Image
Interordi Menu
TopHat
Hats n' spirals
Inactive
2417 posts
Caprice
Caprice
Become Dr. Cossack's waifu
Acquired on 20 April 2012
Rin Tezuka
Rin Tezuka
Acquired on 1 April 2012
Engineer
Engineer
Acquired on 1 April 2012
Spy
Spy
Acquired on 1 April 2012
Soldier
Soldier
Acquired on 1 April 2012

... and 22 more
Quote

http://www.myfoxphilly.com/dpp/news/dpgo_Video_April_Fools_Day_Virus_fc_200903262336060

This thing lies dormant in your PC, and will supposedly activate April 1st (date chosen to either create an interesting news article or to make people suspect it of being a farce)

Apart from what it is and when it's set to go off, nothing else is known. It could brick your PC, it could cue up Rickroll on your PC every 5 minutes.

Microsoft is offering a free scan and a patch to protect against it. Type in "conficker" in wikipedia- links to both the scan and the patch will be found at the bottom of the page.

Sage
All Business.
Offline
1762 posts
Quote

Quote:
Originally posted by Teej
http://www.myfoxphilly.com/dpp/news/dpgo_Video_April_Fools_Day_Virus_fc_200903262336060

This thing lies dormant in your PC, and will supposedly activate April 1st (date chosen to either create an interesting news article or to make people suspect it of being a farce)

Apart from what it is and when it's set to go off, nothing else is known. It could brick your PC, it could cue up Rickroll on your PC every 5 minutes.

Microsoft is offering a free scan and a patch to protect against it. Type in "conficker" in wikipedia- links to both the scan and the patch will be found at the bottom of the page.


..sigh lol

Don't be suspicious about it's existence, it really is going to download it's payload on April 1. Keep in mind the exploit Conficker was patched back in October. Also, this variant (Variant C) is an update to previous infections. It doesn't self-propagate like the A variant. If you've been keeping up-to-date, you're fine.

Also, the infection rate of Conficker reached it's peak in Janurary. Not even that peak was as high as the infection rate for MSBLAST.

This variant is a pretty hearty one. It definitely falls into the category of "format is easiest fix." I would advise determining if you're infected before April 1.

Microsoft has been doing bounties since MSBLAST. I want to say that's how they got the guy who wrote SQL Slammer.

My money's on a planned DDoS attack on a significantly noticeable network. That's the only way the timing makes sense. I mean, waiting for months just to send spam or steal passwords/credit card numbers doesn't make sense at all. One thing's for sure, the botmaster is happy with the size and scope of his botnet and is now ready to use it.

Symantec's writeup (They call it Downadup, but it is the same worm):
http://www.symantec.com/norton/security_response/writeup.jsp?docid=2009-030614-5852-99&tabid=1


Fight, Megaman! For everlasting peace! ~ :o

Staff Backer Doctacosa
Admin
SciLab Official
Benevolent Dictator
Offline
6437 posts
Zenny
Zenny
Unlock all of the main forum features!
Acquired on 1 April 2014
Princess Celestia
Princess Celestia
Got all items in the AFD2012 event!
Acquired on 1 April 2012
Squid beaker
Squid beaker
Earned all 150 original CL achievements
Acquired on 17 January 2016
Unity.EXE emblem
Unity.EXE emblem
Defeat Bass.EXE in the AFD2013 event!
Acquired on 1 April 2013
Lilly Satou
Lilly Satou
Acquired on 1 April 2012

... and 25 more
Quote

What I don't understand is why now. The worm has been spreading around for several weeks, and the extra delay is giving people a chance to protect their computers before it wakes up...


The admin formerly known as Dr. Cossack.

Looking for me elsewhere? Maybe look at my Fediverse account for some more-or-less random postings! If you're a gamer, check out my Osmium profile. I'm building that tool!

TopHat
Hats n' spirals
Inactive
2417 posts
Caprice
Caprice
Become Dr. Cossack's waifu
Acquired on 20 April 2012
Rin Tezuka
Rin Tezuka
Acquired on 1 April 2012
Engineer
Engineer
Acquired on 1 April 2012
Spy
Spy
Acquired on 1 April 2012
Soldier
Soldier
Acquired on 1 April 2012

... and 22 more
Quote

Well...just updated all mah windows software and downloaded the patch.

I also performed the scan, and it found nothing.

Still not gonna risk turning on the computer that day, however.

Samsara
Superstar!
Offline
4039 posts
Quote

You know the simplest solution. Change the system date :P


Staff Backer Doctacosa
Admin
SciLab Official
Benevolent Dictator
Offline
6437 posts
Zenny
Zenny
Unlock all of the main forum features!
Acquired on 1 April 2014
Princess Celestia
Princess Celestia
Got all items in the AFD2012 event!
Acquired on 1 April 2012
Squid beaker
Squid beaker
Earned all 150 original CL achievements
Acquired on 17 January 2016
Unity.EXE emblem
Unity.EXE emblem
Defeat Bass.EXE in the AFD2013 event!
Acquired on 1 April 2013
Lilly Satou
Lilly Satou
Acquired on 1 April 2012

... and 25 more
Quote

Which works, unless the worm checks on an external time source...

I'd be surprised if this was the case, but you never know!


The admin formerly known as Dr. Cossack.

Looking for me elsewhere? Maybe look at my Fediverse account for some more-or-less random postings! If you're a gamer, check out my Osmium profile. I'm building that tool!

Sakura
Aqua-cadet
Inactive
1027 posts
Quote

Is this worm actually real? I highly doubted it but I can't get it, so does anyone know for sure?



Staff Backer Doctacosa
Admin
SciLab Official
Benevolent Dictator
Offline
6437 posts
Zenny
Zenny
Unlock all of the main forum features!
Acquired on 1 April 2014
Princess Celestia
Princess Celestia
Got all items in the AFD2012 event!
Acquired on 1 April 2012
Squid beaker
Squid beaker
Earned all 150 original CL achievements
Acquired on 17 January 2016
Unity.EXE emblem
Unity.EXE emblem
Defeat Bass.EXE in the AFD2013 event!
Acquired on 1 April 2013
Lilly Satou
Lilly Satou
Acquired on 1 April 2012

... and 25 more
Quote

Yes, it's very much a real thing, although it hasn't had a huge impact... yet. While it didn't trigger itself on April 1st as it was expected, some stuff did happen a week later. It's able to evolve, too, so the worse might still be coming our way.


The admin formerly known as Dr. Cossack.

Looking for me elsewhere? Maybe look at my Fediverse account for some more-or-less random postings! If you're a gamer, check out my Osmium profile. I'm building that tool!