<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog  worm_downad</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/worm_downad/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 28 Jul 2010 17:12:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>New Downad/Conficker variant spreading over P2P</title>
		<link>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/</link>
		<comments>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 19:21:14 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=453</guid>
		<description><![CDATA[TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called WORM_DOWNAD.E spreading over the peer-to-peer functionality of the previous version of this now infamous worm.   As well as reactivating the original propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This [...]]]></description>
			<content:encoded><![CDATA[<p>TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P" target="_blank">WORM_DOWNAD.E</a> spreading over the peer-to-peer functionality of the previous version of this now infamous worm.</p>
<p><img class="alignleft size-full wp-image-458" title="worm_downad_e_bd" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/worm_downad_e_bd.gif" alt="worm_downad_e_bd" width="490" height="591" /></p>
<p> </p>
<p>As well as reactivating the original propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This new Downad/Conficker variant is talking to a server which is known already for being associated with the Waledac family of malware, in order to download further malicious components. These components have so far been missing, but could this finally be the &#8220;other boot dropping&#8221; that we have all been waiting for?</p>
<p> </p>
<p>Waledac has, for a while now, been suspected to be the latest offering from the people behind the Storm botnet. Could it be that Downad/Conficker, Waledac and Storm all originate from the same cybercriminal gang?</p>
<p> </p>
<p>Please read the <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_self">TrendLabs Malware blog </a>for a detailed breakdown.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Restore Access to Blocked Sites on Conficked Systems</title>
		<link>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/</link>
		<comments>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 21:29:45 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=397</guid>
		<description><![CDATA[As has been previously noted on this blog and many others over the past few weeks. A machine infected with Downad/Conficker will not be able to access many of the domains which can assist in the cleanup of the infection.   So in anticipation of the &#8220;Impending Technological Apocalypse™&#8220;. Trend Micro is pleased to bring [...]]]></description>
			<content:encoded><![CDATA[<p>As has been previously noted on this blog and many others over the past few weeks. A machine infected with Downad/Conficker will not be able to access many of the domains which can assist in the cleanup of the infection.</p>
<p> </p>
<p>So in anticipation of the &#8220;Impending Technological Apocalypse<span style="font-size: medium;">™</span>&#8220;. Trend Micro is pleased to bring you a method to outsmart the worm and restore access to those blocked web sites on your infected machines.</p>
<p> </p>
<p>1 -In the <strong>Start</strong> menu, choose <strong>Run</strong>. (If you cannot see the <strong>Run </strong>choice in your Start menu you may need to add it. It can be added as follows: Right mouse click the <strong>Start</strong> button and choose <strong>Properties</strong>. Hit the <strong>Customise</strong> button and choose <strong>Advanced</strong>. In the <strong>Start Menu Items </strong>section, scroll down until you see the check box for <strong>Run Command</strong>, check that box as below, and hit <strong>OK</strong>).</p>
<p><img class="alignleft size-full wp-image-399" title="startmen" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/startmen.png" alt="startmen" width="403" height="423" /></p>
<p> </p>
<p> </p>
<p>2- Alright, so now you can hit the <strong>Start</strong> button and choose <strong>Run</strong>. In the Run window that appears, type <em><strong>cmd</strong></em> as below and hit <strong>OK</strong>.</p>
<p><img class="alignleft size-full wp-image-400" title="runcmd" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/runcmd.png" alt="runcmd" width="347" height="186" /></p>
<p> </p>
<p>3 -In the window that appears, type the command <strong><em>net stop dnscache</em></strong>, and hit Enter, then type <em><strong>exit</strong></em> and hit Enter again. It should appear exactly as show below.</p>
<p><img class="alignleft size-full wp-image-403" title="dosbox" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/dosbox.png" alt="dosbox" width="669" height="338" /></p>
<p> </p>
<p>4 &#8211; Right, we&#8217;re almost done, just a belt-and-braces check to do now. Again click <strong>Start</strong> and choose <strong>Run</strong>. This time type <em><strong>services.msc</strong></em> in the Run box and click <strong>OK</strong>. It brings up a window as shown below</p>
