Conficker worm sends new instructions: grow botnet, then die
Last Updated: Thursday, April 9, 2009 | 2:46 PM ET
CBC News
Related
Internal Links
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
The Conficker worm has begun to update the machines it has infected with a new set of instructions to spread to other machines and then self-destruct, security experts say.
Security researchers tracking the worm said some of the infected computers began receiving instructions on April 7 from other infected machines. Conficker is able to send updates to computers it has infected either by directing the computers to visit websites or through a peer-to-peer network of infected machines.
Last week Conficker had computer and internet organizations worldwide up in arms against it because it was known that a variant of the worm would begin accelerating the speed with which it reached out to websites on April 1.
It was thought the worm might send out instructions that day, but instead it appears to have waited a week before doing so, and rather than sending the instructions through a website, it sent them over the peer-to-peer network.
The instructions tell the computers to attempt to contact other computers and exploit a vulnerability in older Microsoft Windows products — Windows 2000, Windows XP and Windows Server 2003 — that would allow the worm to take over the computer and expand its network of infected machines.
The instructions had appeared on previous versions of the worm but were removed in the Conficker C variant, leading security experts to believe the people behind the virus were trying to temporarily slow its growth to make it harder to track.
The new instructions also direct computers to visit established websites such as myspace.com, msn.com, ebay.com, cnn.com, and aol.com, but once there no code is downloaded or weaknesses are exploited, leading some firms to suggest the worm is simply checking to confirm the computer is connected with the internet.
The instructions also appear to have a time limit, Symantec reports. On May 3, 2009, the new instructions will not only stop running, but the worm will activate a self-removal program, although it's not known when it does this whether it will leave behind some legacy of the worm or perhaps another, different worm.
Kevin Haley, director of Symantec Security Response, said the self-destruction instruction is unique, and may be the virus writer's way of making it harder for users to track its progress.
"Conficker is the name on everybody's lips right now, so if you remove the traces of Conficker but leave something else behind, users won't know what to look for," he said.
Symantec has speculated Conficker might be connected to another spam bot, called Waledac.
Share Tools
Top News Headlines
- Vancouver rioter sentenced to 17 months
- Ryan Dickinson has been sentenced to 17 months in jail for his part in the June 15, 2010, Vancouver riot. more »
- Former Expos catcher Gary Carter succumbs to brain cancer
- Hall of Fame catcher Gary Carter, who left an indelible mark on baseball in Canada during his 12 years with the Montreal Expos, died on Thursday. The man nicknamed "Kid" or "Kid Carter" for his ever-smiling face and cheerfulness is free from the inoperable brain cancer that sapped his energy and took his life at age 57. more »
- Dog kills newborn in Alberta community
- Officials in Airdrie are revealing few details about the fatal mauling of an infant by a family dog in the southern Alberta city. more »
- Underwear bomber sentenced to life in prison
- A Nigerian man who tried to blow up an international flight near Detroit on behalf of al-Qaida has been sentenced to life in prison without parole. more »
Latest Technology & Science News Headlines
- Apple to stop apps from stealing smartphone contacts
- Apple says it is making policy changes to stop iPhone apps from copying contacts in users' address books without permission. more »
- Moore defends Canada's 'different path' on copyright bill
- Heritage Minister James Moore says Canada's copyright legislation is taking a very different path from a controversial U.S. piracy bill that drew widespread protests. more »
- Canada helps target pollution in developing world
- Soot and methane pollution in the developing world are being targeted by a new coalition of six countries, including Canada. more »
- Online surveillance bill could change, Harper signals
- The government says it's open to amending its bill that would give police and intelligence agencies new powers to access Canadians' electronic communications and get telecommunications subscriber data. more »
Bob McDonald's Blog
Glacier Discovery Walk: Will the visitor centre enhance the view? Feb. 14, 2012 9:22 AM Environment minister Peter Kent has announced the construction of a new Glacier Discovery Walk and visitor centre on the Icefields Parkway in Jasper National Park. It raises the issue of how to balance commercial development in our National Parks against the preservation of the last refuges of wilderness.
Quirks & Quarks
- February 18: Guitar Hero, or Guitar Zero? Feb. 15, 2012 10:53 AM An NYU professor of psychology describes how he was able to learn to play the guitar in midlife in spite of a limited musical aptitude, and what it tells us about how our brains learn.
Latest Features
- Dog kills newborn in Alberta community
- Degrassi's Wheels death announced, over 4 years later
- Refugee reforms include fingerprints, no appeals for some
- Montreal telemarketers in fraud case still making calls
- Bully victim's mother tells of 'suicide box'
- Honduras prison fire is world's deadliest
- Nortel collapse linked to Chinese hackers
- 2 small earthquakes rattle Vancouver Island
- Barefoot girl's icy trek not blamed on babysitter

