Search for software:
Powered by RegNow

Saturday, April 18, 2009

Malicious Software Is Revised

Several researchers said there might be a connection between the authors of Conficker and of another program known as Waladec, a malware program that has been used to distribute fraudulent advertisements through e-mail spam.

The program, known as Conficker, targets versions of Microsoft’s Windows operating system and has now been distributed in four versions, computer security specialists said. Now, however, the system for programming Conficker uses a peer-to-peer mechanism that can be initiated from any one of millions of infected systems.

The riddle of a malicious software program that has spread throughout the Internet deepened Thursday as security researchers examined a new version of the software that they said made it more difficult to eradicate the program.An earlier version of the program had been set to begin contacting servers on April 1, raising widespread concern about the authors’ intent.

The consensus within the computer security industry is that although there are now some indications that Conficker’s authors are intent on building a giant spam system, there is no hard evidence.

Originally, they had appeared to plan to download instructions to Conficker by generating new Internet addresses that infected machines could download instructions from. Several of the groups monitoring the program said the most recent version, which began to appear Tuesday, appeared to be targeted at improving a peer-to-peer communications system between computers that are infected and hardening the system by making infected machines more resistant to anti-virus software. They also noted that the Conficker authors have switched strategies and are using the program’s peer-to-peer mechanism to update the system.

1 Comments:

Anonymous John T said...

Great post. Keep it up!!!

April 18, 2009 at 2:32 AM  

Post a Comment

Subscribe to Post Comments [Atom]

<< Home

Subscribe to SOFTWARE by Email

Search for software:
Powered by RegNow