
On April 1, the Conficker worm may launch a new attack, warns Compulenta .
Security experts warn that the Conficker worm will receive some kind of update on April 1st. What exactly and what will happen after this is not reported. Experts believe that the malware can be used to organize DDoS attacks, as well as to carry out mass mailings of spam or infected letters.
Microsoft, with the support of a number of organizations, has already launched a campaign to combat the worm, which includes blocking domain names that can be used by the parasite program. In turn, Symantec offers a utility to remove Conficker.
Conficker was discovered in November last year, but its activity peaked in early January: in a matter of days, the worm infected about ten million computers around the world. The malware, which can spread in a variety of ways, including through removable drives, allows attackers to remotely control infected computers.
According to Microsoft experts, the virus enters the system through the Windows file "services.exe", becoming part of its code.
Once in Windows, the virus assigns itself the extension ".dll" and a name consisting of 5-8 letters, for example, "piftoc.dll".
The activated virus then creates an HTTP server, overloads the entire system, making it very difficult to recover, and begins downloading files from hacker sites. Infection can also occur through USB devices? for example, flash key fobs or MP3 players.