The Raging Windows Worm has attacked over 8.9 Million Computers

January 19, 2009 by John Messina weblog
Downadup Worm

( -- Last week the global internet community was hit by the Downadup worm also know as Conficker, or Kido. This worm is now using multiple ways of infecting computers, including USB sticks. If someone were to take a USB memory stick from one infected computer and plug it into another, it would infect that computer and the network as well. Once a USB memory stick is infected, there is no Microsoft patch to remove the worm.

This attack has been more widespread on corporate networks because companies did not have the patch installed in time. This could have been caused by any number of reasons. For instance an IT Department may have been short handed or have workload related issues preventing the patch from being installed in a timely manner. Microsoft did a good job in having home computers updated with the patch but corporate networks are still being infected.

This worm is very sophisticated because it exploits multiple secure flaws in Microsoft's Windows OS's. The worm starts by injecting itself into one of Microsoft's common system process, services.exe. From there it creates a new random five letter DLL file in the Windows system folder. The Windows registry is then edited to make reference to the DLL file and runs when the computer is restarted.

Once the worm is in the computer system, it creates an HTTP server and proceeds to download malware from the hacker's websites. System restore has been wiped clean and reset on the computer making it impossible to restore your system prior to the infection.

Each day there are hundreds of dummy domain names being generated by an algorithm coded in the worm but only one site is the actual malware site. With this trickery employed, it makes it very difficult to find what is being installed each day.

This worm spreads mainly through corporate networks. An infected computer will scan the network for other computers and gain access through the Windows secure flaw. Even though a password is needed to gain access to other computers, it will guess short passwords by brute force method thereby gaining access to those computers.

The only way to stop this worm is by applying Microsoft's patch MS08-067 before computer networks get infected.

© 2009

Explore further: Headless Conficker worm lives in computers

Related Stories

Help! How to avoid fast-moving computer worm

January 28, 2009

Since early January, a worm that has been referred to by several names, including "Downadup," "Kido" and "Conficker," has been infecting millions of computers around the world. The worm exploits a previously discovered vulnerability ...

Downadup Worm Hits Over 3.5 Million Computers

January 16, 2009

( -- Security firm F-Secure has advised that the Downadup worm has spread to more than 3.5 million computers by exploiting a vulnerability Microsoft patched last October. This is achieved by trying to connect ...

Low-cost strategy developed for curbing computer worms

January 13, 2009

Thanks to an ingenious new strategy devised by researchers at University of California, Davis and Intel Corporation, computer network administrators might soon be able to mount effective, low-cost defenses against self-propagating ...

Recommended for you

The ethics of robot love

November 25, 2015

There was to have been a conference in Malaysia last week called Love and Sex with Robots but it was cancelled. Malaysian police branded it "illegal" and "ridiculous". "There is nothing scientific about sex with robots," ...

Glider pilots aim for the stratosphere

November 20, 2015

Talk about serendipity. Einar Enevoldson was strolling past a scientist's office in 1991 when he noticed a freshly printed image tacked to the wall. He was thunderstruck; it showed faint particles in the sky that proved something ...


Adjust slider to filter visible comments by rank

Display comments: newest first

2.6 / 5 (5) Jan 19, 2009
Linux...need I say more?
1 / 5 (1) Jan 19, 2009
1 / 5 (1) Jan 19, 2009
But NO Apple Macs - Hmmmm
not rated yet Jan 19, 2009
worms are bad.
4 / 5 (1) Jan 19, 2009
Well, this crap is the reason why i switched to Mac. Despite the lack of games, it doesn't get this crap, so I'm happy.

Before you flame, I also have a windows gaming computer - I just never connect it to the internet.
1.5 / 5 (2) Jan 19, 2009
Viruses happen.
1 / 5 (2) Jan 19, 2009
Linux...need I say more?

5 / 5 (2) Jan 20, 2009
The moral? Use Linux :)
1 / 5 (1) Jan 20, 2009
my main pc still runs windows and will do until Linux becomes more compatible. If you get decent anti virus (Nod32) and don't go on dodgy websites you will be fine. I only use Linux on my computers that are not top spec.
not rated yet Jan 20, 2009
We've had this virus at work, it's a right pain in the rear. We've spent hours removing it from having it on just a small handful of PC's.
If they catch who made it, they should be hung or something for wasting millions of man hours.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.