Newsletter Archives

  • Conficker waking up?

    A bunch of coincidences.

    At this moment, the Conficker Working Group web site is down.

    There are stories popping up all over that Conficker is starting to update – to morph – using P2P technology, not the 50,000 web sites originally thought to be the most likely source.

    If you want to follow along, avoid the senational stuff being published and keep an eye on the definitive story with the SANS Internet Storm Center.

    By the way, if you’re Googling to find info about removing Conficker, don’t believe everything you see, OK? Ryan Naraine at ZDNet reports that many of the Conficker-related web domain names have been taken over by cretins selling “scareware” antivirus programs.

    UPDATE: Looks like everything is back to normal with the Working Group site. SANS hasn’t raised any red flags. There’s even some doubt as to the nature of the P2P update. Conficker remains a huge threat – reasonable estimates of the number of infected Windows XP machines ranges from 1 million to 15 million – and everybody should check their machines for infection. But at this point the sky isn’t falling.