Conficker worm sends new instructions: grow botnet, then die
Last Updated: Thursday, April 9, 2009 | 2:46 PM ET
CBC News
Related
Internal Links
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
The Conficker worm has begun to update the machines it has infected with a new set of instructions to spread to other machines and then self-destruct, security experts say.
Security researchers tracking the worm said some of the infected computers began receiving instructions on April 7 from other infected machines. Conficker is able to send updates to computers it has infected either by directing the computers to visit websites or through a peer-to-peer network of infected machines.
Last week Conficker had computer and internet organizations worldwide up in arms against it because it was known that a variant of the worm would begin accelerating the speed with which it reached out to websites on April 1.
It was thought the worm might send out instructions that day, but instead it appears to have waited a week before doing so, and rather than sending the instructions through a website, it sent them over the peer-to-peer network.
The instructions tell the computers to attempt to contact other computers and exploit a vulnerability in older Microsoft Windows products — Windows 2000, Windows XP and Windows Server 2003 — that would allow the worm to take over the computer and expand its network of infected machines.
The instructions had appeared on previous versions of the worm but were removed in the Conficker C variant, leading security experts to believe the people behind the virus were trying to temporarily slow its growth to make it harder to track.
The new instructions also direct computers to visit established websites such as myspace.com, msn.com, ebay.com, cnn.com, and aol.com, but once there no code is downloaded or weaknesses are exploited, leading some firms to suggest the worm is simply checking to confirm the computer is connected with the internet.
The instructions also appear to have a time limit, Symantec reports. On May 3, 2009, the new instructions will not only stop running, but the worm will activate a self-removal program, although it's not known when it does this whether it will leave behind some legacy of the worm or perhaps another, different worm.
Kevin Haley, director of Symantec Security Response, said the self-destruction instruction is unique, and may be the virus writer's way of making it harder for users to track its progress.
"Conficker is the name on everybody's lips right now, so if you remove the traces of Conficker but leave something else behind, users won't know what to look for," he said.
Symantec has speculated Conficker might be connected to another spam bot, called Waledac.
Share Tools
Top News Headlines
- Aylmer triple stabbing leads to first-degree murder charges

- The estranged partner of a young mother who was stabbed to death along with her parents at their home in Aylmer, Que., has been charged with first-degree murder Friday. more »
- Wildfires, high winds put northeastern Ontario on alert
- It's going to be a tense weekend in northeastern Ontario where strong, shifting winds have been fuelling a forest fire that has blanketed the Timmins area with smoke and ash. more »
- Labrador fire out of control
- A forest fire continues to burn out of control in Happy Valley-Goose Bay today, according to provincial firefighting officials. more »
- The risks and responsibilities of taking on Mt. Everest

- The deaths of five climbers last weekend on Mt. Everest, with more summits underway this weekend, fuels the debate about the risks and responsibilities of high altitude climbing. more »
Latest Technology & Science News Headlines
- Unloading of docked SpaceX capsule to start Saturday
- The privately bankrolled SpaceX Dragon capsule made a historic arrival at the International Space Station on Friday, and astronauts will begin unloading some of the 544 kilograms of food, water, clothing and other supplies its carrying starting Saturday.
more »
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Aylmer triple stabbing leads to first-degree murder charges
- Everest victim's husband says family not seeking government help
- B.C. premier unhappy with disgraced Mountie's transfer
- Canada ending 'Buffalo shuffle' for visas, closing consulate
- What a Greek euro exit could mean for Canada
- Third B.C. salmon farm quarantined
- RCMP officer charged in fatal crash
- Police probe Halifax homicide after shooting
- Ottawa man in hospital after lightning strike

