About
Subscribe

Downadup spreads like wildfire

Trend Micro warns of a worm called WORM_DOWNAD.AD. The worm has already affected 8.9 million computers, and it is suggested that consumers keep their machines up-to-date, disable the autorun feature in Windows, and enforce strong password policy.

Johannesburg, 21 Jan 2009

Trend Micro (TSE: 4704), a global leader in Internet content security, announced today that it has been informed of a worm which is spreading like wildfire. The worm is called Downadup, or Conficker, and self-propagates by exploiting a Microsoft vulnerability. It is reported that 8.9 million computers have already been affected globally.

Rik Ferguson, Solutions Architect, Solution Service & xSP Business Development, Trend Micro, comments: "From our perspective this is interesting because this 'old school' worm has a command-and-control structure that the victim machines call out to. It's essentially a hybrid of old and new techniques, and we are concerned this could be the first step in the creation a massive botnet."

The worm has been in the wild since late November of 2008. According to the officials, the problem is global. Infections have been seen in North America, Asia, Europe, South America, Australia and New Zealand and Africa, and the problem is still growing.

"There are three main reasons why this worm is able to spread so effectively. The first and most important being unpatched machines, so recommendation number one, keep your machines up-to-date with all available patches at all times. It also spreads through removable media and network shares via autorun files. It is standard security practice to disable the autorun feature in Windows. Finally, it also tries to replicate through brute force password cracking attempts, so enforce strong password policy on all user accounts," suggests Ferguson. Consumers are also advised to check the Trend Micro Safe Computing Guide:

http://us.trendmicro.com/us/threats/home-user/preventing-intrusions/safe-computing-guide/

With the Smart Protection Network and the latest Trend Micro Engine and Pattern files, Trend Micro can provide detection for this worm in the cloud and at the gateway, server and end-point.

Share

Trend Micro

Trend Micro, a global leader in Internet content security, focuses on securing the exchange of digital information for businesses and consumers. A pioneer and industry vanguard, Trend Micro is advancing integrated threat management technology to protect operational continuity, personal information, and property from malware, spam, data leaks and the newest Web threats. Visit TrendWatch at www.trendmicro.com/go/trendwatch to learn more about the threats. Trend Micro's flexible solutions, available in multiple form factors, are supported 24/7 by threat intelligence experts around the globe. Many of these products and solutions are powered by the Trend Micro Smart Protection Network, a next-generation cloud-client content security infrastructure designed to protect customers from Web threats. A transnational company, with headquarters in Tokyo, Trend Micro's trusted security solutions are sold through its business partners worldwide. Please visit www.trendmicro.com.