Security Update for Conficker
Mar 31st, 2009 by Janie Palacios
Colleagues,
In order to protect the University computers from an exploit that takes advantage of the autorun feature of the Windows operating system, the autorun feature will be disabled for all Windows devices. This modification will affect all computers that are joined to the UTPA domain. The computers that are not joined to the domain but have management software will be targeted with a script to disable the setting.
Why are we doing this? DIR is highly recommending that all state agencies prepare for this outbreak on April 1st . The Conficker Trojan, (aka Downup, Downadup and Kido) will begin to make its appearance across the internet.
When will this be done? Approximately 12:00 PM today the change will be made on all computers in the UTPA domain to disable the autorun feature.
What about those machines that are not managed by the Division of Information Technology? You will need to ensure all patches have been applied and your computer restarted. For more information, see the below links:
Microsoft Malicious Software Removal Tool
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en
Microsoft Security Bulletin MS08-067
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
Should I be worried about my home computer? Yes, you will also need to ensure all patches have been applied on your home computers. These computers will also need to be restarted prior to 11:59pm today. Note: Information Technology cannot assist with your home computers or problems you may have with your home computers. It is a best practice to ensure all computer equipment is updated with the latest security updates and has an anti-virus application installed, that is updated.
How will this affect me? Anytime a USB device or CD is attached to a pc, it will no longer automatically begin to run. You will need to follow the following steps:
1. Go to My Computer
2. Click on the device letter is associated with the device
3. Proceed with the desired action
Important Note: Please restart your computer after 12:30pm today or at your earliest convenience. If you do not restart your pc before 11:59 pm today, your computer and your USB devices will potentially be at risk.
If you have any questions regarding the information listed above, please call the Computer Support Desk at ext 2020 or 956.381.2020.
Beverly Jones CIA, CISA
Interim Chief Information Security Officer
