With Conficker issue not yet over , a replica of it is out in the “market” . Recently reported by Microsoft as a replica of Downadup, the worm is detected to be Win32/Neeris.gen!C. Microsoft calls it a “copycat” of downadup.
This latest variant of Neeris , which has been in existence since 2005 , seems to mimick all of Conficker’s spreading techniques, including the exploitation of MS08-067 and the AutoRun spreading tactic . The worm author has however created it to be an easily spotted malware with extensions like .exe or .scr , extensions that could easily be doubted by an average Internet user.
These worms are now rapidly spreading through Internet Messengers like MSN !
MS malware protection center report on Neeris could be found here .