Mike Harvey, Technology Correspondent
Attend a special evening hosted by Mike Atherton
The Conficker virus, which has infected millions of computers around the world, is finally activating itself in a bid to become a money-making machine for cybercriminals.
Infected machines have started to update themselves and download a fake anti-virus program aimed at tricking users into paying out for useless security software, security researchers said.
The virus may also be destined to be used by its cybercriminal creators to send millions of spam emails and steal passwords from infected computers by creating a "botnet" of "zombie" machines.
Ivan Macalintal, a Trend Micro advanced threats researcher, said Conficker began showing activity on Tuesday, nearly a week after the expected April 1 activation date that had computer security experts on alert around the world.
Infected machines were contacting each other to download new malicious software, he said.
"As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update," Macalintal wrote in a post on the TrendLabs Malware blog. "The Conficker/Downad P2P communications is now running in full swing!"
Other researchers at Kaspersky Labs found that Conficker was downloading a fake $49.95 security scanner called Spyware Protect 2009, which may mean millions of Conficker-infected machines will start getting pop-up messages advertising the product.
The latest version of Conficker is also downloading another, separate worm called Waledac onto the infected systems. Waledac is a known botnet linked to data theft and email spam campaigns.
Paul Ferguson at internet security company Trend Micro noted: "Having followed the activities of Eastern European online cyber crime for several years, there is one thing we are certain about — these criminals are motivated by one thing: money.
"How was Downad/Conficker helping them meet their goals? It wasn’t. A very large botnet of compromised computers doesn’t make money if it justs 'sits there' doing nothing. So now we see that the Downad/Conficker botnet has awakened, and perhaps their desire to monetising their efforts is becoming more clear."
Waledac usually spreads via a malicious web link or an e-mail, typically a fake greeting card. Once it infects a numer of machines they can be remotedly controlled to send scam emails advertising medical products or phishing messages.
The Conficker virus started spreading late last year. At first it was a relatively simple worm but its creators issued updates turning it into a more sophisticated and resilient virus that has found new ways to spread. It has also gained the ability to shut down a computer's defences
Conficker infects machines by exploiting a weakness in Windows, the software that runs on most computers. At its peak it had compromised about 12 million PCs, although that may have fallen to about two million thanks to new security measures.
Once the worm is on a computer, that PC becomes part of a “botnet” – a network of computers that can be controlled by the virus's creator.
In the past year the virus has spread to computers in schools, hospitals and government departments. It has got into the defence forces of Britain, Germany and France, grounding the French Navy's fighter jets for a time.
A task force assembled by Microsoft has been working to stamp out the worm and the company has placed a bounty of $250,000 on the heads of those responsible for the threat.
The worm, a self-replicating program, takes advantage of networks or computers that have not kept up to date with Windows security patches. Microsoft has modified its free Malicious Software Removal Tool to detect and get rid of Conficker.
Among the ways one can tell if their machine is infected is that the worm will block efforts to connect with websites of security firms such as Trend Micro or Symantec where there are online tools for removing the virus.
Industry sectors news at a glance. Interactive heatmap, video and podcast
Everything the Business Traveller needs to know to make a better trip
Get ready for the winter sports season, with our resort guides and snow reports
We are backing British business, what is the confidence of the nation and what businesses are succeeding?
Growing demand for energy, oil that is harder to reach and the rise of carbon dioxide emissions. We examine the energy challenge
With rail travel in Europe on the rise, we review the benefits of travelling by train
In this special section we explore new food trends to help improve your dinner party and impress guests
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
1998
£47,955
12 months for the price of 11 and a 5% discount.
Offer ends 31/11/09
Check your free Experian credit report before applying
Car Insurance
£353 per day
Phonepay Plus
London
PwC’s Consulting practice helps businesses of all shapes and sizes work smarter and grow faster
PwC
£37,000
Department for Culture, Media and Sport
London
Currently £36,285
Department for Culture, Media and Sport
London
Moments from Battersea Park.
For sale with Winkworth
Find out about shared ownership.
See your free Experian credit report beforehand
Accommodation, flights, tickets to the race and a KL city tour for only £999pp
PremierHolidays.co.uk
For your ultimate tailor-made ski holiday, click here
Get covered on your travels with a superb range of policies at great prices. Visit InsureandGo.com
World Class Golf, Spa and preferential Beach Club. Private estate overlooking West Coast
Villas from £275 per night inclusive of Golf
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.