Alert: New worm affecting corporate networks

  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.
  • warning: preg_match() expects parameter 2 to be string, array given in /var/www/html/includes/bootstrap.inc on line 684.

Alert: New worm affecting corporate networks

By Victor Ng | Jan 8, 2009

F-Secure has issued an alert about new versions of the "Downadup" worm, which infect Windows workstations and servers, causing various problems.

Since New Year, F-Secure has received several reports of corporate networks getting infected with variants of this worm. Information and network security experts are working closely with affected companies as well as with various CERT organizations to fight this worm outbreak.

Downadup (also known as Conficker) is large family of network worms. They are unusually difficult to remove, especially in the case of an internal infection inside a corporate network.

What to do to avoid infection

  • Make sure latest Microsoft patches have been applied
  • Make sure your organization is running the latest version of your antivirus product
  • Check that the antivirus product has the latest updates
  • Turn off AUTORUN and AUTOPLAY for USB sticks
  • Make sure users domain passwords are strong
  • Take extra care about the domain administrators’ passwords

What to do if your network is already infected

  • Check your antivirus vendor’s website for disinfection instructions
  • Disinfection of this worm is complex and could require shutting down parts of your network
  • Restrict USB stick usage and block unnecessary traffic at your firewalls

What does the worm do?
Downadup uses several different methods to spread. These include using the recently patched vulnerability in Windows Server Service, guessing network passwords and infecting USB sticks.

 
 
12

Add comment

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <a> <p> <span> <div> <h1> <h2> <h3> <h4> <h5> <h6> <img> <img /> <map> <area> <hr> <br> <br /> <ul> <ol> <li> <dl> <dt> <dd> <table> <tr> <td> <em> <b> <u> <i> <strong> <font> <del> <ins> <sub> <sup> <quote> <blockquote> <pre> <address> <code> <cite> <embed> <object> <strike> <caption>
  • Lines and paragraphs break automatically.
  • Use <!--pagebreak--> to create page breaks.

More information about formatting options

 

Comments

knowledge_central_tab

 
 
Knowledge Central
Today's top security priorities
Attacks based on vulnerabilities in websites are skyrocketing, and not many solutions are available to protect organizations against them. How do you deal with this and other key security issues today?
Taking a holistic business-centric approach to security
Today’s CIOs face multiple challenges, including the need to innovate in an extremely competitive business climate, address highly dynamic regulatory and compliance challenges, speed ROI to counter shrinking IT budgets, and secure their organizations against a wide barrage of sophisticated threats.
 
 
 
UTM product offers Logansport Savings Bank superior protection
Astaro Security Gateway’s IPS was able to block attacks that other intrusion prevention systems (IPS) missed at Logansport Savings Bank.
Hong Leong Financial opts for Juniper Networks at new Malaysia head office, data center
Hong Leong Financial Group Berhad builds complete and seamless data center and office network infrastructure with Juniper switches, security devices and Junos software.