PDA

View Full Version : [all variants] Downadup



RealG187
February 19th, 2009, 03:00 AM
I have heard of a virus called Downadup and usually when I hear about a viurs I don't care because there are always viruses and I am not dumb enough to open a virus infected file.

However for closure, Ubuntu is immune to this virus right? I run a VM with Windows, is that a problem, will only the VM be infected if something happens (in which case I delete it and restore the backup)

N4zgu1
February 19th, 2009, 03:16 AM
I think that your virtual machine can be infected, but it wont harm your ubuntu

lone_wolfII
February 19th, 2009, 03:53 AM
_Currently_ downadup doesn't actually do much other than update itself and check to see if there's any new instructions on some remote server.
For now you should be safe as long as Windows is kept up to date.

XP is the most vulnerable to this virus. When you plug in a USB drive, make sure to open it normally through My Computer, rather than in the dialog box that comes up.

RealG187
February 19th, 2009, 09:10 PM
Could they try to find that server and resolve it's IP to track down the creater?

unoodles
February 19th, 2009, 10:39 PM
Could they try to find that server and resolve it's IP to track down the creater?

No.

It accesses randomly created domain.

http://www.f-secure.com/weblog/archives/00001582.html

RealG187
February 20th, 2009, 03:00 AM
I don't get how that can be possible.

What happens if I goto one of the domains in that list?

UPDATE: Here are some links with info I found a while back (wanting to remove the shortcuts off my hard drive) but I don't wanna bump this so I am editing:

http://www.guardian.co.uk/technology/blog/2009/jan/25/downadup-windows-worm
http://www.symantec.com/security_response/writeup.jsp?docid=2008-112203-2408-99