also @ TechSpot: Weekend Open Forum: Have you upgraded to Windows 7 yet?
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > News and Links from Around the Web

Are you a Conficker Zombie?

Closed Thread
Bookmark Thread Tools
  #1  
Old 02-20-2009
jobeard's Avatar
TechSpot Evangelist
 
Location: Southern Calif.
Member since: Apr 2005, 7,906 posts
Are you a Conficker Zombie?

Conflicker [A] has hit millions of systems.

Now there's Conflicker B++ too

The big picture Taxonomy of Conflicker is


Another common infection Taxonomy is


(see the original article here)

The Computerworld article is here

CAUTION: Don't be overly concerned over the comment on HOST file at the bottom of that article;
MVSP.org and Spybot S&D modify the HOST file to intentionally inhibit access to known bad sites.
Such 'lockouts' are easily see on any line containing 127.0.0.1
  #2  
Old 02-20-2009
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Conflicker/downadup Cleanup and removal

Instructions: http://www.bleepingcomputer.com/malw...adup-conficker

Bit defender Removal tool http://www.bitdefender.com/site/Down...reeRemovalTool

Microsoft patch (to prevent if not already infected or use after clean) http://www.microsoft.com/downloads/r...DisplayLang=en

Mike

EDIT: New for Conflicker!

Just yesterday Mcafee introduced a special Stinger dedicated to Conflicker

Get it here http://www.majorgeeks.com/McAfee_AVE...er__d6157.html

I will edit my other post and add it there.

This is a bad one so.....

I advise anyone who supects this malware to shoot it with all 3 programs followed by MBAM , SAS and ComboFix.

And tet another from Sophos: http://www.majorgeeks.com/Sophos_Con...ool_d6158.html

Last edited by mflynn; 03-31-2009 at 02:32 PM..
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 02-20-2009
jobeard's Avatar
TechSpot Evangelist
 
Location: Southern Calif.
Member since: Apr 2005, 7,906 posts
VERY GOOD IDEA; one location for description and solution
  #4  
Old 03-31-2009
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Hi everyone been away and busy for last few days but thought I would take time post this!

New for Conflicker!

Just yesterday Mcafee introduced a special Stinger dedicated to Conflicker

Get it here http://www.majorgeeks.com/McAfee_AVE...er__d6157.html

I will edit my other post and add it there.

This is a bad one so.....

I advise anyone who supects this malware to shoot it with all 3 programs followed by MBAM , SAS and ComboFix.

Mike

EDIT: Another just today http://www.majorgeeks.com/Sophos_Con...ool_d6158.html

Last edited by mflynn; 03-31-2009 at 02:32 PM..
  #5  
Old 03-31-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
More info on this: http://www.winsupersite.com/server/conficker.asp
  #6  
Old 03-31-2009
SNGX1275's Avatar
TS Special Forces
 
Location: Rolla, Missouri, USA
Member since: Feb 2002, 9,289 posts
System specs
How bad is this really? I've been hearing about it on the news since Sunday's 60 Minutes (on cbs). Prior to that I hadn't really heard about it.

It kind of sparks my intrest because as some of you know, I don't run any AV on my machines. I'm pretty self confident that I'm in the clear, but something 'big' like this would be the kind of thing to shake my confidence if I was comprimised.

Is this a type of thing where we don't know what it does until April 1? That is my impression at this point. And I think rather than dling and running a bunch of software I don't want on my machines I'm just going to risk it and see what happens in 5.25 hours.

Disclaimer:
Do not follow my example if you are concerned for your data, I'm assuming entire responsibility only for what happens to my computers.
  #7  
Old 03-31-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Um put it this way, I presently don't have any issue, where I am
  #8  
Old 03-31-2009
LookinAround's Avatar
TechSpot Evangelist
 
Location: Chicago-land, IL
Member since: Apr 2007, 3,666 posts
Quote:
Originally Posted by SNGX1275 View Post
How bad is this really? I've been hearing about it on the news since Sunday's 60 Minutes (on cbs). Prior to that I hadn't really heard about it.

It kind of sparks my intrest because as some of you know, I don't run any AV on my machines. I'm pretty self confident that I'm in the clear, but something 'big' like this would be the kind of thing to shake my confidence if I was comprimised.

