On GameFAQs: The top 10 natural laws ignored in games
BNET Business Network:
BNET
TechRepublic
ZDNet

By ,
Posted on ZDNet News: Apr 9, 2008 5:02:00 PM

Hewlett-Packard has released a batch of USB keys for numerous Proliant server models which contain malware that could allow an attacker to take over an infected system.

The worms contained on the 256KB and 1GB USB drives have been identified as W32.Fakerecy and W32.SillyFDC. The worms spread by copying themselves to removable or mapped drives and affect systems running Windows 98, Windows 95, Windows XP, Windows Me, Windows NT and Windows 2000, according to AusCERT.

HP's Software Security Response Team issued a warning to AusCERT this week after discovering the worms on the USB drives and has also provided a list of affected servers to the security response organization.

To find out whether a drive is infected, HP recommends inserting it into a system with up-to-date antivirus software. Systems with up-to-date antivirus should be protected from the threat, according to HP.

John Bambenek, a researcher at the security organization Sans Internet Storm Center, has said that because the infected USBs only affect Proliant servers, a targeted attack cannot be ruled out.

However, the threat risk from the worms is considered to be low. "This is probably not going to escalate into a widepread epidemic," Nishad Herath, senior research scientist at McAfee Avert Labs, told ZDNet.com.au. "But I would most definitely urge users to perform a virus scan of any media--including any new blank drives--you receive from vendors prior to installing/using them as slip-ups like this have been known to happen in the past."

HP claims the worm-infected USBs will have only affected a small number of customers.

"HP takes all quality issues very seriously. Because the keys involved are used to install optional floppy-disk drives, this only affects the USB Floppy Drive Key kit which is a very low volume option and impacts a very small percentage of our ProLiant customer base. We've determined root cause and are fully confident that we have resolved this event. To date, no customers have reported this issue," a spokesperson for HP told ZDNet.com.au.

HP has provided an advisory page for customers with affected USB keys.

To find out whether a drive is infected, HP recommends inserting it into a system with up-to-date antivirus software. Systems with up-to-date antivirus should be protected from the threat, according to HP.

John Bambenek, a researcher at the security organization Sans Internet Storm Center, has said that because the infected USBs only affect Proliant servers, a targeted attack cannot be ruled out.

Liam Tung of ZDNet Australia reported from Sydney.

  • Talkback
  • Most Recent of 13 Talkback(s)
File system vs. firmware infestation
pj_mouse scribbled: There's no need to recall a device that can be easily fixed by the consumer with a simple virus scan.

That assumes the infestation isn't in the USB stick's fir... (Read the rest)
Posted by: Raymond Danner Posted on: 06/05/08  (Edited: 06/05/2008 @ 01:13) You are currently: Logged In | Log out
Reminds me of the early days of computing CobraA1   | 04/09/08
I miss Hybris zmud   | 04/10/08
RE: HP ships USB sticks with malware pocketchalker@...   | 04/09/08
Difference between safety and security. ShadeTree   | 04/10/08
Recall? pj_mouse   | 04/10/08
YES RECALL - Have you tried to fix one of these??? acad2kman   | 05/09/08
File system vs. firmware infestation Raymond Danner   | 06/05/08
RE: HP ships USB sticks with malware dagresta@...   | 04/10/08
RE: HP ships USB sticks with malware gregry   | 04/10/08
RE: HP stuck with malware, China Phobia - stick with Linux sgdreamer   | 04/10/08
Story about Russian phishers...... bobd08   | 05/08/08
RE: HP ships USB sticks with malware DarbyOhara   | 04/11/08
RE: HP ships USB sticks with malware catseverywhere@...   | 06/05/08

What do you think?

advertisement
advertisement