<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Individual Eleven - The World&#039;s Cyberbrain &#187; conficker</title>
	<atom:link href="http://www.individualeleven.net/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.individualeleven.net</link>
	<description>Tech and gadgetry for free thinking individuals.</description>
	<lastBuildDate>Wed, 04 Jan 2012 11:00:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>US-CERT issues Conficker warning</title>
		<link>http://www.individualeleven.net/2009/04/us-cert-issues-conficker-warning/</link>
		<comments>http://www.individualeleven.net/2009/04/us-cert-issues-conficker-warning/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 01:54:53 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[w32.downadup]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=518</guid>
		<description><![CDATA[Another memo, another bulletin has arrived. This time it is from United States Computer Emergency Readiness Team (US-CERT), our security department seems to be busy lately these memos are becoming more frequent. Regardless, it is all for the good, after all it is interesting to know what actions are being taken globally. Their alert underlines [...]]]></description>
			<content:encoded><![CDATA[<p>Another memo, another bulletin has arrived. This time it is from <a href="http://www.us-cert.gov/cas/techalerts/TA09-088A.html" target="_blank">United States Computer Emergency Readiness Team (US-CERT),</a> our security department seems to be busy lately these memos are becoming more frequent. Regardless, it is all for the good, after all it is interesting to know what actions are being taken globally.</p>
<p>Their alert underlines what we already know, so it is not exactly a revelation to us. However, I find it interesting that the problem has escalated to such an extent that Homeland Security has been involved. Possibly, there is the feeling of an attack at national security, cyber terrorism anyone? I had a pleasurable evening last night with some friends, and we discussed whether the Chinese government engineered Conficker. I personally feel it is most likely an independent organisation or the Russian government. However, without going into a whirlwind of skulduggery and conspiracy, we were perhaps wrong on both counts and it is some 16-year-old code monkey, which just happens to be bored for the past year or so.</p>
<p>On a lighter note, I am now officially on holiday and I am visiting a friend of mine in Holland next week. I managed to achieve as much as I can at work, and I have locked away all pens and Post-It notes from the prying eyes of work colleagues. Call me possessive, but I would like my desk to be intact and to have all contents unmoved when I return. I am sure I will make some sporadic blog posts on my travels; I will be taking a British Airways flight, which means my first visitation of Terminal 5 at Heathrow airport. I hope that the baggage handlers are not on strike&#8230;</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fus-cert-issues-conficker-warning%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fus-cert-issues-conficker-warning%2F&text=US-CERT+issues+Conficker+warning" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fus-cert-issues-conficker-warning%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/04/us-cert-issues-conficker-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 1st – Joke on Conficker.D?</title>
		<link>http://www.individualeleven.net/2009/04/april-1st-%e2%80%93-joke-on-confickerd/</link>
		<comments>http://www.individualeleven.net/2009/04/april-1st-%e2%80%93-joke-on-confickerd/#comments</comments>
		<pubDate>Wed, 01 Apr 2009 17:24:25 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Conficker.D]]></category>
		<category><![CDATA[Sophos Conficker tool]]></category>
		<category><![CDATA[w32.downadup]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=516</guid>
		<description><![CDATA[I walked into work today, with an air of anticipation on the potential torrent of problems with our servers. Fortunately, it was all quiet on the western front with not a single incident of viral infection reported. It was so anti-climatic in a way, a similar feeling you get when you pay good money to [...]]]></description>
			<content:encoded><![CDATA[<p>I walked into work today, with an air of anticipation on the potential torrent of problems with our servers. Fortunately, it was all quiet on the western front with not a single incident of viral infection reported. It was so anti-climatic in a way, a similar feeling you get when you pay good money to watch a mediocre film, after reading the hyperbole that came with it.</p>
<p>Not that any complaints were issued, myself and many others were quite relieved but we pre-empted the problem early on and thankfully our security precautions were not put to the test. Perhaps the warning of impending doom was the April Fool’s joke in itself, maybe we will never know. Nevertheless, this is perhaps not the last we will hear of this and as ever, new security vulnerabilities appear every day.</p>
