Home > Insights > Blogs 

CA Community

This Blog

New Conficker Variant Not Fooling Around

Published: March 11 2009, 10:54 PM
by Zarestel Ferrer

One piece of malware we’ve been monitoring since late last week is a new Conficker (AKA Downadup) variant.

This worm, detected as Win32/Conficker.C, is getting ready for April Fool’s Day on 1 April, although it definitely won’t be fooling around. On that day, Conficker.C will commence its attempt to generate 50,000 URLs daily and try to access (download or report back to) 500 of them. It is a clever strategy, but the security industry is certainly on the lookout.

The snippet of code below shows the malware’s date check:

Win32/Conficker.C prepares for a big launch on 1 April 2009

This current variant, unlike its predecessors Conficker.A and Conficker.B, may not light a fire under your intrusion detection systems because it has lost some of its former spreading functionality. However, Conficker.C does include a new behavior – the ability to terminate tools used to monitor and remove Conficker from affected systems. For example, as illustrated below, it can terminate Process Explorer among others:

Win32/Conficker.C contains functionality to terminate security-related processes

Please stay informed and aware of this new malware. You can find a full behavioral analysis for Win32/Conficker.C in our encyclopedia:
http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77976

CA ISBU is monitoring this threat and will publish reports on information gathered as we receive and process it.

Share this post:  EmailEmail

By: Zarestel Ferrer
Zarestel Ferrer is a Senior Research Engineer with CA's Internet Security Business Unit (CA ISBU) based in Melbourne, Australia. Previous to CA, he worked as a software developer and then moved into security as a Senior Anti-virus Engineer at Trend Micro. He also worked for PC Tools Research as a...
Read More..

3 people have left comments:

If my computer is clean now, can a virus/worm/trojan be avoided if I don't turn my computer on (on April 1st)?  I'm scanning it now with Windows Live Care One, and will scan with SkyBot Search and Destroy right after.

Posted by: Jan Jacobs | March 30, 2009 3:24 PM

just use a mac

Posted by: Chris | March 31, 2009 10:45 PM

don't have to worry about these things on a linux box...

Posted by: john | April 1, 2009 9:56 AM

 
 
Page Tools