Is this a type of thing where we don't know what it does until April 1? That is my impression at this point. And I think rather than dling and running a bunch of software I don't want on my machines I'm just going to risk it and see what happens in 5.25 hours.

Disclaimer:
Do not follow my example if you are concerned for your data, I'm assuming entire responsibility only for what happens to my computers.
I saw 60 minutes as well. And agree. I've run my usual backups but otherwise, I'm still waiting for Y2K to hit!
  #9  
Old 03-31-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,027 posts
Quote:
Originally Posted by LookinAround View Post
I'm still waiting for Y2K to hit!


That really did make me laugh out loud


anyway: MS Article
http://www.microsoft.com/protect/com...conficker.mspx

Last edited by kimsland; 03-31-2009 at 09:40 PM..
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 03-31-2009
supersmashbrada's Avatar
TechSpot Evangelist
 
Location: Detroit
Member since: Mar 2007, 3,071 posts
System specs
Quote:
Originally Posted by kimsland View Post


That really did make me laugh out loud


anyway: MS Article
http://www.microsoft.com/protect/com...conficker.mspx

I got suspended from High School because we had to write a paper about the y2k issue. 95% of my class had fear of the issue, along with my teacher.

My paper basically stated how ignorant people are. Did we not forget that we have 24 time zones. Will the world end one hour at a time?
  #11  
Old 04-01-2009
jobeard's Avatar
TechSpot Evangelist
 
Location: Southern Calif.
Member since: Apr 2005, 7,906 posts
Quote:
Originally Posted by SNGX1275 View Post
...It kind of sparks my intrest because as some of you know, I don't run any AV on my machines. I'm pretty self confident that I'm in the clear, but something 'big' like this would be the kind of thing to shake my confidence if I was comprimised.
and I'm big on on proactive defense and down on the reactive A/V approach.
Good router and firewall controls trump A/V everytime (imo).

If I can keep healthy, then the prescription/rx with the doctors bill can be avoided altogether

Oh sure I have one -- once in a while I even scan with it.

But using good software{Thunderbird, Firefox}, Spywareblaster(controlling ActiveX), Spybot S&D(controlling startups), trimming Services, and a firewall that controls in/out bound access will cover the bases 99% of the time.
  #12  
Old 04-02-2009
captaincranky's Avatar
TechSpot Evangelist
 
Member since: Oct 2006, 3,484 posts
Quote:
Originally Posted by jobeard View Post
But using good software{Thunderbird, Firefox}, Spywareblaster(controlling ActiveX), Spybot S&D(controlling startups), trimming Services, and a firewall that controls in/out bound access will cover the bases 99% of the time.
It seems to be fashionable nowadays, to award all the credit (or blame), to just the AV software, but it can't be stated how much help it's receiving from FF (with "NoScript") and Spybot, not only it's resident "Tea timer", with it also controlling the hosts file. I'm not certain, but it seems like it's got something akin to "Combo Fix", built in.
  #13  
Old 04-02-2009
jobeard's Avatar
TechSpot Evangelist
 
Location: Southern Calif.
Member since: Apr 2005, 7,906 posts
forgot to mention -- A/V is THE proactive protection for email -- just got to scan them for scruff
  #14  
Old 04-02-2009
tw0rld's Avatar
TechSpot Enthusiast
 
Member since: Oct 2007, 551 posts
Avira is the Closest to proactive as A/V gets, and that's to know threats. What we really need is for operating systems to be built in such a way as to prevent the execution of malicious codes. An environment that would be able to decipher the codes compiled in a program to determine if it is malicious or not, simply based on what task the program was designed to carry out. This can be liken to telepathy.

Imagine being the security Guard at a Bank. The chance of robbers getting by you is high, because you can't stop and interrogate each individual. Now think of the probability of any robbers getting by you if you were able to stop,and interrogate each individual to get an idea of what their intentions are. The probability of the Bank getting robbed would be close to zero.

Last edited by tw0rld; 04-02-2009 at 06:41 PM..
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Tags
conflicker, pe_virux
Thread Tools


Similar Topics
Topic Category Replies Last Post
Mal/Conficker-A is a worm for the Windows platform Virus & Malware removal 11 01-27-2009 03:37 PM
i need help with Stubbs the Zombie PC Gaming and Consoles 5 06-22-2007 05:42 PM


All times are GMT -4. The time now is 07:42 PM.