HP ships USB sticks with malware included

update HP has released a batch of USB keys for numerous Proliant server models which contain malware that could allow an attacker to take over an infected system.

The worms contained on the 256KB and 1GB USB drives have been identified as W32.Fakerecy and W32.SillyFDC. The worms spread by copying themselves to removable or mapped drives and affect systems running Windows 98, Windows 95, Windows XP, Windows Me, Windows NT and Windows 2000, according to AusCERT.

HP's Software Security Response Team issued a warning to AusCERT this week after discovering the worms on the USB drives and have also provided a list of affected servers to the security response organisation.

Want to know more?

For all the latest news, analysis and opinion on security, click here

To find out whether a drive is infected, HP recommends inserting it into a system with up-to-date antivirus software. Systems with up-to-date antivirus should be protected from the threat, according to HP.

John Bambenek, a researcher at the security organisation Sans Internet Storm Center, has said that because the infected USBs only affect Proliant servers, a targeted attack cannot be ruled out.

However, the threat risk from the worms is considered to be low. "This is probably not going to escalate into a widepread epidemic," Nishad Herath, senior research scientist at McAfee Avert Labs, told ZDNet.com.au. "But I would most definitely urge users to perform a virus scan of any media — including any new blank drives — you receive from vendors prior to installing/using them as slip-ups like this have been known to happen in the past."

HP claims the worm-infected USBs will have only affected a small number of customers.

"HP takes all quality issues very seriously. Because the keys involved are used to install optional floppy-disk drives, this only affects the USB Floppy Drive Key kit which is a very low volume option and impacts a very small percentage of our ProLiant customer base. We've determined root cause and are fully confident that we have resolved this event. To date, no customers have reported this issue," a spokesperson for HP told ZDNet.com.au.

HP has provided an advisory page for customers with affected USB keys.

Advertisement

Talkback 1 comments

  1. HP Wormalot USB Mem Sticks Nick -- 09/04/08

    Yeah Inserting a possibly infected $15 USB stick in to a working computer is a good idea!! "why dont you test it in that domain controller over there!" :-) i cant believe they would recommend that, how about send it back or bin it :-) hmm


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jude Willis Why eBay tried to screw Aussie users
    Now that the bizarre ruckus over eBay's proposed PayPal monopoly appears totalled, it seems a good time to ponder why eBay chose Australia to risk its reputation on such a massively unpopular scheme.
  • Array The more things change…
    With all the excitement over the iPhone, few people have noticed that 1 July was the 11th anniversary of the deregulation of Australia's telecommunications market.
  • Array I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • More blogs »

Tags

Back to top

Featured