Home Conficker Worm Neeris Worm: A Copycat Conficker Worm Discovered

Neeris Worm: A Copycat Conficker Worm Discovered

Posted: April 6, 2009

Conficker infected millions of computers and now another threat called Neeirs Worm is copying the same infection strategies of Conficker.

A worm, which is now about 4 years old, called Neeris worm, is copying Conficker's attack strategies which could potentially infect millions of computers. Not much is known about the Neeris Worm, which dates back to May 2005. Neeris Worm is exploiting the same MS08-067 vulnerability that Microsoft patched back in October 2008 at the time of Conficker emerging into the wild.

Conficker used the MS08-067 vulnerability to infect computers and it was a very effective method as it was able to infect 12 million or more computers around the world and giving everyone a big scare especially from the Conficker.C variant. The Conficker.C variant proved to be not as effected as many feared before the date of April 1st which marked the day that it would start contacting its controllers.

In what other way is Neeris simular to Conficker Worm?

The Neeris Worm is now updated using the same methods of Conficker to spread such as using the autorun.inf file where it is able to worm its way onto and from the root directory of a USB drive or other USB storage based devices. Basically this process spreads the infection onto a system silently when it is connected to a computer that is not infected.

Because Neeirs worm, from the research of many security firms, has many of the same characteristics of Conficker, it is believed that the makers of Conficker and Neeirs have joined forces. Neeirs starting showing up on the radar screen again with the new infection methods as early as March 31st and into April 1st. Is this a coincidence that it coincides with the April 1st date that Conficker was supposed to start performing malicious actions?

To add to the mystery of Neeirs worm is the fact that it is not downloaded by any Conficker variant and no proof that it is actually related to Conficker.C's April 1 activation. Also, Neeris Worm, being 4 years old now, was never added or fingerprinted to be a parasite detected by Microsoft's Malicious Software Removal Tool. Why did Microsoft overlook this worm? Is it possible that the Neeirs worm is yet another scare tactic just like Conficker.C's and it will not causing any harm? This is very possible but it is still wise to apply the MS08-067 vulnerability patch to your system to prevent infection from the Neeirs worm and Conficker Worm variants.

Do you fear that we have not seen the last of Conficker Worm or its methods for infecting computers? Do you think that a worm such as Neeirs will emerge as a serious threat finishing what Conficker started?

Loading...