We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
79,773 News Articles

Symantec spots new variant of Conficker worm

New Downadup version kills antivirus software

A third version of Conficker, also known as Downadup, has been identified by Symantec, which says the new variant gives infected machines more powerful instructions to disable anti-virus software and analysis tools, among other actions.

W32.Downadup.C is a modular component for machines currently infected with Downadup. This variant of Downadup is not attempting to self-replicate and appears to behave more like a Trojan than a worm, said Vincent Weafer, vice president of Symantec Security Response.
"Think of it as an updated module that's more aggressive, more robust in defending itself," Weafer said.

The W32 Downadup.C variant was discovered on Friday in a Symantec honeypot and is still under investigation. Symantec expects to identify additional capabilities shortly, said Weafer, who added that Symantec has not yet seen W32.Downadup.C in customer networks directly.

Earlier versions of Downadup did attempt to disable anti-virus software, but the third version represented in the Downadup.C module is designed mainly to provide more protective actions to infected Windows-based machines so they can better defend themselves from anti-virus software and other eradication methods.

"It's more aggressive, it has more services," said Weafer.

See more PC security advice

How to stop Conficker

Network World


IDG UK Sites

Samsung Galaxy Alpha vs iPhone 5S comparison review: Metal smartphones fight

IDG UK Sites

Gateway to your kingdom: why everybody should check and update their broadband router

IDG UK Sites

Netflix whips up 3D VR viewing room for Oculus Rift during company hack day

IDG UK Sites

Widespread 2011 MacBook Pro failures continue: Petition for fix surpasses 10,000 signatures