<p>If you were not so fortunate, then you may be interested in this. As part of our research, Sophos released a newer stand-alone <a href="http://www.sophos.com/support/knowledgebase/article/54447.html" target="_blank">Conficker clean-up tool.</a> We have not needed to use it, but I thought it prudent to share if you are still fire fighting in your I.T environment. You will need to have a MySophos account to download the tool; you can create one on their site.</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fapril-1st-%25e2%2580%2593-joke-on-confickerd%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fapril-1st-%25e2%2580%2593-joke-on-confickerd%2F&text=April+1st+%E2%80%93+Joke+on+Conficker.D%3F" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fapril-1st-%25e2%2580%2593-joke-on-confickerd%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/04/april-1st-%e2%80%93-joke-on-confickerd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker.D worm Doomsday – 1st April</title>
		<link>http://www.individualeleven.net/2009/03/confickerd-worm-doomsday-%e2%80%93-1st-april/</link>
		<comments>http://www.individualeleven.net/2009/03/confickerd-worm-doomsday-%e2%80%93-1st-april/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 20:39:17 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Conficker.D]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[w32.downadup]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=511</guid>
		<description><![CDATA[Microsoft sent a bulletin to us at work, with some additional memos internally about this. In their bulletin, they mentioned a collective (Conficker Working Group) specifically created to combat this virus and a note about the $250,000 reward for the culprits. However, the main detail here is the possibility that 1st April will be the [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft sent a bulletin to us at work, with some additional memos internally about this. In their bulletin, they mentioned a collective (Conficker Working Group) specifically created to combat this virus and a note about the $250,000 reward for the culprits. However, the main detail here is the possibility that 1st April will be the trigger date for the Conficker.D variant, to initiate contact with internet domains. Perhaps after contact, the instructions will be to redirect you to another URL that has the real payload. But I suppose we won’t know until it actually happens. <a href="http://blogs.technet.com/msrc/archive/2009/03/27/update-on-conficker-d.aspx" target="_blank">Full blog entry by Microsoft can be read here.</a></p>
<p>As stated, this behaviour is the same as Conficker.B but introduces a wider scope in terms of which domains it will try to target. This will no doubt indicate that the virus writers want to spread this as widely as possible. If you were like me, then you would have been fully security patched by now across all affected platforms. The main thing here is to:</p>
<ul>
<li>Update your systems with <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">MS08-067</a></li>
<li>Keep your AV software up to date</li>
<li>Monitor port 445 traffic if possible</li>
</ul>
<p>Taking precautions is the main thing, and if you are sensible, you will not encounter this virus at all. Given how this worm is still causing problems, mainly in enterprise environments, all system administrators should be fully up to speed with this. Our company policy of banning USB devices is still in place, and we have resorted to burning files onto CD/DVD R/W. However, in certain cases we have permitted usage of USB drives.  We have separate “sheep-dip” machines, which are completely standalone, with McAfee VirusScan Enterprise 8.5 installed. It seems to do the trick, we scan the USB drives prior to usage, copy the files you need and then scan it again afterwards.</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fconfickerd-worm-doomsday-%25e2%2580%2593-1st-april%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fconfickerd-worm-doomsday-%25e2%2580%2593-1st-april%2F&text=Conficker.D+worm+Doomsday+%E2%80%93+1st+April" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fconfickerd-worm-doomsday-%25e2%2580%2593-1st-april%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/03/confickerd-worm-doomsday-%e2%80%93-1st-april/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A mixed bag</title>
		<link>http://www.individualeleven.net/2009/02/a-mixed-bag/</link>
		<comments>http://www.individualeleven.net/2009/02/a-mixed-bag/#comments</comments>
		<pubDate>Sat, 14 Feb 2009 02:42:34 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[1234567890 Unix time]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Eidos]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Valentine's Day]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=325</guid>
		<description><![CDATA[Well this week has been catastrophic at work. Anything you could possibly imagine that could go wrong did go wrong. We’ve been given second hand server kit to build from, including the CPU which consequently gave up the ghost on first boot. My illustrious colleague had fun tackling that one and trying to convince Project [...]]]></description>
