HP ships USB sticks with malware

HP ships USB sticks with malware
Related Stories
The next generation of security threats
December 5, 2007
Infamous Russian malware gang vanishes
November 9, 2007
F-Secure: Low threat from mobile malware
September 27, 2007
Related Blogs
USB flash drives need a condom

March 15, 2008
Hewlett-Packard has released a batch of USB keys for numerous Proliant server models which contain malware that could allow an attacker to take over an infected system.

The worms contained on the 256KB and 1GB USB drives have been identified as W32.Fakerecy and W32.SillyFDC. The worms spread by copying themselves to removable or mapped drives and affect systems running Windows 98, Windows 95, Windows XP, Windows Me, Windows NT and Windows 2000, according to AusCERT.

HP's Software Security Response Team issued a warning to AusCERT this week after discovering the worms on the USB drives and has also provided a list of affected servers to the security response organization.

To find out whether a drive is infected, HP recommends inserting it into a system with up-to-date antivirus software. Systems with up-to-date antivirus should be protected from the threat, according to HP.

John Bambenek, a researcher at the security organization Sans Internet Storm Center, has said that because the infected USBs only affect Proliant servers, a targeted attack cannot be ruled out.

However, the threat risk from the worms is considered to be low. "This is probably not going to escalate into a widepread epidemic," Nishad Herath, senior research scientist at McAfee Avert Labs, told ZDNet.com.au. "But I would most definitely urge users to perform a virus scan of any media--including any new blank drives--you receive from vendors prior to installing/using them as slip-ups like this have been known to happen in the past."

HP claims the worm-infected USBs will have only affected a small number of customers.

"HP takes all quality issues very seriously. Because the keys involved are used to install optional floppy-disk drives, this only affects the USB Floppy Drive Key kit which is a very low volume option and impacts a very small percentage of our ProLiant customer base. We've determined root cause and are fully confident that we have resolved this event. To date, no customers have reported this issue," a spokesperson for HP told ZDNet.com.au.

HP has provided an advisory page for customers with affected USB keys.

To find out whether a drive is infected, HP recommends inserting it into a system with up-to-date antivirus software. Systems with up-to-date antivirus should be protected from the threat, according to HP.

John Bambenek, a researcher at the security organization Sans Internet Storm Center, has said that because the infected USBs only affect Proliant servers, a targeted attack cannot be ruled out.

Liam Tung of ZDNet Australia reported from Sydney.

More from News.com on this story's topics

Security threats

Create an email alert | RSS feed

Viruses and worms

Create an email alert | RSS feed

Consumer hardware

RSS feed

Hewlett-Packard

Create an email alert | RSS feed

See more CNET content tagged:
HP Compaq ProLiant, HP Compaq ProLiant Server, HP, malware, worm

11 comments (Page 1 of 1)
HP & Viruses
by timotaug April 9, 2008 3:10 PM PDT
I purchased an hp dv6500 laptop. all I installed was AVG and ran a scan of the system and 2 of the preloaded games were in fected. ! was a trojan the other a worm. ThE gRANNY GAME AND ONE OTHER. I called to inform them of the issue (which i corrected by deleting the infections) They said there was no way and to try an F-disk to resolve. mind you I just turned it on for the 1st time and installed AVG.
Reply to this comment View reply
Mac and linux users dont need to worry ever.
by dan356 April 10, 2008 8:53 PM PDT
Yeah yet another advantage of being a mac user. plus im also a linux user. I just dual boot. Hmmm, maybe this is a scare from hp and microsoft to go make people get really expensive anti virus protection because the creators of windows have no skills in making a decent well protected system. The only advantage to windows is gaming. Which if your into next gen gaming chances are you have a ps3 or 360 like i do. So I'm set no need to buy a windows comp for gaming. I think Apple should make their OS multiplatform. It would kill Microsoft in a year. In fact, its been really foolish of Apple to allow microsoft to get really far ahead in the Comp bussiness. But Microsoft is falling really fast in the market. People are just pissed from vista. Yeah if Apple ever allows their OS to be released on Pcs say goodbye to Microsoft. Also, to the people that say the only reason Windows has so many viruses is because everyone uses it. They are dead wrong.... The reason is microsoft only thinks about nerdy bussiness men and gaming. Never about security or anything that a normal web browser would care about. They only upgrade microsoft office, thats about it. It was pretty funny when microsoft said"windows vista is top of the line security" LOL! Now it has at least 500 to 800 viruses. Not to mention loads of spyware.
Reply to this comment View all 3 replies
The more concerning issue...
by dwinks April 11, 2008 3:02 PM PDT
I think the more concerning issue here is that HP is shipping thumb drives with only 256KB of space. What exactly could someone do with that little space. I think a completely blank office document is larger than that now, let alone one with a few pages of text and graphics. On the other hand, I have to give kudos to the virus writers for making such a compact and efficient virus that it can fit into just 256KB of space.
Reply to this comment
Powered by Jive Software
advertisement
Click Here
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.
Today's Top Stories
Flaw turns Gmail into spamming machine
Nvidia CEO denies buyout of Via
Fisker Auto flashes look at sporty electric sedan
FBI probe nets fake Chinese networking parts
Weekend QuickCast
Most Popular Stories
Google to launch Friend Connect for the social Web
FBI probe nets counterfeit Chinese networking parts
Why Intel's betting its chips on 4G
A modest proposal to fix Dell's customer service
Did you get infected? Virus runs amok amid JavaOne
Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

Markets

Market news, charts, SEC filings, and more

Related quotes

Hewlett-Packard (0.14%) 0.07 49.13
Dow Jones Industrials (-0.94%) -120.90 12,745.88
S&P 500 (-0.67%) -9.40 1,388.28
NASDAQ (-0.23%) -5.72 2,445.52
CNET TECH (-0.64%) -11.13 1,724.28
  Symbol Lookup



advertisement
Click Here
On CHOW: 10 perfect grilled cheese sandwiches
Advanced
search
Advanced
search
Visit other CNET Networks sites: