Symantec has observed an increase in infections relating to W32.Downadup over the holiday period and is urging organizations to apply the patch for Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability as soon as possible.
A new variant of this threat, called W32.Downadup.B, appeared on December 30th and can not only propagate by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability, but can also spread through corporate networks by infecting USB sticks and accessing weak passwords. These propagation methods are nothing new; W32.Spybot, W32.Randex, and W32.Mytob variants all use almost identical methods to spread, but this variant requires more effort to protect corporate networks.
W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed. The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible. The worm also monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network request timed out. This means infected users may not be able to update their security software from those websites. This can be problematic as worm authors generally dish out new variants constantly.
Symantec researchers are seeing considerable detections of both variants of W32.Downadup and W32.Downadup.B. As illustrated by the following infection maps based on data from the past 60 days, the infections are geographically quite widespread. The highest infection rates typically correspond to countries with high rates of computer/Internet usage.
Symantec strongly encourages users to patch their system against the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability, take steps to control the execution of applications referenced in the autorun.inf files that may be located on removable and network drives, and enforce a strong password policy on all computers within their networks. Particularly during holiday periods patch updates can be missed and is an opportune time for malware to spread. Consider implementing an automated patch management solution to help mitigate risk.
Click here to obtain more information about how to prevent a threat from spreading using the "AutoRun" feature.
For more detail on the evolution and infection statistics of this threat, check out the earlier Security Response blog posting - W32.Downadup Infection Statistics - posted on January 6th.
Friday, February 20, 2009
New Variants of W32.Downadup.B
Subscribe to:
Post Comments (Atom)
Link Exchange
Donation
Visitor
Online
Do you like this blog
Arsip Blog
-
▼
2009
(209)
-
▼
February
(61)
- Zuckerberg, the maker facebook
- Make district program uses vb6 and sql server 2000
- Program maker uses visual basic 6
- Inbox Dollars Sign Up Get $5
- Earning with linkpayer
- Boost SEO with ask2link
- Trying adsense with great bidvertiser
- Now earning fast with incentria
- Earn money with Clix n Cash
- Earning IndoPTC
- Free domain with co.cc cc.cc redirect to your blog
- How to create link banner
- What is AdSense for feeds?
- My blog using do follow
- How to remove W32.Downadup.B worm manually
- Technical Details w32.downadup.b
- New Variants of W32.Downadup.B
- Why Ziddu
- Informasi mengenai virus dari Yahoo messenger
- Cara memasang sitemap di blogger
- Elite politik konflik....?
- Indonesia jangan terlalu banyak import
- Tragedi Villa Puncak
- The 411 on the 502
- Intro to Feed Placements
- What kind of revenues can i earn from adsense ?
- The 7 things you should never do
- Six ways to experiment with AdSense and grow your ...
- Payments by Western Union now available in Indonesia
- Senggolan Maut
- Inge, Rekan Kerjaku
- Pacar Kakakku
- Pembantu-pembantu yang Seksi
- Asiah Pembantuku, Dari Jinak Menjadi Liar
- Dugem Dan Seks
- Hujan Membawa Nikmat
- Hypersex Party
- Oops.. I Did It Again (With Sinta)
- Kisah Seks Saat Medical Check Up
- Akibat Berenang Bugil
- Yilly Menggodaku di Kereta dan akhirnya …
- Nafsu Terpendam Angela
- Sensasi Inah dan Mbak Asti
- Anggi Sudah Terlatih sejak SD
- Pacarku ternyata Doyan Seks Bebas
- Hati-hati penipuan di internet Lottery Winner
- Langsung jadi kaya lewat bisnis online
- Satu lagi search dapat duit seperti My Home Page F...
- Peperangan Timur Tengah kapan segera berakhir
- Bekerja secara online akan semakin luas dan semuan...
- Bagaimana Cara Menaikkan Alexa Rank Blog Anda
- Proses Pendaftaran Adsense
- Persiapan Dengan Adsense
- Sebenarnya, mendapatkan uang sebagai adsense publi...
- Sekilas Tentang Google Adsense
- Memanfaatkan Friendster & FaceBook Sebagai Lahan P...
- 1000 Cara Meningkatkan Ranking Alexa
- Marketing versi Blogger
- Google PageRank dan Cara Meningkatkan PageRank
- Cara mudah meningkatkan pagerank
- 75 Cara Untuk Meningkatkan Traffic Blog Anda
-
▼
February
(61)
0 comments:
Post a Comment