			<content:encoded><![CDATA[<p>Well this week has been catastrophic at work. Anything you could possibly imagine that could go wrong did go wrong. We’ve been given second hand server kit to build from, including the CPU which consequently gave up the ghost on first boot. My illustrious colleague had fun tackling that one and trying to convince Project Managers to source new kit, you know how that goes. The main source of cooling in the server room, the large AC at the back, spontaneously burst into flames. The smell of smoke and burning PCB was intoxicating; I had to make alternative routes to the kitchen so I could make tea. Also for the past two weeks, I have been trying to virtualise an Exchange cluster from physical boxes into ESX. The P2V worked fine, except I had no idea why this one particular server kept churning out Kerberos errors. I have tried everything, installed, uninstalled, netdom reset, went through the cluster installation documents over and over, perused over hundreds of knowledge base articles, checked Active Directory, evicted the node so many times to start afresh. System Attendant refused to start which means Exchange could be classed as dead. Suffice it to say, there was something fundamentally wrong that I had no time to troubleshoot&#8230; an executive decision was made and I am rebuilding the damn thing within ESX from OS up.  Not to mention the strange weather we are having, Chicago was getting tons of rain while we were getting the snow. Shouldn’t it be the other way round?!</p>
<p>But I digress, there has been some interesting news this week that I will just put into one big hat. So here we go&#8230;<br />
<br/><br />
<a href="http://www.guardian.co.uk/business/2009/feb/12/mergersandacquisitions-games" target="_blank"><span style="text-decoration: underline;"><strong>Square Enix buys Eidos</strong></span></a><br />
Are we going to see Lara Croft standing alongside the likes of Cloud and Squall? Or maybe she can come on as a Summon using her pistols of death. Either way, Eidos’ last iteration of the Tomb Raider series did horribly, as dictated by the sales figures. It’s a shame that this franchise has gone downhill so rapidly, but I’m sure the gods at Square Enix can turn things around with the licenses they have now acquired.</p>
<p><a href="http://entertainment.slashdot.org/article.pl?sid=09/02/13/1534240&amp;from=rss" target="_blank"><span style="text-decoration: underline;"><strong>1,234,567,890 &#8211; Almost like a birthday</strong></span></a><br />
When the clocks hit 23.31:30 UTC, it was exactly 1234567890 seconds since January 1st 1970 when the Unix clock started ticking. This event is almost like witnessing a full eclipse, and there are going to be some geeky parties going on I’m sure.</p>
<p><a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5719302.ece" target="_blank"><span style="text-decoration: underline;"><strong>Facebook is $65 million poorer</strong></span></a><br />
Oh woe is me. This is probably pocket change for Mark Zuckerberg, the founder of Facebook, whether he really did steal the idea from his ex Harvard pals or not remains to be seen. I’m sure that if Facebook was not was as successful as it is now, they wouldn’t be suing him. The problem is, just because you have an idea does not mean you can implement it into a viable business. So considering this, some credit is due to Mr Zuckerberg.</p>
<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2009/02/13/AR2009021302080.html?wprss=rss_technology" target="_blank"><span style="text-decoration: underline;"><strong>Microsoft issues bounty for Conficker culprits</strong></span></a><br />
It’s that old chestnut again, what seemed to be a rather harmless worm virus (after all, it doesn’t really do much if you take precautions and implement safeguards) has turned into something of a black plague in the enterprise world, including government institutions. The person or persons involved have been marked; watch out for wanted posters on a lamp post near you.</p>
<p><span style="text-decoration: underline;"><strong>And finally&#8230;</strong></span><br />
It’s Valentine’s Day, so I hope you all have a wonderful time with your loved ones&#8230; perhaps you will get a surprise from an unexpected someone. However, if you feel all alone sobbing in a dark, damp corner somewhere then here is an ASCII heart just for you!<br />
<br/><br />
_________pork and____________pork and<br />
______pork and bea_______pork and beansp<br />
____pork and beanspor___pork and beanspork<br />
___pork and beanspork and beanspo_______pork<br />
__pork and beanspork and beanspo_________pork<br />
_pork and beanspork and beanspork a_______pork<br />
_pork and beanspork and beanspork and b______p<br />
pork and beanspork and beanspork and bean__por<br />
pork and beanspork and beanspork and beans_por<br />
pork and beanspork and beanspork and beanspork<br />
pork and beanspork and beanspork and beanspor<br />
_pork and beanspork and beanspork and beansp<br />
