<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:,2009:/1/tag:www.readwriteweb.com,2009://1.14581-</id>
  <updated>2009-11-07T00:40:58Z</updated>
  <title>Comments for It&apos;s Alive! Conficker Wakes Up - And Now It Has a Business Model</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.23-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=14581" title="It's Alive! Conficker Wakes Up - And Now It Has a Business Model" />
    <published>2009-04-09T16:38:39Z</published>
    <updated>2009-04-10T03:53:33Z</updated>
    <title>It&apos;s Alive! Conficker Wakes Up - And Now It Has a Business Model</title>
    <summary>Conficker, the Internet worm that caused a mild panic reminiscent of Y2K late last month, but which failed to do anything spectacular that would have warranted the breathless coverage on 60 Minutes (&quot;The Internet is Infected&quot;), has finally woken up. This morning the worm&#160; started to update itself via a peer-to-peer network between infected machines...</summary>
    <author>
      <name>Frederic Lardinois</name>
      
    </author>
    
    <category term="NYT" />
    
    <category term="News" />
    
    <category term="Real World" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="conficker_mar_09.jpg" src="http://www.readwriteweb.com/images/conficker_mar_09.jpg"  /><a href="http://en.wikipedia.org/wiki/Conficker">Conficker</a>, the Internet worm that caused a mild panic reminiscent of Y2K late last month, but which <a href="http://www.pcworld.com/article/162570/is_conficker_finally_history.html">failed</a> to do anything spectacular that would have warranted the breathless coverage on <a href="http://www.youtube.com/watch?v=Ar-l3FRUdGw">60 Minutes</a> ("The Internet is Infected"), has finally woken up. This morning the worm&#160; started to update itself via a <a href="http://blog.trendmicro.com/a-look-inside-conficker-p2p-traffic/">peer-to-peer network</a> between infected machines after downloading its payload from a server in South Korea.</p>]]>
      <![CDATA[<p>It is not clear how many machines were infected with this worm, but estimates range from 9 million to 15 million.</p>

<p>While earlier variations of the Conficker worm prevented infected machines from accessing the servers of most antivirus companies, this new variant also blocks access to sites that offer tools for removing the worm like BitDefenders <a href="http://www.bdtools.net/">bdtools.net</a>.</p>

<p><img alt="alive_apr09.png" align="left" src="http://www.readwriteweb.com/images/alive_apr09.png"  />Oddly, the Conficker worm now also includes an instruction that tells the worm to remove itself on May 3 (the hackers clearly like deadlines), though after that, it will keep a port open on these machines that will allow the hackers to get back into these computers at any time.</p>

<h2>The Big Picture: Spyware, Spambots, Pop-Ups</h2>

<p>According to both <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/">Trend Micro</a> and Symantec, Conficker, after downloading its update, also downloads a variant of the well-known <a href="http://www.mxlogic.com/itsecurityblog/1/2009/02/The-Many-Phases-of-Waledac.cfm">Waledac malware</a>. Waledac is one of the world's most active spambots.</p>

<p>Security researchers are still <a href="http://garwarner.blogspot.com/2009/04/is-there-conficker-e-waledac-makes-move.html">trying to understand</a> the connection between Waledac and Conficker's new E variant (only a <a href="http://www.virustotal.com/analisis/d4fa1ee6ef7d08aafc30eb6b71911b99">small number of antivirus products</a> can currently detect this version of Waledac, by the way). Some, however, speculate that this connection could mean that Conficker was created by the same group of hackers that created Waledac and its predecessor, the infamous <a href="http://en.wikipedia.org/wiki/Storm_botnet">Storm botnet</a>.</p>

<h2>Business Model?</h2>

<p><img alt="fake_spyware_conficker.png" align="right" src="http://www.readwriteweb.com/images/fake_spyware_conficker.png"  /><a href="http://www.viruslist.com/en/weblog?weblogid=208187654">According to</a> Kaspersky Labs' Alex Gostev, Waledac will download a rogue antivirus application onto infected machines, as well as an email-worm that can steal data and send spam. The fake antivirus software will ask users to pay $49.95 for "Spyware Protect 2009," which, of course, is anything but an antispyware product. </p>

<h2>Protect Yourself (and others)</h2>

<p>Of course, if your Windows machine is up to date and if you have kept your antivirus software up to date then chances are very good that you are well protected against Conficker. </p>

