![]() |
Conflictor C worm WARNING Conficker.C Worm - Major Attack targeted to start on April Fools Day, Please ensure all Servers/PCs are patched I got this from another forum and give the credit for this warning to them. Conficker.C Worm - Major Attack targeted to start on April Fools Day - Calendar Of Updates harrywaldron Microsoft MVP - Security ***** post Mar 20 2009, 04:14 PM MSMVP The Conficker worm is one of the most dangerous malware threats in years, especially for corporate users. A new "C" variant has been developed that's even more potent and stealthier than the two prior variants. It's imperative that Microsoft's MS08-067 patch be applied to all servers and workstations, while the worm is currently dormant. If it establishes a foothold anywhere in the network, it can even spread to systems that are patched with the MS08-067, if they are insecure in other areas, (i.e., it uses multiple attack methods). Please take precautions now, as this one will be even more difficult than "B" was to clean. Conficker.C Worm - Major Attack targeted for April Fools Day http://techfragments.com/news/629/So...to_Spread.html http://arstechnica.com/security/news...activation.ars http://www.maximumpc.com/article/new...pril_fools_day Latest Conficker worm gets nastier | Security - CNET News http://www.ca.com/us/securityadvisor....aspx?id=77976 QUOTE: Just when you might have thought it was safe to start using USB flash drives at work again, the third, and by all accounts, most fiendish version of the Conficker worm that's infected millions of PCs already is set to attack on April 1st, Ars Technica reports. Conficker.C's designed to hide itself even more thoroughly than its older siblings Conficker.A and Conficker.B, using tricks such as: • Inserting itself into as many as five Windows-related folders such as System, Movie Maker, Internet Explorer, and others (under a random name, of course) • Creating access control entries and locking the file(s) • Registers dummy services using a "one (name) from column A, one from column B, and two from column C" method To find out what happens when Conficker.C strikes, join us after the jump. Conficker.C's payload makes it harder than ever to recover from being infected: • Deactivates Windows Security Center notifications • Prevents restart in Safe Mode • Prevents Windows Defender from running at system startup • Deletes all system restore points • Disables various error-reporting and security services • Terminates over twenty security-related processes • Blocks DNS queries • Blocks access to security and antivirus websites • And, to top it all off, Conficker.C can choose from a list of 500 domains to contact out of a pool of 50,000 (way up from Conficker.B's 32 out of 250). Conficker.C - Detailed Evaluation by SRI An Analysis of Conficker C QUOTE: Variant C represents the third major revision of the Conficker malware family, which first appeared on the Internet on 20 November 2008. C distinguishes itself as a significant revision to Conficker B. In fact, we estimate that C leaves as little as 15% of the original B code base untouched protect.gif Below are some resources for information and cleaning tools for the Conficker worm: Conficker - Cleaning tips for corporate users http://msmvps.com/blogs/harrywaldron...ate-users.aspx Internet Storm Center - Conficker Resource Center SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc Microsoft Resources Virus alert about the Win32/Conficker.B worm http://www.microsoft.com/technet/sec.../ms08-067.mspx |
More information concerning the Conflictor worm! Bits from Bill: Conficker Judgement Day on April 1st Bits from Bill: Conficker Threat: Fact or Fiction Security Garden: Conficker Information for the Home Computer User |
Use this link to a free online scanner for the conflicter worm and associates. Remove Downadup - Removal tool for Downadup (known also as Conficker or Kido) This scanner is quick and fast but a browser add-on will need to be installed for the scanner to work. Those that are most likly to be infected are those from South America and Asia as that is where most un updated protection computers are located because of the use of pirated software. Microsoft does not support updates to these areas unless proven WGA. |
Here is a tools list that will help in the removal of conflicter. Understand that if you are infected or get infected, you may not be able to go directly to the web pages for these tools from the infected computer because of blocking or complete shut down of your computer internet service. It might be wise to down load these to your computer before so and run them for the protection! Conficker Work Group - ANY - RepairTools |
It was amazing how pervasive this was. We run a really tight ship at work, but it still wormed it's way in. I guess it just takes 1 person. |
All times are GMT -4. The time now is 05:21 AM. |
Copyright © 2005-2013 SysChat.com