If you have been getting tempting messages with video links in your accounts in social networking sites such as Facebook, Twitter,
IT Exploring Internet Explorer 8, Myspace, Bebo, Friendster and Hi5, beware. Any attempt to download the promised video will make you another victim of Koobface, a worm that could steal critical and personal information from your computer.
The government's India Computer Emergency Response Team has warned that Koobface, a play on the name of social networking site Facebook, comes with an enticing tagline and spreads by spamming the contacts of the victim on networking sites.
With more than 3 million members of Facebook alone in India, Koobface's potential for wreaking havoc on the country's computer systems is immense — a fact that has prompted the government to issue the warning alert.
Typically, Koobface victims get a message from one of their contacts inviting them to click on a video link. The link leads you to a site mimicking the video-sharing site, Youtube. Once there, you are asked whether you want to download a software needed to watch the video.
If you click `yes', the worm gets activated, leaving your computer vulnerable. The worm not only disrupts your internet experience by sending your searches on engines like Google elsewhere and return garbled replies, it also steals data that may have been left in your computer's memory.
If you do or have already been Koobfaced the only way to protect your machine is to delete all files and registry keys that have been added by the worm. Internet users have also been advised by the government agency to install and maintain updated anti-virus software in their computers, as also a desktop firewall, and block ports which are not required.
While you may not be able to notice the worm rummaging through your electronic files searching for personal data, including passwords, the visible signs of the worm would show up on your internet browsing where you would get abnormal results to your searches and be misdirected to other sites.
Agencies
Home for all technology and products -- news, features and interviews of top-notch enterprises in India. This portal covers all the major happenings across verticals including telecom, mobility, gadgets & gizmo, retail, services, BFSI, energy, manufacturing, SMBs, business technologies, GreenIT, outsourcing...
Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts
Thursday, August 13, 2009
Saturday, April 25, 2009
Has Conficker attacked thousands of PCs globally?
A malicious software programme known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.
Conficker, also known as Downadup or Kido, is quietly turning thousands of personal computers into servers of e-mail spam and installing spyware, they said.
The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.
Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.
"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."
Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said. The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.
"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.
He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.
He said the worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow. "We expect to see a differen
t component or a whole new twist to the way this botnet does business," said Ferguson, a member of The Conficker Working Group, an international alliance of companies fighting the worm.
Researchers had feared the network controlled by the Conficker worm might be deployed on April 1 since the worm surfaced last year because it was programmed to increase communication attempts from that date. The security industry formed the task force to fight the worm, bringing widespread attention that experts said robably scared off the criminals who command the slave computers.
The task force initially thwarted the worm using the Internet's traffic control system to block access to servers that control the slave computers. Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.
The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.
Agencies
Conficker, also known as Downadup or Kido, is quietly turning thousands of personal computers into servers of e-mail spam and installing spyware, they said.
The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.
Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.
"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."
Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said. The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.
"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.
He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.
He said the worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow. "We expect to see a differen
t component or a whole new twist to the way this botnet does business," said Ferguson, a member of The Conficker Working Group, an international alliance of companies fighting the worm.
Researchers had feared the network controlled by the Conficker worm might be deployed on April 1 since the worm surfaced last year because it was programmed to increase communication attempts from that date. The security industry formed the task force to fight the worm, bringing widespread attention that experts said robably scared off the criminals who command the slave computers.
The task force initially thwarted the worm using the Internet's traffic control system to block access to servers that control the slave computers. Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.
The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.
Agencies
Subscribe to:
Posts (Atom)