Gadgets & Tech

8° London Hi 11°C / Lo 6°C

Mystery virus hits 15 million PCs around the world

MoD and hospital computers among those infected by worm – the purpose of which is still unclear

By David Randall

A mysterious computer virus, the purpose of which has yet to become apparent, is spreading so fast that it has already infected more than 15 million computers around the world. Some six million machines have been contaminated in the past three days alone by the virus, a worm known as Downadup, Conficker or Kido.

More than 3,000 British organisations – including hospitals, the Ministry of Defence, councils, and what are described as "well-known firms" – have been hit. They and the hundreds of thousands of other victim organisations in countries such as the US, Russia, China and India are now bracing themselves for the virus to be triggered and do whatever malicious work it has been designed to do.

There remains the possibility that it has no function other than to demonstrate its originator's skill, but security experts think it unlikely a worm so sophisticated has no ulterior purpose. Tom Gaffney, technical manager of F-Secure, says this could be to capture confidential information, such as online account details and passwords, but it is more likely to be a "rootkit", which gives the virus designer administrative access – effectively, control over the computer and then, perhaps, its network. He said that Conficker is the worst outbreak of this type seen for six years, since the Slammer worm ran amok in 2003.

Conficker's origin is thought to be in Ukraine, mainly because the first thing the worm does is check if a computer has a Ukrainian-configured keyboard. If it does, the worm leaves it unmolested. Former Soviet states are where so-called "computer warfare" (the hacking of target networks, or hijacking of websites) has been most common. It was prevalent during last year's Georgia-Russia conflict.

So far, Conficker's impact has been irritating, but not disastrous. Low-level computers at the Ministry of Defence were affected, with some service staff left without access for two weeks. More than 800 computers within the Sheffield Teaching Hospitals Trust were affected. Other trusts, notably in South Wales, have been hit, and admin computers at Strathclyde fire service have also been affected. Mr Gaffney says his firm also has first-hand knowledge of infections at a few councils and "a number of well-known firms". F-Secure estimates 15 million computers are affected worldwide. Other security specialists favour a lower figure.

The worm, which does not affect Apple Macs, exploits a vulnerability in Windows, for which Microsoft provided a security patch as long ago as October. But the failure of many users to apply the patch (some say nearly one in three Windows users have ignored it), or to install anti-virus software, has allowed Conficker to proliferate. A common source of infection has been USB sticks and the application used to download their contents. There are also many users, especially non-corporate ones, unaware that their computer is affected, and therefore at risk of disastrous consequences if the virus is triggered. F-Secure, along with other security specialists, has a free online scan for the virus available on its website.

Additional research by Lara Richards

Post a Comment

View all comments that have been posted about this article.

Offensive or abusive comments will be removed and your IP logged and may be used to prevent further submission. In submitting a comment to the site, you agree to be bound by the Independent Minds Terms of Service.

Comments

when does this end
[info]sn0m wrote:
Sunday, 25 January 2009 at 08:24 am (UTC)
I think it is quite bad when hospitals are affected. I have had peaceful sleep since I adopted Linux to run my family pc.
Re: when does this end
[info]aberkopeep wrote:
Thursday, 29 January 2009 at 01:58 pm (UTC)
Indeed all ok with Linux for me.. Just a shame our public services don't embrace said operating system.
Mystery virus
[info]rednassak wrote:
Sunday, 25 January 2009 at 11:42 am (UTC)
"The worm, which does not affect Apple Macs, exploits a vulnerability in Windows..."

Wouldn't it have been simpler just to say that the worm only affects computers running Windows? As a (slightly smug) user of Linux for my own computers (heaven knows if our Windows based system in our office is okay), I would have welcomed confirmation that I have nothing fear.

Rednassak
hope
[info]vhawk1951 wrote:
Monday, 26 January 2009 at 01:55 am (UTC)
I just hope Kaspersky can deal with it
Conficker virus
[info]awheeler28 wrote:
Monday, 26 January 2009 at 09:30 pm (UTC)
My computer was infected yesterday. I had McAfee (which was recently installed) but it apparently still got in. I purchased a new anit-virus/anti-spyware (AVG) and that did the trick.
Re: Conficker virus
[info]vhawk1951 wrote:
Tuesday, 27 January 2009 at 02:47 pm (UTC)
why purchased? AVG is free
windows patch
[info]vhawk1951 wrote:
Tuesday, 27 January 2009 at 02:50 pm (UTC)
i find windows updates invariably screw up my computer- from where can i get said patch? - what is it called?

Article Archive

Day In a Page

Sun | Mon | Tue | Wed | Thu | Fri | Sat

Select date