__pork and beanspork and beanspork and bean<br />
____pork and beanspork and beanspork and b<br />
______pork and beanspork and beanspork a<br />
_________pork and beanspork and beans<br />
____________pork and beanspork and<br />
______________pork and beanspork<br />
_________________pork and bean<br />
___________________pork and<br />
_____________________pork a<br />
______________________pork<br />
_______________________po<br />
<br/></p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fa-mixed-bag%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fa-mixed-bag%2F&text=A+mixed+bag" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fa-mixed-bag%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/02/a-mixed-bag/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NOD32 – Conficker/downadup, variants abound</title>
		<link>http://www.individualeleven.net/2009/01/nod32-%e2%80%93-confickerdownadup-variants-abound/</link>
		<comments>http://www.individualeleven.net/2009/01/nod32-%e2%80%93-confickerdownadup-variants-abound/#comments</comments>
		<pubDate>Sun, 18 Jan 2009 01:07:52 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[NOD32]]></category>
		<category><![CDATA[ThreatSense]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=114</guid>
		<description><![CDATA[Someone asked me if NOD32 can successfully detect and remove Conficker. I was certain it can from what I have been told (as mentioned in my previous post), I use NOD32 at home but I have not been affected so could not say so myself. I decided to look it up anyway and scarily there [...]]]></description>
			<content:encoded><![CDATA[<p>Someone asked me if NOD32 can successfully detect and remove Conficker. I was certain it can from what I have been told (as mentioned in my previous post), I use NOD32 at home but I have not been affected so could not say so myself. I decided to look it up anyway and scarily there seems to be ALOT of variations, judging by the different names ESET have given in their list of database updates. It was first mentioned in database version 3638 (25th November 2008) and goes from Win32/Conficker.A to .Z, they ran out of letters in the alphabet and started to name them Win32/Conficker.AA etc. This just demonstrates the polymorphic capabilities of this worm, if you haven’t security patched your machine by now then good luck to you.</p>
<p>The last mention on ESET’s database search is Win32/Conficker.AK, database update version 3772 released on 16th January 2009. I have used NOD32 for many years and I have to say it is one of the best AV products on the market, and the support for different OS platforms is a plus. You can look for viruses that are included in all their database releases on the <a href="http://www.eset.com/support/updates.php" target="_blank">ThreatSense Updates search.</a></p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fnod32-%25e2%2580%2593-confickerdownadup-variants-abound%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fnod32-%25e2%2580%2593-confickerdownadup-variants-abound%2F&text=NOD32+%E2%80%93+Conficker%2Fdownadup%2C+variants+abound" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fnod32-%25e2%2580%2593-confickerdownadup-variants-abound%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/01/nod32-%e2%80%93-confickerdownadup-variants-abound/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Net-Worm.Win32.Kido.bt &#8211; Kaspersky&#8217;s alternative name for Conficker/downadup</title>
		<link>http://www.individualeleven.net/2009/01/net-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup/</link>
		<comments>http://www.individualeleven.net/2009/01/net-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 23:39:52 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[Net-Worm.Win32.Kido.bt]]></category>
		<category><![CDATA[w32.downadup]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=107</guid>
		<description><![CDATA[After a bit of digging around, I finally found the Conficker worm being mentioned on Kaspersky&#8217;s website. It doesn&#8217;t help that they do not use the most common monickers for this but anyway. I am now beginning to understand why our copy of Kaspersky is not detecting the one we found on our network. Here [...]]]></description>
			<content:encoded><![CDATA[<p>After a bit of digging around, I finally found the Conficker worm being mentioned on Kaspersky&#8217;s website. It doesn&#8217;t help that they do not use the most common monickers for this but anyway. I am now beginning to understand why our copy of Kaspersky is not detecting the one we found on our network. Here is an excerpt of the description from their site. I have highlighted in bold/underline the problem:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><span>This worm spreads via local networks and removable storage media. It is a PE <span style="text-decoration: underline;"><strong>DLL file</strong></span>. The components of the worm are between 155KB and 165KB in size. It is packed using UPX.</span></p>
<h2>Installation</h2>
<p>The worm copies its executable file to the Windows system directory as follows:</p>
