Conficker Arrives

ArmageddonIs it time to buy those boxes of ammo and head for the hills? We’ll see.

This Wednesday, April 1st the Conficker worm will do something. No one knows what. But it has security experts up late. It is believed that at one point Conficker was on 6% of the world’s PCs. This has been reduced dramatically by the work of Microsoft in issuing special patches for the worm. But hundreds of thousands of PCs are still estimated to be infected.

Early this month, Symantec’s security researchers began noticing that the worm was changing in order to avoid steps to interrupt the worm’s links with its hacker controllers. The first versions of the worm generated a list of 250 possible domains each day that could be used to route instructions from hackers. The new edition uses a list of 50,000 URLs in order to overwhelm security researchers.

Typically hackers use large botnets of computers to commit distributed denial of service (DDOS) attacks against websites. The hackers will demand that large websites pay them in order to be spared.

If you are worried about your computers or those of people you love, you can read Microsoft’s alert and my earlier post on how to prevent and remove the virus.

New iPood?

I saw this new “iPOOd” trowel at a Virginia REI store. Like an actual iPod, it is lightweight and has very few buttons. Unlike an iPod, it is good for digging.

ipood

Down & Up Worm Worst Ever

Over the last few months, the “Down and Up” worm, also known as “Conficker” has infected an estimated 6% of all PCs worldwide. The concern is what the authors will now do with all these compromised systems. They could ask for credit card information as the bogus Antivirus 2009 does. They could use the computers to attack and demand money from websites through denial of service (DOS) attacks. No one knows yet what the intentions of the authors are.

It is considered the most professional and pernicious worm attack that researchers have yet seen. It effects all versions of Windows. As a worm, it does not require any user action for the computer to be compromised. The machine must just not be recently patched.

Download the Malicious Software Removal Tool (also available in Windows Updates) in order to protect your computer or to possibly get rid of the worm (most people who have it do not know). Then you can feel comfortable that your computer is owned by you and not by the bad guys.

Windows 7 Beta

Microsoft’s beta of Windows 7 was released a couple of days ago. Prior to that, it had been seen and reviewed extensively because it was on bittorrent (peer-to-peer) sites. There is speculation that Microsoft themselves leaked this build to the Internet to build interest. Given the poor consumer embrace of Windows Vista, it appears that Microsoft is using this update to ditch the term Vista.  Windows 7 does appear to be faster and better than Vista.

Back Story

After Vista’s so-so entry into the world, Microsoft revamped their development approach to Windows. A few years ago, Microsoft’s approach was to have a main development build of Windows. When it was time to make the desktop or server versions, they would fork the source code tree. This forked approach proved unwieldy for keeping track of all the code.

For Windows 7, the code is now componentized. This means that each part of the OS is worked on individually and managed in one spot. To make the desktop OS, you simply pull all the components needed together. For Windows Server, you do the same. Due to this streamlined approach, not only will Microsoft be able to come out with OSs in a timely manner, but updates will also be smaller and released more frequently.

Optimizations and Drivers

In the process of modularizing the OS, they also looked through the code to see what was used the most and worked on optimizing that code. So while the entire OS hasn’t been “optimized”, the stuff that matters is. I’m running Windows 7 on my Acer Aspire One, and it runs quite fast, faster than Vista or XP.

Since Microsoft wants Windows 7 to launch without a hitch, they’re not changing the driver model from Vista. So if your printer or scanner now (finally) works, then it’ll work in Windows 7 too. They are also putting pressure on hardware manufacturers to have signed/updated drivers.

What’s new in Windows 7?

The biggest difference you can see in Windows 7 is the new taskbar.

You aren’t forced to use the taskbar and you can go back to the old way if you want. This taskbar looks much like the dock in Apple’s Mac OS X, but it’s a little nicer. You can run a program more than once (can’t do that on a mac). But the best thing is Aero Peek.

I’ve been looking for something equivalent to OS X’s exposé for quite some time, and this is better. When you mouseover the program icon in the task bar, it brings up a thumbnail of every window that application has. When you move over the thumbnail, that window fades in while all other windows fade out. If you have a phone number or some quick info you need to view in another application, you can get to it without any mouse clicks.

Not Far Away

For a beta, Windows 7 is already very stable and is reportedly feature complete. This means that Microsoft can’t be far from releasing it, possibly by mid-2009. With the new Mac OS X Snow Leopard arriving around that time too, it should be a good year for operating system upgrades.

Malicious Software Removal Tool (MSRT)

Microsoft recently reported that their Malicious Software Removal Tool (MSRT), which was included in Windows Updates on December 9, 2008, has now removed over 400,000 copies of the nefarious “Antivirus 2009”.

An Arlington, VA client was recently infected by that Antivirus 2009 malware. It has been the most pernicious malware that I have seen recently, as most users can be tricked into installing it. Many fake sites exist that you might find during a normal web search. The sites appear to be a standard Windows Control Panel page which pretends to search for and find viruses. If you click “Ok” or “Remove All” you will be infected.

It will eventually take away all administrative rights from you and ask for your credit card to update and remove the viruses. Of course, it never removes anything, but instead gives your credit card info to the bad guys to use as they wish. Your computer is also a zombie ready to do whatever they ask of it.

The problem is that the dialog boxes and alerts look just like legitimate ones that might appear from Microsoft. See the fake Antivirus 2009 alert above.

I mentioned another variant of this malware called Antivirus XP 2008 in an earlier post.

While there are other tools you could use, Microsoft’s Malicious Software Removal Tool (MSRT) is a real solution that will remove and protect the computer from this Malware. It is available as a critical update from Microsoft.

It is not always apparent how to run Microsoft’s Malicious Software Removal Tool (MSRT). If you have it installed, you can just go to Start – Run and they type mrt