News >> Browse Articles >> Microsoft
News >> Browse Articles >> Security
Microsoft Offers $250K Reward to Catch Worm Authors
Michael Barkoviak / DailyTech
February 13, 2009
'Conficker continues to infect a large number of computers while security experts try and figure out what to do.' -
Microsoft has created a new technology industry posse and a $250,000 reward for people who help turn over the creators of the Conficker worm.
The Conficker worm multiplied like wildfire, and spreads through a hole found in Microsoft Windows systems, though the vulnerability was patched in October. It also is able to disable anti-malware protection and will block an infected PC from visiting anti-malware vendors Web sites to receive updates.
Security experts are even more worried about the possibility the worm calls home every 24 hours to at least 250 servers each day for instructions or directed actions.
The Houston police department was forced to stop arresting people with traffic warrants because the worm spread its way through the police and city court's computer systems. Violent offenders were still arrested, but those with outstanding traffic warrants were simply issued citations instead of being arrested, Houston police officials said.
There also was a Conficker outbreak among French military computers, which led to several fighter planes being grounded until everything could be fixed.
Microsoft is working with the Internet Corporation for Assigned Names and Numbers (ICANN) and PC security experts while trying to identify the worm's creators. VeriSign, NeuStar, Public Internet Registry, Global Domains International, AOL, F-Secure, George Tech, and several other organizations have joined the fight to help capture who ever created the Internet worm.
"As part of Microsoft's ongoing security efforts, we constantly look for ways to use a diverse set of tools and develop methodologies to protect our customers," Microsoft Trustworthy Computing Group G.M. George Stathakopoulos said in a statement. "By combining our expertise with the broader community we can expand the boundaries of defense to better protect people worldwide."
Security company Symantec reported that more than 2.2 million IP addresses over the past five days have been infected with two different forms of the worm, three months after it first hit the Internet. To date, it's infected at least 10 million PCs since first being introduced into the wild.
© 2009, DailyTech

Stnightmare
6 months ago
46 comments
just think if you knew the creators of the worm do you think that 250k is really worth it do you realize how many passwords and bank info ect.... info they are getting i wouldnt take the 250k i would see what the creators had to offer first you know say they offered you 500k instead of 250k microsoft was offering what would you take?
warbman
9 months ago
46 comments
Microsoft CEO’s and Executives are the primary reason on why so many IT jobs are outsourced today. They have literally waged war on American’s by calling them incompetent, illiterate, uneducated, stupid, too costly, and unworthy of making a living wage.
Microsoft Executives are the ones that used their money to lead other American CEO’s in the massive export of American IT jobs. Microsoft is the primary leader in promoting foreign worker’s use of the Internet to subvert current Visa laws. Note that Microsoft has done nothing to stem the tide of foreign nationals that subvert visa laws by illegally working on American computers, and those computers are primarily us Microsoft’s OS. That is no accident. It is by design and intentional. These executives are fully aware and informed of the harm they have caused to the American public.
Microsoft has played a role in leading the way in the systematic destruction of high quality and high paid technical employment in the United States. Microsoft is in part responsible for systematically eroding the American standard of living.
The American dream used to be that an individual would get educated, work hard, move up the ranks, and be rewarded with a good home and solid retirement. Microsoft has led the way in waging war against that American dream by forging alliances with foreign enemies. Microsoft executives are fully informed and aware of the war that they have waged on the American public.
Now, suddenly, Microsoft Executives are complaining that the enemies they empowered have waged war against their OS. Those poor… poor….victims. Wha…..wha….wha…..
Microsoft deserves the attack. More will come and that will lead to more destabilization. Good. It is time the elites learn their lesson. They need to be made to fear destabilization.
The only way that this war will stop is when American Executives stop waging war on the public. All they need to do is be ethical, fair, pay reasonable wages, and give American’s hope. In the absence of such leadership, the virus and worm warfare will escalate. That is because every American worker now knows to arm themselves with a defensive weapon called a Virus/Worm builder. With that weapon American’s are now being empowered to defend themselves against the enemy.
Good job!
Azorot
9 months ago
2 comments
I have a used and use Linux and windows os and when in doubt use a terminal/command prompt. it's as simple none of this drive by download/ no spyware/ no adware/ nothing of the sort and best of all it all white on black. You cannot hide things from pure text. Now that being said I agree with TimBergkvist you are being over confident on windows and Linux. There are any reasons why one os is better than the other.
in my opinon this quote is good and this is what a viral coder is Social engineer
why? Because there is NO patch for human Stupidity.
no matter what if the end user clicks on the link you are done for thus the problem.
AndrewSoftwareGuy
9 months ago
48 comments
Mute point all computer systems and networks are vulunerable.Nothing in IT is as advanced as wet where enough said. I would not mind taking a shot at 250,000 grand.
TimBergkvist
9 months ago
12 comments
Lighten up. Sounds like you have way too much FAITH in microsoft and linux. Both (and others) are fallible. Protect yourself as best as you can. I have had my own issues with microsoft products over the years. Whenever I get fed up with 'em I try to switch over and in the end I can't fully do it successfully. For now, I use a MAC and boot into vista when I need it. The MAC is certainly a breath of fresh air. My wife (who isn't a superuser by any stretch) loves the MAC. I have no faith in it either, it is what it is. Stay civil, learn from your mistakes, be supportive.
sbarreros
9 months ago
6 comments
It is all about the facts, that's why even more than 20 years later of the conception of windo$ we are still talking about a virous that can do a lot of damage.
peejay006
9 months ago
14 comments
You half witt sbarreros OS Wars are so 90's... get a life man.
sbarreros
9 months ago
6 comments
I wonder why the millions of linux and unix servers that financial companies use to run their sensitive data are less broken into then windows servers?