<p><span class="pre"><span style="text-decoration: underline;"><strong>%System%\&lt;rnd&gt;.dll</strong></span> </span> &lt;rnd&gt; is a string of random symbols</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>I hate to say this Kaspersky, but the infected file has varying permutations for the file extension. It is not just .DLL but it can be pretty much anything, from .txt to .png or .jpg. Basically, you cannot use the .DLL extension as the only method for detection and if this is the case, it is not going to find it. Perhaps the first variant &#8220;a&#8221; was originally a .DLL but not anymore and I believe the &#8220;b&#8221; version is much more widespread now. So how about taking a leaf out of Trend Micro&#8217;s book and look for behaviourial patterns instead of just by filename&#8230;</p>
<p><a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=21782725" target="_blank">Kaspersky description for Net-Worm.Win32.Kido</a></p>
<p><a href="http://support.kaspersky.com/faq/?qid=208279973" target="_blank">Kaspersky method of removal. It may work on some versions of the virus</a></p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fnet-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fnet-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup%2F&text=Net-Worm.Win32.Kido.bt+%26%238211%3B+Kaspersky%26%238217%3Bs+alternative+name+for+Conficker%2Fdownadup" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fnet-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/01/net-wormwin32kidobt-kasperskys-alternative-name-for-confickerdownadup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update – Conficker, W32.downadup virus</title>
		<link>http://www.individualeleven.net/2009/01/update-%e2%80%93-conficker-w32downadup-virus/</link>
		<comments>http://www.individualeleven.net/2009/01/update-%e2%80%93-conficker-w32downadup-virus/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 23:36:32 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[f-secure]]></category>
		<category><![CDATA[kb890830]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[MSRT]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[w32.downadup]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=89</guid>
		<description><![CDATA[This is spreading like wildfire, but from the tests we carried out using an infected USB stick the F-Secure tool to remove the virus does not work. It reports back to say that the virus is not detected, but during our tests when we do the same scan using the Trend Micro tool it gets [...]]]></description>
			<content:encoded><![CDATA[<p>This is spreading like wildfire, but from the tests we carried out using an infected USB stick the F-Secure tool to remove the virus does not work. It reports back to say that the virus is not detected, but during our tests when we do the same scan using the Trend Micro tool it gets picked up immediately. Until F-Secure amend their standalone scanner, I would not use it to combat this. More information on F-Secure’s tool is <a href="http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml" target="_blank">here.</a> I am assuming that F-Secure are not including all variants and they need to update it.</p>
<p>Microsoft has also issued a new <a href="http://support.microsoft.com/kb/890830" target="_blank">Malicious Software Removal Tool</a>, KB article 890830, which is released regularly for removal of many viruses. However, the main one we are interested in is this:</p>
<p><img class="alignnone size-full wp-image-90" title="kb890830" src="http://www.individualeleven.net/wp-content/uploads/2009/01/kb890830.jpg" alt="kb890830" width="429" height="114" /></p>
<p>You can deploy this quite easily across your organisation via group policy, Microsoft Systems Management Server (SMS) or any other third party software/update distribution solutions such as the one from Altiris. So far, the only products that I have encountered which can detect and delete the virus is still McAfee, NOD32 and eTrust. I am not sure about Symantec as I refuse to use a product that grinds your entire system to a halt. No news on Kaspersky either, our purchase of Kaspersky 2009 is redundant until they release a new definition file.</p>
<p><strong>EDIT &#8211; McAfee VirusScan Enterprise</strong></p>
<p>This gets better and better, McAfee VirusScan 7.1 DOES NOT detect conficker unfortunately, even with the latest DATs installed. We compared this to our other rig which uses VirusScan 8.5 and that detects and removes successfully. So I would suggest upgrading to the 8.5 version if you use McAfee in your organisation. The engine for 8.5 must have a better heuristic detection method.</p>
<p>Another thing to note is that there are (as far as I know) two versions of this worm, W32.downadup.a and W32.downadup.b. The &#8220;b&#8221; version has the added bonus of spreading via autorun.inf as described in my previous post, so whatever AV solution you use make sure that it covers both. Sophos will be investigated as a possible solution for some of our rigs, having such a large test environment at my disposal does mean I can test and roll back as many times as I want before we commit.</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fupdate-%25e2%2580%2593-conficker-w32downadup-virus%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fupdate-%25e2%2580%2593-conficker-w32downadup-virus%2F&text=Update+%E2%80%93+Conficker%2C+W32.downadup+virus" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fupdate-%25e2%2580%2593-conficker-w32downadup-virus%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/01/update-%e2%80%93-conficker-w32downadup-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker virus, aka W32.downadup</title>
