Conficker goes B++
Malware writers have created a new version of the Conficker worm that no longer needs to phone home to download its malware package.
Dubbed Conficker B++, the new strain opens a backdoor on the infected machine allowing hackers to push out updates directly to the worm, without it needing to contact a remote server first.
Or in the words of Microsoft's advisory: "We've discovered that the new variant no longer patches netapi32.dll against all attempts to exploit it. Instead, it now checks for a specific
pattern in the incoming shellcode and for a URL to an updated payload."