<p><img class="alignleft size-full wp-image-407" title="services" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/services.png" alt="services" width="701" height="526" /></p>
<p> </p>
<p>5 &#8211; Double-click the <strong>DNS Client</strong> entry in the list, and if it is not already stopped, hit the <strong>Stop</strong> button.</p>
<p> </p>
<p>Hey presto! You should now be able to access all of those previously blocked sites, of course including the excellent <a href="http://housecall.trendmicro.com/uk/" target="_blank">HouseCall </a>for all your cleanup needs.</p>
<p> </p>
<p>This service has been brought to you by a large Indian meal, a very long day and a well-known Tennesee Sippin&#8217; Whiskey</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Poisoned Downad/Conficker Removal Searches&#8230;</title>
		<link>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/</link>
		<comments>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 21:12:04 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[SEO]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=373</guid>
		<description><![CDATA[Reminder: For a FREE tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available here. As soon as the good news breaks that it is possible to use tools such as the network scanning tool nmap to search for machines infected by Downad/Conficker, then the malicious SEO work starts. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Reminder</strong>: For a <strong><span style="color: #800000;">FREE </span></strong>tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available <a href="http://www.trendmicro.com/download/dcs.asp" target="_blank">here</a>.</p>
<p>As soon as the <a href="http://www.theregister.co.uk/2009/03/30/conficker_signature_discovery/" target="_blank">good news breaks</a> that it is possible to use tools such as the network scanning tool <a href="http://nmap.org/" target="_blank">nmap </a>to search for machines infected by Downad/Conficker, then the malicious SEO work starts.</p>
<p><img class="alignleft size-full wp-image-375" title="nmapconresult1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/nmapconresult1.png" alt="nmapconresult1" width="560" height="323" /></p>
<p>If you need malware removal tools type the URL of your vendor of choice directly into the browser bar and use links on their website. Do not rely on Google search results at this time, as they may have been &#8220;optimised&#8221;.</p>
<p>Careful what you click on, these Google results are loaded!</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>UK Parliament Conficked!</title>
		<link>http://countermeasures.trendmicro.eu/uk-parliament-conficked/</link>
		<comments>http://countermeasures.trendmicro.eu/uk-parliament-conficked/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 20:01:52 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=342</guid>
		<description><![CDATA[  According to blogger Dizzy Thinks, the UK Parliament has become the latest institution to fall victim to the spread of Downad/Conficker. In an internal memo, which was subsequently leaked, network users were advised the following:   To: All users connecting directly to the Parliamentary Network The Parliamentary Network has been affected by a virus [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-352" title="UB006571" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/houses-of-parliament01.jpg" alt="UB006571" width="450" height="299" /></p>
<p> </p>
<p>According to blogger <a href="http://dizzythinks.net/2009/03/exclusive-uk-parliamentary-network.html" target="_blank">Dizzy Thinks</a>, the UK Parliament has become the latest institution to fall victim to the spread of Downad/Conficker. In an internal memo, which was subsequently leaked, network users were advised the following:</p>
<p> </p>
<blockquote><p><em><strong>To: All users connecting directly to the Parliamentary Network</strong></em></p>
<p><em>The Parliamentary Network has been affected by a virus known as conficker. This virus affects users by slowing down the Network and by locking out some accounts. We are continuining [sic] to work with our third party partners to manage its removal and we need to act swiftly to clean computers that are infected.</em></p>
<p><em> </em></p>
<p><em>We are scanning the Network and if we identify any equipment which we believe is infected with the virus then we will contact you to ensure that the device is either removed from the Network or cleaned and loaded with the correct software to prevent this infection reoccurring.</em></p>
<p><em>You can help us to contain this problem and prevent new infection by adhering to the following advice:</em></p>
<ul>
<li><em>We are unable to clean PCs and portable computers which are either not switched on or which are not authorised devices. We therefore ask that if you are running a PC or portable computer not authorised to be on the Network that you take it off immediately.</em></li>
<li><em>An additional characteristic of this virus is that for some types of files it can skip direct to the Network from a USB memory stick or other portable storage device (e.g. mp3 players) without hitting the virus checker software. We ask that for the time being you do not use memory sticks or any other portable storage devices on the Parliamentary Network.</em></li>