<p>If you want to learn more about Conficker and how to protect yourself, have a look at <a href="http://www.readwriteweb.com/archives/7_resources_to_help_you_prepare_for_confickers_d-d.php">this list of resources</a> we put together last month. If you want to see if you are infected, head over to <a href="http://iv.cs.uni-bonn.de/fileadmin/user_upload/werner/cfdetector/">this site from the University of Bonn</a>. </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:132726</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c132726" />
    <title>Comment from Mathieu on 2009-04-09</title>
    <author>
        <name>Mathieu</name>
        <uri>http://friendfeed.com/mathplourde</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://friendfeed.com/mathplourde">
        <![CDATA[<p>Well, it seems like everyone but Twitter has a business model...</p>]]>
    </content>
    <published>2009-04-09T18:15:10Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:132733</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c132733" />
    <title>Comment from OLL on 2009-04-09</title>
    <author>
        <name>OLL</name>
        <uri>http://www.vozlabs.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.vozlabs.com">
        <![CDATA[<p>Well, it seems like everyone but Twitter has a business model...</p>

<p>hahahahahahahahaaa</p>]]>
    </content>
    <published>2009-04-09T19:28:16Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:132834</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c132834" />
    <title>Comment from dinleme cihazı on 2009-04-10</title>
    <author>
        <name>dinleme cihazı</name>
        <uri>http://www.dinlemecihazi.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.dinlemecihazi.com">
        <![CDATA[<p>Thanks you </p>]]>
    </content>
    <published>2009-04-10T12:55:56Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:132882</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c132882" />
    <title>Comment from Thedmo on 2009-04-10</title>
    <author>
        <name>Thedmo</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>My gf has a User Account (XP, sp3) on my pc, and was running Spyware Doctor yesterday (April 9) when it appeared to end too soon. </p>

<p>I brought it up and it said "Last Scan 600+ Days Ago." I ran it again. At 66% it began scanning the file "Conficker," which went through tens of thousands of files. </p>

<p>I tried unsuccessfully to access my ASP (another sign of infection, apparently). I went to Microsoft and downloaded the March 30 malware removal tool. Gf does not have admin privileges, so I logged out, logged in as me and ran the tool. </p>

<p>Nothing. Ditto AVG. Ditto Spyware Dr. </p>

<p>I backed up my stuff, noting possibility of infection on the DVDs, and shut down. Today everything is running normally. NO av products caught anything. </p>

<p>I did a stop dsncache and updated my avg today and am running it now. </p>

<p>Any advice, besides "Switch to Linux"?</p>]]>
    </content>
    <published>2009-04-10T23:42:00Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:133481</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c133481" />
    <title>Comment from Jonny on 2009-04-14</title>
    <author>
        <name>Jonny</name>
        <uri>http://www.woopid.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.woopid.com/">
        <![CDATA[<p>This video explaining how to simply find out if you're infected with Conficker, and then tells you how to patch it the issue:<br />
<a href="http://www.woopid.com/video/2334/Conficker-Detection-and-Removal" rel="nofollow">Conficker Detection and Removal</a></p>]]>
    </content>
    <published>2009-04-14T19:24:00Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:134236</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c134236" />
    <title>Comment from conficker worm on 2009-04-18</title>
    <author>
        <name>conficker worm</name>
        <uri>http://conficker-virus-worm.blogspot.com/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://conficker-virus-worm.blogspot.com/">
        <![CDATA[<p>I think conficker is not a virus but its a adware..</p>

<p><a href="http://conficker-virus-worm.blogspot.com/" rel="nofollow">http://conficker-virus-worm.blogspot.com/</a></p>]]>
    </content>
    <published>2009-04-19T00:25:17Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.14581-comment:157940</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.14581" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/its_alive_conficker_wakes_up_and_now_it_has_a_business_model.php#c157940" />
    <title>Comment from Computer Help on 2009-09-16</title>
    <author>
        <name>Computer Help</name>
        <uri>http://www.support1000.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.support1000.com">
        <![CDATA[<p>Conficker can pop up on your computer in various ways, Del Conte added, whether as a pop-up that advertises a way to prevent the worm, or in your e-mail or Facebook account. She advises that, to be safe, you should never click on anything you're not familiar with. </p>]]>
    </content>
    <published>2009-09-16T10:48:18Z</published>
  </entry>

</feed>