-comparatives.org does independant tests... Mcafee did better.
Just reading through the document now, thanks for this =)
You mean you keep sharing disable? Or something else? (THIS I would love to know the secrets of, actually.... I dont care so much if my gaming rig can talk or be talked to... it's for games... but if I can keep others from talking with my office laptop....)
Oh I do alot:
Disable ALL (printer, file, public folder and media) sharing (and the main shares in the C:\ Drive (i.e. $IPC))
Turn off Network Discovery
Change the Network and Workgroup names.
Disable Netbios over TCP/IP (on ALL connections).
Disable IPv6 (it's not needed yet anyway).
Turn off system restore as that can store viruses.
Turn off autoplay so that no viruses or hacks can get in that way.
Disable remote connection.
Stop services which I have no need for and won't stop my computer from playing up if I do.
Disable LM Hosts Lookup (on ALL connections).
Disable and change the name of the guest and administrator accounts.
Hack the registry to make some things more secure.
That's a few things I do, if you'd like to find out more, feel free to ask me :)
As for the Router, I make sure that SSID Broadcasting is disabled, always on highest encryption, get a randomised password from GRC:
https://www.grc.com/passwords.htm
Make sure I only allow certain MAC addresses to:
A) Access the network
B) Access the internet (and only at certain times)
Unfortantly I only have a normal home router so I'm limited on what I can do but I do my best.
Anything else you'd like to know we can chat and discuss ideas, it's always good to bounce ideas off of someone and find out where I'm going wrong, lol.
Diortem 04-02-2009, 03:55 PM Id love to chat, though Im afraid this will be more you teaching me alot here... I know my own machines, but networking has always been a bit of a darkspot for me.
FinalWhiteDove 04-02-2009, 04:20 PM Id love to chat, though Im afraid this will be more you teaching me alot here... I know my own machines, but networking has always been a bit of a darkspot for me.
Yeah, I know what you mean, fortunately I've read a few of books on the subject and I also took a course in CCNA.
So if you'd like to know just hit me up over MSN or something.
BTW, Love that you have Megabyte as your Avatar, I loved that show, shame it had to end so quickly!!!
Diortem 04-02-2009, 04:38 PM later, definately. (though I usually prefer AIM... the the whole one window thing is awesome.)
As for reboot... you dont know the half... lets just say there is a theme with it follows with my two computers....
Deamon: http://i4.photobucket.com/albums/y130/ACIkari/desktopfordeamon.jpg <---gaming rig
Hexadecimal: http://i4.photobucket.com/albums/y130/ACIkari/desktop.jpg <---the office
marshallladd 04-02-2009, 04:56 PM Who is Master Shake?
Master shake
http://z.about.com/d/animatedtv/1/7/0/R/MAsterShake.jpg
FinalWhiteDove 04-02-2009, 05:03 PM later, definately. (though I usually prefer AIM... the the whole one window thing is awesome.)
What do you mean one window, if you mean one window for every conversation I use Pidgin (Multi-IM) for that or amsn for MSN.
As for reboot... you dont know the half... lets just say there is a theme with it follows with my two computers....
Deamon: http://i4.photobucket.com/albums/y130/ACIkari/desktopfordeamon.jpg <---gaming rig
Hexadecimal: http://i4.photobucket.com/albums/y130/ACIkari/desktop.jpg <---the office
That is AWESOME!!!!
FinalWhiteDove 04-02-2009, 05:04 PM Master shake
http://z.about.com/d/animatedtv/1/7/0/R/MAsterShake.jpg
Oh, that's the guy from Aqua Teen Hunger Force? Isn't it?
marshallladd 04-02-2009, 05:21 PM ^bingo.
Awoll SGF 04-03-2009, 04:03 AM http://kelubar.szm.sk/pics/dune/dune%20worm.jpg
Apparently it's worse than people thought.
FinalWhiteDove 04-03-2009, 01:42 PM http://kelubar.szm.sk/pics/dune/dune%20worm.jpg
Apparently it's worse than people thought.
Is that a little maker from Dune?
Diortem 04-03-2009, 04:25 PM Its hadly an adult, isnt it? Still a maker is a maker.. and spice is spice...
FinalWhiteDove 04-03-2009, 05:49 PM Its hadly an adult, isnt it? Still a maker is a maker.. and spice is spice...
... and the spice must flow :)
LEGEND 04-04-2009, 11:04 AM All this talk of spice is making me hungry...
koolaid21 04-04-2009, 12:48 PM so who let this worm out or created it
DemonicDerek 04-04-2009, 07:28 PM Seriously... I think the April Fools joke is that you all think there is a worm out there and yet there probably isn't...
Then again it could be the Anti-Virus industry just trying to get more people to buy their products.
I have Trend Micro Pc Cillin Internet Security and it is da bomb... I haven't had a virus in well since we got it.
The real problem with viruses is that you need to just not visit those shady sites, and if you really need porn on your computer just use torrents... or go buy it legally from the store...
I don't do either (google image search is good enough for me...).
Seriously people learn to recognize shady sites and when to not visit a site when it tries to download crap to your computer automatically and etc.
Vault Dweller 04-04-2009, 09:30 PM ^^ I thought that thing was a "graboid" from Tremors.
|
|