I think you need to read up on why windows fundamentals are more vulnerable, way back when they gave up security and stability for ease of use, case and point, the famous blue screen, why do you think it is so easy for a single application to bring the entire operating system to its knees, and even render it unusable.
As I mentioned earlier, I don't think Linux is perfect, but it is definetly better then micro$ofts crap.
I defenetly enjoy the fact that I get no spyware, virus and all kind of other stuff that windows is affected by, I also enjoy the fact that after a year of using the same installation of my operating system it runs just as fast as the first day I installed it, how many windows can say that?
those are only one or two advantages, and I can go on for hours and hours, but I won't.
There is only one thing I use window$ for gaming, and even that is being taken over by linux.
By definition, linux is more secure and better constructed than windows, it is built on rules that were ment puiposefully for the internet and multi user, where as windows had to patch their system to add this funtionality half assed.
Klarken
9 months ago
38 comments
If someone wants to write a virus what do you target? An OS that has hundreds of millions of installations with users that know little about their computers or an OS that has a few million installations and the typical user is an IT type? Do you target an OS that has 96% of the personal financial applications in the world or one that has less than 1%?
Linux is not more secure folks, it is just a less desirable target for hackers.
sbarreros
9 months ago
6 comments
By its very nature windows is broken, its foundations is cracked. And as a building that is built on a cracked foundation, no matter how many patches and fixes you apply to it, it will not take away the fact that it is vulnerable to any small change.
Having said that, I think it is an outrage the kind of garbage Microsoft sells its customers and the kind of dirty player he is in the industry.
I think people better wise up and start using Linux or a safer alternative if they don't want to have al their sensitive data exposed because you happened to click on a link. I am not saying Linux is perfect, there is no such thing, but at least it is built on top of an architecture that is more secure and stable.
caprich
9 months ago
8 comments
More info on the Virus from the Microsoft Websites for those who wanna learn more about it:
http://support.microsoft.com/kb/962007
http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conf...
carb0n
9 months ago
4 comments
If your reading this by the way, You might be interested in some neat tricks. http://www.sharptricks.net Just some cool little web based trinkets.
carb0n
9 months ago
4 comments
I highly doubt this is a terrorist attack lmao! Ive seen people do it in their own home computers. All it takes is someone with too much time on their hands and a little bit of knowledge or someone who has motive to do so with knowledge (hence; "I'm angry at a certain organization because of such and such"). Sometimes creating a virus/worm or malware leads to a very good career with the federal government or a lucrative software company. I highly doubt terrorists would use such a semi-lethal worm cypher.
There is so much more damaging malware that can be used or created. A court house in Houston? 200+ servers? that's not bad, but Ive seen better. The reason Microsoft and other partners are offering $250k is because the worm is using a vulnerable port in the MS operating system, and they wish to find it to make the windows experience more secure to keep their promise and patch up windows, before their new operating system release in the next year or so. Not to mention all the other software vendors that must keep up with virus definitions. This is very commercial, not terrorists and such. There is money to be made. When they find the person that made this, they will probably be given the $250k and asked to work with MS and partners to make their software more secure. If they disagree of course they will be thrown in the federal prison system until the federal government decides to hire them in exchange for their "freedom". Just a fact, someone invents a device.. who knows better about it than the creator. There are people who do this for a living and they work for MS and others to find vulnerabilities.
Imagine you are a software vendor. Someone releases a worm that is quite a nu sense , but shows and proves that your software is useless against it. What is the smartest and most profitable thing to do in this case? 1. Find the person or group 2. Find the vulnerability and code & method 3. Hire this person/group to point out other vulnerabilities in your software
This person is of no use to them in prison. Plus they wont spend more than a night in prison anyways, the Government will swoop them right out to utilize them for "special" projects.
RonMoore
9 months ago
14 comments
Here is my thoughts o this. This very easly could be the work of one person, but he would have to be highly trained in MS programing. Thats why we start MS first. I read a few months ago that MS was closing several overseas factories. Witch means layoffs and rumors of the closing would have started back in the midle of last year. For some resone I find it hard to beleve that this atack was U.S based. I have to agree with some of you that we have made alot of enimies in the past few years(Bushes term) and that between a discrental MS layoff employee and a nation out level the playing feild could be the reson for the atack. The only way that I see this atack comeing from inside the U.S is a right wing antigov group, but i have know a few of these pepole and they are more violent than techy. As far as the 250k from MS cool. In this ression it could get the atention of someone that can help. As times get harder I would expect that the internet will be hit more and more, just do to the fack that we send sooo much info across the wire and so many will be losing money, homes, cars and ect. That a lone will increes hacker and virus activity.
No matter who it was they will be cought. I just wish that I had info on this jacka**.
colkraig46
9 months ago
34 comments
I think that is a federal offence shuting down acourt house more than a slap on the wrist.