		<link>http://www.individualeleven.net/2009/01/conficker-virus-aka-w32downadup/</link>
		<comments>http://www.individualeleven.net/2009/01/conficker-virus-aka-w32downadup/#comments</comments>
		<pubDate>Sat, 10 Jan 2009 18:12:09 +0000</pubDate>
		<dc:creator>Moto</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[port 445]]></category>
		<category><![CDATA[Trend Micro]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[w32.downadup]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.individualeleven.net/?p=5</guid>
		<description><![CDATA[This little gem has been plagueing corporations all over the world, thanks to a Ukranian virus writer. Something to do for those cold winter nights I suppose when you have no gas. It acts as a botnet of sorts and once infected the machine turns into a HTTP server to spread it further. Another method [...]]]></description>
			<content:encoded><![CDATA[<p>This little gem has been plagueing corporations all over the world, thanks to a Ukranian virus writer. Something to do for those cold winter nights I suppose when you <a href="http://news.bbc.co.uk/1/hi/world/europe/7806870.stm">have no gas.</a></p>
<p>It acts as a botnet of sorts and once infected the machine turns into a HTTP server to spread it further. Another method of transportation is via USB drives with autorun enabled. Signs of infection include hundreds of connections to port 445 (SMB), do a netstat -on at the command prompt. Also access to admin shares are lost and other file shares could be affected.</p>
<p><strong>Removal</strong><br />
First thing is to patch your machine with this security patch from MS: <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">Microsoft Security Bulletin MS08-067 – Critical (KB958644)</a></p>
<p>Secondly, update your anti-virus software with the latest definitions. For a standalone removal tool, go to Trend Micro and download with the latest definition files:<br />
<a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/SysClean-WORM_DOWNAD.zip">Sysclean scan and removal</a><br />
<a href="http://www.trendmicro.com/download/pattern-cpr.asp">Latest Control Pattern file</a><br />
<a href="http://www.trendmicro.com/download/spywarepattern.asp">Spyware detection and cleanup</a><br />
Run sysclean.com once all files are extracted, and it will scan the current machine.</p>
<p>Funnily enough, we decided to go to PCWorld and buy the latest Kaspersky 2009 AV software for our standalone PCs. To our surprise it did not detect the virus at all, forums suggest the Kaspersky ruskies are working on a solution for detection and removal. Also our AV for the corporate network, eTrust by Computer Associates also did not initially detect it until a policy update was applied. According to the techs at CA, it was classed as low risk and not critical. Obviously CA were caught napping when the bulletin was released in October. Nod32 by Eset finds it quite happily without creating too much fuss, same goes for McAfee if you have the latest dats.</p>
<p><a href="http://vil.nai.com/vil/content/v_153464.htm">Information on the virus worm by McAfee</a></p>
<p>Even though they have marked this as low risk, it can be very disruptive. Losing access to file servers containing critical data for everyday operations isn&#8217;t exactly productive. I have also found the hammering of port 445 will slow your network down to a crawl as it will do this on every subnet you are connected to and try to do this for external IP addresses also.</p>
<div class="trackable_sharing"><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.individualeleven.net%2Fconficker-virus-aka-w32downadup%2F" style="text-decoration: none; white-space: nowrap;" title="Facebook" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/facebook.png" alt="Facebook" width="32" height="32"> facebook &nbsp; </a> <a href="http://twitter.com/share?url=http%3A%2F%2Fwww.individualeleven.net%2Fconficker-virus-aka-w32downadup%2F&text=Conficker+virus%2C+aka+W32.downadup" style="text-decoration: none; white-space: nowrap;" title="Twitter" target="_blank" onclick="window.open(this.href,'share','menubar=0,resizable=1,width=500,height=350'); return false;"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/twitter.png" alt="Twitter" width="32" height="32"> twitter &nbsp; </a> <a href="mailto:?subject=Check out http%3A%2F%2Fwww.individualeleven.net%2Fconficker-virus-aka-w32downadup%2F" style="text-decoration: none; white-space: nowrap;" title="Email"><img align="absmiddle" src="http://www.individualeleven.net/wp-content/plugins/trackable-social-share-icons/buttons/1/email.png" alt="Email" width="32" height="32"> email &nbsp; </a> </div><!-- PHP 5.x -->]]></content:encoded>
			<wfw:commentRss>http://www.individualeleven.net/2009/01/conficker-virus-aka-w32downadup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

