09 April 2009
BitDefender researchers in the Antimalware Labs have identified a new variant of the Downadup / Conficker worm, able to circumvent detection and disinfection using the removal tools created for its previous versions.
In addition to blocking access to any website of antivirus vendors, as well as third-parties offering online scanning services or removal tools, the malicious binary has been updated to refuse users access to bdtools.net, BitDefender�s online repository for distributing disinfection and removal tools.
The updated disinfection tools are now available online at www.disinfecttools.com, a domain that is not currently blacklisted on the compromised machines.
�Since the new variant blocks bdtools.net the new recommended domain name is www.disinfecttools.com ( from our preliminary analysis this is not blocked by the malware ),� said Viorel Canja, head of the BitDefender Labs.
All the BitDefender 2009 products detect the worm as Win32.Worm.Downadup.Gen and stop its execution before it is able to perform changes on the system. In order to stay safe while surfing the Web, BitDefender recommends that you install a complete and up-to-date anti-malware software solution.
MEDIA RELATIONS
[email protected]INDUSTRY ANALYST RELATIONS
[email protected]INVESTOR RELATIONS
[email protected]