<li><em>If you do identify a problem with the equipment you are running, please contact the PICT Service Desk on 020 xxxx 200x when it reopens on Wednesday 25 March from 8am.</em></li>
<li><em>If you are connecting using one of our remote access services, from a Constituency Office for example, a separate communication will be sent to you.</em></li>
</ul>
<p><em>Director of Parliamentary ICT.</em></p>
<p> </p></blockquote>
<p>This raises several salient questions in my mind&#8230;</p>
<p>1- What the expletive are &#8220;<em>unauthorised devices</em>&#8221; doing on the Parliamentary network in the first place? Of all the organisations in the country you would expect the UK parliament to be using Network Access Control technology to keep the wrong &#8216;uns out!</p>
<p> </p>
<p>2- What kind of anti-malware solution are they running there that allows a worm to &#8220;<em>skip</em> <em>direct to the Network from a USB memory stick or other portable storage device (e.g. mp3 players) without hitting the virus checker software</em>&#8221; and also, one that doesn&#8217;t detect the worm itself?</p>
<p> </p>
<p>3- Where&#8217;s the port control or DLP solution?Tthe memo itself being made public amply demonstrates (if any proof were needed) that the potential for data leakage exists, and this is Parliament.</p>
<p> </p>
<p>4- What kind of message is this &#8220;<em>We are unable to clean PCs and portable computers which are not switched on</em>&#8220;? Surely this could be interpreted as &#8220;<em>We are experiencing an outbreak, please make sure all computers are switched on</em>&#8220;. That doesn&#8217;t sound like good containment policy to me.</p>
<p> </p>
<p>I don&#8217;t want this post to be entirely negative though, so, <em>Dear Parliament, if you are having trouble cleaning this up, give us a call we&#8217;ll come and do it for nothing</em>.</p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/uk-parliament-conficked/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Downad/Conficker, who&#8217;s the April Fool?</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/</link>
		<comments>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 17:52:47 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311</guid>
		<description><![CDATA[A brief outline of the story so far with WORM_DOWNAD and some thoughts about the April 1st &#8220;activation date&#8221;.     &#8220;This could well be very big, but it will also be very quiet.&#8221; I&#8217;m beginning to get a little exercised by many of the verbs I am seeing attached to this malware in recent commentary; words like [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">A brief outline of the story so far with </span><a href="http://www.trendmicro.com/vinfo/virusencyclo/default2.asp?m=q&amp;virus=DOWNAD&amp;alt=DOWNAD" target="_blank"><span style="color: #888888;">WORM_DOWNAD</span></a><span style="color: #888888;"> and some thoughts about the April 1st &#8220;activation date&#8221;.</span></span></span></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">&#8220;This could well be very big, but it will also be very quiet.&#8221;</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">I&#8217;m beginning to get a little exercised by many of the verbs I am seeing attached to this malware in recent commentary; words like &#8220;virus set to explode&#8221;, &#8220;erupt&#8221;, &#8220;blow up&#8221; or &#8220;will infect 12m computers on April 1st&#8221;. I put the following information together to try to clarify exactly what will be &#8220;activated&#8221; on April the 1st and bring some rationality to the debate.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">First Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">In November 2008, Downad/Conficker was seen for the first time. This first variant was the most simple; it spread by exploiting a vulnerability (</span><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank"><span style="color: #888888;">MS08-67</span></a><span style="color: #888888;">) that was actually patched by Microsoft back in October of 2008. This variant actively avoided infecting systems that were configured to use a Ukrainian keyboard layout or had IP addresses registered to the Ukraine (which may give some clue as to its origins). This original variant, once it had infected a machine would firstly randomly generate IP addresses and use those to search for new victims to infect and then go on to attempt to download some rogue antivirus “scareware” as a one-time event. From that point on, it would generate a daily list of 250 pseudo-random domain names using the top level domain suffixes com, .net, .org, .info, and .biz and attempt to connect out to those servers and download further malicious content.