Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Storm worm seems to be fading away
Search Topic:
Uniqs:
435
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Anti-DNS pinning & DNS-rebinding attacks! »
« Configuring Zone Alarm to allow RDC  
AuthorAll Replies

daveinpoway
Premium
join:2006-07-03
Poway, CA
Storm worm seems to be fading away

Good news! Read it here: »www.pcworld.com/article/id,13872···l_dnxnws


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

OK so what I'm interested in here is why is this fading away, what are the causes for its growth and subsequent shrinkage? Was the growth due to slow AV detection, delays in signature distribution, masses of unprotected systems, or what? Whatever it those reasons are they apparently are being fixed as the number of infected systems is dropping.

As far as the reduction I found this statement to be a bit frightening:

Then on September 11, Microsoft added Storm detection (Microsoft's name for Storm's components is Win32/Nuwar) into its Malicious Software Removal tool, which ships with every Windows system. Overnight, Storm infections dropped by another 20 percent.

This implies that 20% (aprox) of the infected systems have no virus protection and are dependent on Microsoft's Malware removal tool for their protection. What about any infected systems after Microsoft updated the Malware removal tool, as that means that they don't have updates enabled or otherwise didn't checked for or apply updates from Microsoft which is scary in its own right.

Once again patching technology is easy, patching people isn't.

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool


SnowyOne
Premium
join:2003-04-05
Kailua, HI
That all being true then maybe Microsoft via it's Malicious Software Removal tool ought to do a check for an active AV on the installed machine & display a nag screen to install one when one isn't found.

mysec
Premium
join:2005-11-29

reply to daveinpoway
said by daveinpoway See Profile :

Good news! Read it here: »www.pcworld.com/article/id,13872···l_dnxnws
quote:
despite the intense publicity that the network of infected computers has received, it's actually been shrinking steadily and is presently a shadow of its former self.

For a different take on that:

Security Bites Podcast: Storm's brewing on the Internet
»www.news.com/Security-Bites-Podc···ubj=news

quote:
SecureWorks, found this week that the Storm worm's botnet is subdividing, suggesting that whoever controls the Storm worm botnet might be planning to sell off parts of it others.

Other Storm activities:

'Storm worm' exploits YouTube
»www.news.com/Storm-worm-exploits···ubj=news
_____________________________________________

-rich

daveinpoway
Premium
join:2006-07-03
Poway, CA

reply to SnowyOne
XP has a Security Center that displays a warning if it detects things like your AV definitions being out of date, firewall turned off and so forth; I can't recall for sure, but I believe this feature was added in SP 2. Obviously, there will be clueless folks out there who are running older, unsupported versions of Windows or who ignore the security warnings.
Forums » Up and Running » Security » SecurityAnti-DNS pinning & DNS-rebinding attacks! »
« Configuring Zone Alarm to allow RDC  


Wednesday, 02-Dec 13:18:49 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [159] Comcast Releasing Promised Usage Meter
· [74] Latest Consumer Reports Survey Not Kind To AT&T
· [69] Baltimore To Ban Lazy Cable Installs
· [60] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [49] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [36] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
Most people now reading
· MS admits Windows Updates principally created to annoy [Security]
· LFM Overkill [World of Warcraft]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· So I found a gold mine... [World of Warcraft]
· UBB round 2 at the CRTC [Canadian Broadband]
· Data Usage Meter Launched [Comcast HSI]
· [Newsgroups] Newzleech down? [Filesharing Software]
· cleaning LCD [General Questions]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]