ESET Threat Blog

Archive for the 'Conficker' Category

by Aryeh Goretsky Distinguished Researcher
August 9, 2010 at 3:04 pm

ESET released its Global Threat Report for the month of September, 2009, identifying the top ten threats seen during the month by ESET's ThreatSense.Net™ cloud.  You can view the report here and, as always, the complete collection is available here in the Threat Trends section of our web site.  While the report identifies a number … Read More…

Comments
8

?>
by David Harley Senior Research Fellow
September 4, 2009 at 10:02 am

The Register has reported that it cost Ealing Council, in London (UK) some £500,000 in lost revenue and repairs after a "virus infection" in May. According to El Reg’s John Leyden, the virus in question was Conficker-D, though because of differences in Conficker variant naming, it’s difficult to say exactly which variant that would refer to. … Read More…

Comments
0

?>
by Randy Abrams
August 3, 2009 at 11:13 am

Potentially Abandoned Conficker Grows
According to an article at Internetnews.com http://www.internetnews.com/security/article.php/3832846 the authors of the Conficker botnet may have abandoned it, yet it continues to grow in numbers. The growth of the botnet is troubling because it is completely preventable and because it means the infected computers are vulnerable to other threats and that these users … Read More…

Comments
0

?>
by David Harley Senior Research Fellow
August 3, 2009 at 8:13 am

Our July ThreatSense.Net® report has been released today, and will eventually be available from the Threat Center page here. Most of the top ten entries are old friends: well, familiar names might be a better way of putting it. One of the disadvantages of having a scanner that makes heavy use of advanced heuristics is … Read More…

Comments
3

?>
by David Harley Senior Research Fellow
July 6, 2009 at 8:01 am

SC Magazine in the UK picked up on our Global Threat Report for June, based on statistics that derive from our ThreatSense.Net® threat-monitoring technology. Thanks, Dan: when you do as much writing as I do, it’s comforting to know that someone is reading it.
I thought, though, I’d develop some thoughts on a topic arising … Read More…

Comments
0

?>
by Randy Abrams
May 1, 2009 at 12:13 pm

As we do each month, ESET has released its monthly threat report. As you might expect, there were a lot of Conficker detections out there. There were also almost as many detections for autorun threats that are not Conficker. In other words, if you have disabled autorun, then you protect against a lot more than … Read More…

Comments
0

?>
by David Harley Senior Research Fellow
April 12, 2009 at 9:36 am

Larry Seltzer, one of the better commentators on malware issues, has picked up on the disparity between ESET’s naming of the latest variant and Symantec’s – they call it W32.Downadup.E. Richard Adhikari (who also seems to pretty clueful) also picked up on the naming issue when we exchanged emails a few days ago.
This issue kind … Read More…

Comments
2

?>
by David Harley Senior Research Fellow
April 10, 2009 at 3:06 pm

So now for a little more tech detail on Win32/Conficker.AQ (kindly supplied by Juraj Malcho at our labs in Europe – however, if I get anything wrong, that will almost  certainly be down to my faulty interpretation!)
The new variant has two main components. The server component is an .EXE that infects vulnerable PC’s in the … Read More…

Comments
0

?>
by David Harley Senior Research Fellow
April 9, 2009 at 9:04 am

If you just got here looking for my blog on Conficker and "blended hoaxes", I’m afraid I just pulled it (temporarily at least) in the light of new data that’s come in since last night: I don’t want to mislead anyone, as it seems that the new Conficker stuff is a lot more active and … Read More…

Comments
3

?>
by David Harley Senior Research Fellow
April 9, 2009 at 1:51 am

Talking of the C-worm ("Will no-one rid me of this troublesome malware?") I mentioned in a blog from a couple of days ago that Jose Nazario supplied some useful information on an issue I was checking into.
The issue concerned reports from a Russian news site of Distributed Denial of Service attacks on Russian sites: the … Read More…

Comments
0

?>
Share |
Subscribe by Email
To receive new posts automatically through email, enter your email address:

Delivered by FeedBurner

Blog Search
Archives

Switch to our mobile site