</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;"><img class="alignleft size-full wp-image-313" title="worm_downad_a1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/worm_downad_a1.gif" alt="worm_downad_a1" width="450" height="475" /></span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">Second Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">January 2009 saw the second Downad/Conficker variant, which was largely a rewrite of the first; it no longer excluded Ukrainian systems and did not try to download the “scareware” as the first variant did. It also used several more mechanisms through which to spread. In addition to exploiting the Microsoft vulnerability, it also spread by writing to any removable drives plugged into infected systems, any shared network drives currently attached and additionally searched for machines on the same network against which it would attempt a brute force password attack using a list of over 240 predefined common passwords. This second variant also attempted to disable many well known anti-virus programs, blocks access to security related web sites, and disabled key Microsoft security services such as Windows Automatic Update. These additional methods of self-propagation are though to have contributed to the worm’s success at infecting large numbers of machines.</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;"> </span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">This second variant also generates a daily list of 250 domains to try to connect to this time using more top level domain suffixes com, .net, .org, .info, .biz, and adding .ws, .wn and .cc  The domains generated by the two versions do not overlap.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> <img class="alignleft size-full wp-image-314" title="downad_1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/downad_1.jpg" alt="downad_1" width="448" height="448" /></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">Third Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In March 2009, a significant third Downad/Conficker variant surfaced. This new version appears to have been spread by an update pushed out to machines previously infected with the second variant. This new version now generates a daily list of 50,000 Internet domain names instead of the 250 generated previously and rather than the 5 or 8 top level domains used by the first two variants, this version uses 110 different top level domains. Only 500 of these generated domains are queried, and only once per day. It is this mechanism that is coded to begin on 1<sup>st</sup> April, and the sheer numbers of domain names involved render redundant the blocking mechanisms used so far to combat the worm.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In addition to this already established HTTP Command &amp; Control infrastructure, this new variant also introduced Peer to Peer communications capabilities between infected hosts, presumably in an effort to get around the security and internet industries attempts to shut down the HTTP connection mechanism.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In this third update, the propagation methods present in the first and second variants have been removed and the stance of the infection has shifted to a more defensive one. This signals perhaps that the cybercriminals behind this feel they have infected enough machines to turn this into a “simple” botnet for distributing whichever malicious code they see fit. Remember though, the propagation functionality could just as easily be switched on again as required by the authors.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">It&#8217;s really anyone&#8217;s guess what the infected hosts will be used for if the command &amp; control infrastructure goes live on April 1st. Pushing rogue AV? Sending Spam? Carrying out Denial of Service attacks on other servers and Internet infrastructure? Hosting Malware and Phishing sites? Or simply creating a very large asset pool of infected PCs for the owners to rent out for cash? Personally I don&#8217;t buy into the mass attack scenario, the motivator for mainstream cybercrime is still cash generation, and &#8220;bringing down the Internet&#8221; wouldn&#8217;t be much of an earner. The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment. Making so much noise that every victim knows they&#8217;re infected will have entirely the opposite effect. This could well be very big, but it will also be very quiet.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">If you believe your system may be infected by Downad/Conficker, then online scanners and tools almost certainly won&#8217;t be of any use to you, because the websites will be blocked by the infection. I would recommend you download </span><a href="http://www.trendmicro.com/download/dcs.asp" target="_blank"><span style="color: #888888;">SysClean</span></a><span style="color: #888888;">, a free tool from Trend Micro to remove any infection.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">For a great in-depth analysis of Downad/Conficker, please have a look at the </span><a href="http://mtc.sri.com/Conficker/" target="_blank"><span style="color: #888888;">Research Paper</span></a><span style="color: #888888;"> written by SRI International</span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>
