Conficker worm: new version detected
Posted: April 16th, 2009 | Tags: Botnet, Conficker |The “Kaspersky’s Labs” warns about appearance of the new version of the Conficker also known as Kido and Downadup.
Conficker has been detected in November of last year, however the peak of its activity has been on the beginning of January: for a few days the worm has infected about ten millions computers worldwide.
New variant of Conficker has started to extend in the end of last week: the infected computers, co-operating with each other through P2P-connections, have given the command to other infected computers on loading of upgrades and two files — FraudTool. Win32.SpywareProtect2009.s and Email-Worm. Win32.Iksmas.atz. The first of these units represents a counterfeit antivirus which is placed on the servers allocated in territory of Ukraine. At start the program suggests «to delete the found viruses», demanding for it about 50 dollars. The second file — a mail worm possessing a functional of theft of the data and a spam sending.
«Kaspersky’s labs» marks that for 12 hours one bot infected with the new version of Conficker has sent over 42 thousand spam emails. If to assume that the total amount of infected computers is about 5 million it turns out that the Conficker botnet is capable to dispatch approximately 400 billions spam messages daily.
Different sources also inform that in the end of last week the Conficker has penetrated into computer network of University of Utah (USA), having infected about 700 computers at medical school, medical nursing care college and so forth the Primary analysis of a code of new variant Conficker allows to say that it will function till May, 3rd.























Leave a Reply