SysChat

SysChat (http://www.syschat.com/forum.php)
-   Security (http://www.syschat.com/tips-n-tricks/security/)
-   -   Conflictor C worm WARNING (http://www.syschat.com/conflictor-c-worm-warning-4424.html)

lurkswithin 03-22-2009 04:36 PM

Conflictor C worm WARNING
 
Conficker.C Worm - Major Attack targeted to start on April Fools Day, Please ensure all Servers/PCs are patched
I got this from another forum and give the credit for this warning to them.

Conficker.C Worm - Major Attack targeted to start on April Fools Day - Calendar Of Updates

harrywaldron
Microsoft MVP - Security
*****
post Mar 20 2009, 04:14 PM
MSMVP



The Conficker worm is one of the most dangerous malware threats in years, especially for corporate users. A new "C" variant has been developed that's even more potent and stealthier than the two prior variants. It's imperative that Microsoft's MS08-067 patch be applied to all servers and workstations, while the worm is currently dormant.

If it establishes a foothold anywhere in the network, it can even spread to systems that are patched with the MS08-067, if they are insecure in other areas, (i.e., it uses multiple attack methods).

Please take precautions now, as this one will be even more difficult than "B" was to clean.

Conficker.C Worm - Major Attack targeted for April Fools Day
http://techfragments.com/news/629/So...to_Spread.html
http://arstechnica.com/security/news...activation.ars
http://www.maximumpc.com/article/new...pril_fools_day
Latest Conficker worm gets nastier | Security - CNET News
http://www.ca.com/us/securityadvisor....aspx?id=77976

QUOTE: Just when you might have thought it was safe to start using USB flash drives at work again, the third, and by all accounts, most fiendish version of the Conficker worm that's infected millions of PCs already is set to attack on April 1st, Ars Technica reports. Conficker.C's designed to hide itself even more thoroughly than its older siblings Conficker.A and Conficker.B, using tricks such as:

• Inserting itself into as many as five Windows-related folders such as System, Movie Maker, Internet Explorer, and others (under a random name, of course)
• Creating access control entries and locking the file(s)
• Registers dummy services using a "one (name) from column A, one from column B, and two from column C" method
To find out what happens when Conficker.C strikes, join us after the jump.

Conficker.C's payload makes it harder than ever to recover from being infected:

• Deactivates Windows Security Center notifications
• Prevents restart in Safe Mode
• Prevents Windows Defender from running at system startup
• Deletes all system restore points
• Disables various error-reporting and security services
• Terminates over twenty security-related processes
• Blocks DNS queries
• Blocks access to security and antivirus websites
• And, to top it all off, Conficker.C can choose from a list of 500 domains to contact out of a pool of 50,000 (way up from Conficker.B's 32 out of 250).

Conficker.C - Detailed Evaluation by SRI
An Analysis of Conficker C

QUOTE: Variant C represents the third major revision of the Conficker malware family, which first appeared on the Internet on 20 November 2008. C distinguishes itself as a significant revision to Conficker B. In fact, we estimate that C leaves as little as 15% of the original B code base untouched

protect.gif Below are some resources for information and cleaning tools for the Conficker worm:

Conficker - Cleaning tips for corporate users
http://msmvps.com/blogs/harrywaldron...ate-users.aspx

Internet Storm Center - Conficker Resource Center
SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc

Microsoft Resources
Virus alert about the Win32/Conficker.B worm
http://www.microsoft.com/technet/sec.../ms08-067.mspx

lurkswithin 03-30-2009 07:26 AM

More information concerning the Conflictor worm!

Bits from Bill: Conficker Judgement Day on April 1st

Bits from Bill: Conficker Threat: Fact or Fiction

Security Garden: Conficker Information for the Home Computer User

lurkswithin 03-30-2009 05:57 PM

Use this link to a free online scanner for the conflicter worm and associates.

Remove Downadup - Removal tool for Downadup (known also as Conficker or Kido)


This scanner is quick and fast but a browser add-on will need to be installed for the scanner to work.

Those that are most likly to be infected are those from South America and Asia as that is where most un updated protection computers are located because of the use of pirated software.

Microsoft does not support updates to these areas unless proven WGA.

lurkswithin 03-30-2009 10:07 PM

Here is a tools list that will help in the removal of conflicter.

Understand that if you are infected or get infected, you may not be able to go directly to the web pages for these tools from the infected computer because of blocking or complete shut down of your computer internet service.

It might be wise to down load these to your computer before so and run them for the protection!

Conficker Work Group - ANY - RepairTools

pauls 04-04-2009 07:26 PM

It was amazing how pervasive this was. We run a really tight ship at work, but it still wormed it's way in. I guess it just takes 1 person.


All times are GMT -4. The time now is 07:00 PM.


Copyright © 2005-2013 SysChat.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54