Content
W32/Conficker.worm.gen.a
- Type
- Virus
- SubType
- Generic Worm
- Discovery Date
- 01/06/2009
- Length
- various
- Minimum DAT
- 5485 (01/04/2009)
- Updated DAT
- 5657 (06/25/2009)
- Minimum Engine
- 5.2.00
- Description Added
- 01/06/2009
- Description Modified
- 01/13/2009 9:10 AM (PT)
Tab Navigation
Characteristics
When executed, the worm copies itself using a random name to the %Sysdir% folder. (Where %Sysdir% is the Windows system folder; e.g. C:\Windows\System32) New variants have been observed dropping copies of themselfs aslo into: Where [random] is a 4 to 8 long letters only random name. On NTFS filesystems the dropped files do have often modified access permissions. Access is completely removed on the file for all users and groups. This is done to make detection and cleaning more difficult. It modifies the following registry key to create a randomly-named service on the affected syetem: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\"ServiceDll" = "Path to worm" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\"ImagePath" = %SystemRoot%\system32\svchost.exe -k netsvcs Several variants do remove access to the above registry key by changing the key ACLs. This also in an attempt to make detection and removal of the serive key more difficult. The service name is generated dinamically by associating words from an hardcoded list: It will inject intelf into various running processes. Different variant have been observer injecting into one or more of: Attempts connections to one or more of the following websites to obtain the public ip address of the affected computer. Attempts to download a malware file from the remote website hxxp://trafficconverter.biz/[Removed]antispyware/[Removed].exe New variants are connecting to various other hosts. Starts a HTTP server on a random port on the infected machine to host a copy of the worm. Continuously scans the subnet of the infected host for vulnerable machines and executes the exploit. If the exploit is successful, the remote computer will then connect back to the http server and download a copy of the worm. The http connection is performed on a random port and the file transferred will have an extension of Later variants of w32/Conficker.worm do attempt to connect to remote hosts using the local credentials and a list of username retrieved from the target system and a long list of hardcoded passwords. In doing so it may lock down domain accounts where the policy is set to allow only a limited number of wrong passwords. On succesfully exploited remote systems the worm drops a copy of itself in the $sysdir% folder and creates a scheduled tasks to execute it. It may olso create a copy in the remote "Recycle Bin" folder and an Autorun.inf file. Using these techniques the worm may replicate on to non vulnerable systems or reinfect previously infected systems after they have been cleaned. The worm hooks system APIs to prevent access to security websites. A list of some of the locked domains is: Some security services may also be disabled by the infection.
Symptoms
Method of Infection
This worm exploits the MS08-067 Microsoft Windows Server Service vulnerability in order to propagate. Machines should be patched and rebooted to protect against this worm re-infecting the system after cleaning. It also spread by brute forcing remote systems password and installing scheduled tasks and/or autorun.inf files on the victim.
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
This detection is for a worm that exploits the MS08-067 vulnerability as the main vehicle of infection. It also uses other common technique for spreading as underlined in the Method of infeciton section. It also download and execute various files onto the affected system.
Aliases
- Worm:Win32/Conficker.A (Microsoft)
- Crypt.AVL (AVG)
- Mal/Conficker-A (Sophos)
- Trojan.Win32.Pakes.lxf (F-Secure)
- Trojan.Win32.Pakes.lxf (Kaspersky)
- W32.Downadup (Symantec)
- Worm:Win32/Conficker.B (Microsoft)
- WORM_DOWNAD.A (Trend Micro)
Characteristics
Characteristics -
When executed, the worm copies itself using a random name to the %Sysdir% folder. (Where %Sysdir% is the Windows system folder; e.g. C:\Windows\System32) New variants have been observed dropping copies of themselfs aslo into: Where [random] is a 4 to 8 long letters only random name. On NTFS filesystems the dropped files do have often modified access permissions. Access is completely removed on the file for all users and groups. This is done to make detection and cleaning more difficult. It modifies the following registry key to create a randomly-named service on the affected syetem: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\"ServiceDll" = "Path to worm" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\"ImagePath" = %SystemRoot%\system32\svchost.exe -k netsvcs Several variants do remove access to the above registry key by changing the key ACLs. This also in an attempt to make detection and removal of the serive key more difficult. The service name is generated dinamically by associating words from an hardcoded list: It will inject intelf into various running processes. Different variant have been observer injecting into one or more of: Attempts connections to one or more of the following websites to obtain the public ip address of the affected computer. Attempts to download a malware file from the remote website hxxp://trafficconverter.biz/[Removed]antispyware/[Removed].exe New variants are connecting to various other hosts. Starts a HTTP server on a random port on the infected machine to host a copy of the worm. Continuously scans the subnet of the infected host for vulnerable machines and executes the exploit. If the exploit is successful, the remote computer will then connect back to the http server and download a copy of the worm. The http connection is performed on a random port and the file transferred will have an extension of Later variants of w32/Conficker.worm do attempt to connect to remote hosts using the local credentials and a list of username retrieved from the target system and a long list of hardcoded passwords. In doing so it may lock down domain accounts where the policy is set to allow only a limited number of wrong passwords. On succesfully exploited remote systems the worm drops a copy of itself in the $sysdir% folder and creates a scheduled tasks to execute it. It may olso create a copy in the remote "Recycle Bin" folder and an Autorun.inf file. Using these techniques the worm may replicate on to non vulnerable systems or reinfect previously infected systems after they have been cleaned. The worm hooks system APIs to prevent access to security websites. A list of some of the locked domains is: Some security services may also be disabled by the infection.
Symptoms
Symptoms -
Method of Infection
Method of Infection -
This worm exploits the MS08-067 Microsoft Windows Server Service vulnerability in order to propagate. Machines should be patched and rebooted to protect against this worm re-infecting the system after cleaning. It also spread by brute forcing remote systems password and installing scheduled tasks and/or autorun.inf files on the victim.
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A