Stay Smart Online Stay Smart Online

Update on Microsoft Windows Worm - Conficker/Downadup - SSO-AD2009-009

26 March 2009

Software and platforms affected

The following software is affected

Microsoft Windows (all versions)

for the following operating system platforms:

Windows 2000
Windows XP
Windows Vista
Windows Server 2003
Windows Server 2008

What is the problem?

Media reports are circulating which indicate malicious activity is expected to occur on 1st April 2009 by computers already infected with a new variant of malicious software called Conficker C. It is known that many computers in Australia are already infected with this malware. However, if you have been diligent in keeping your Microsoft Windows software up to date at all times, then it is unlikely your computer would be infected with this malicious program.

The main way computers are infected by this malicious software is through a security bug in Microsoft Windows which criminals can often find and exploit when the computer is connected to the Internet.

Infection by this worm could result in a number of symptoms, such as:

User accounts may unable to log in
Windows update may be disabled
Common anti-virus products may be disabled
Access to many security-related websites may not work, including, but not limited to: Microsoft, Symantec, Sophos, McAfee and Trend Micro.

Failure to remove this malicious software could mean that your personal information, including passwords, could be stolen and/or your computer could be used by criminals in other ways including to send spam.

What we recommend you do

Because it is difficult to tell if your computer is infected or not, we recommend you download and use Microsoft's Malicious Software Removal Tool which will remove the Conficker malware if it is on your computer:

 http://www.microsoft.com/security/malwareremove/default.mspx

Note that this tool is not a replacement for installing and using anti-virus software. To help protect your computer you should use anti-virus software and keep it updated.

Where you can find more information

The following link provides more information about the bugs and the software platforms affected:

http://www.microsoft.com/security/portal/Entry.aspx?name=Win32%2fConficker
http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.C
http://www.ssoalertservice.net.au/view/5fdcb8307b4e1a140896f670f7595360

Disclaimer

This Advisory has been prepared by AusCERT for the Department of Broadband, Communications and the Digital Economy.

The information is intended for used by home users and small to medium sized businesses and is general information only and not intended as advice and was accurate and up to date at the time of publishing. The material and information in this Advisory is not adapted to any particular person's circumstances and therefore cannot be relied upon to be of assistance in any particular case. In any important matter, you should seek professional advice relevant to your own circumstances.

The Commonwealth, AusCERT, and all other persons associated with this Advisory accept no responsibility or liability for information either included or referred to in the Advisory. No responsibility or liability is accepted for any damage, loss or expense incurred as a result of the information contained in the Advisory, whether by way of negligence or otherwise.

The listing of a person or organisation in any part of this site or Advisory does not imply any form of endorsement by the Commonwealth of the products or services provided by that person or organisation. Similarly, links to other web sites have been inserted for your convenience and do not constitute endorsement of material at those sites, or any associated organisation, product or service.

Please note that material in this Advisory, as the case may be, includes views or recommendations of third parties, which do not necessarily reflect the views of the Commonwealth, or indicate its commitment to particular course of action. Material on this site or in this Advisory may also include information provided by third parties. The Commonwealth cannot verify the accuracy of information that has been provided by third parties.

 

 

Back to top