|
|
 |
Shadow, The Conficker Cyber Worm Update!Win32.HLLW.Shadow.based
UPDATE: The Shadow/Conficker worm has began to make it's move on infected computers. It had sat dormant for a while, leading folks to dismiss the infection as a false alarm, but is now beginning to take action.
What It Does:
Spreads across networks connected to the infected computer.May block security updates for protection programs as well as Windows Updates.Downloads and installs malicious files and rogue protection programs such as Spyware Protect.Sets up a service to watch for any changes made to it's files in order to help prevent detection and cleaning.Adds itself to the infected computer's registry so that the infection runs when Windows starts.Installs autorun infection in order to spread to any portable media that is used on an infected computer (such as USB/Flash drives, portable hard drives, diskettes, etc). Once the portable media is infected, the infection will install itself onto any other computer that the media device gets connected to.
How It Infects: Win32.HLLW.Shadow.based has no specific means of infection. May be spread through malicious websites, links, email attachments, infected networks, or infected portable media devices.
How To Avoid Infection: Do not click any unexpected links in instant messages. Do not download email attachments from unexpected sources. Do not download unknown files or files from unknown sources. Do not share portable devices. If using StopSign, be sure that the On-Access Scan is installed and enabled. Ensure that all updates are installed from Microsoft's Windows Update.
Vulnerable Operating Systems: Windows 98/Me/NT/2000/XP
Type: Trojan
Technical Name: Win32.HLLW.Shadow.based
Aliases: Net-Worm.Win32.Kido!IKWin32/Conficker.worm.88576Worm/Conficker.D.1W32/Conficker.BWin32:CoPackWorm/Generic.WLOWin32.Worm.Downadup.GenI-Worm.Kido.ipWorm.Downadup-4Worm.Win32.Exploit.Conficker.c.~Win32.Conficker.XWin32/Conficker.CW32/Conficker.BWorm:W32/Downadup.DYW32/Kido.IP!worm.imWin32.Worm.Downadup.GenNet-Worm.Win32.KidoNet-Worm.Win32.Downadup.iwTrojan-Downloader.Win32.Kido.aW32/Conficker.worm.gen.cW32/Conficker.worm.gen.cWorm.Conficker.D.1Worm:Win32/Conficker.DWin32/Conficker.XW32/Conficker.KLWorm/W32.Kido.88576W32/Conficker.C.wormTrojan.DownloaderWorm.Win32.MS08-067.cW32/Confick-GWorm.Win32.Downadup.GenW32.Downadup.CWORM_DOWNAD.ADNet-Worm.Win32.Kido.iwWorm.Win32.Conficker.88576.B
|