There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus batch bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop lcd malware memory modem monitor motherboard network printer problem ram registry router slow software sound toshiba trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless xbox
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Conficker.C - who do you tell if infected ???

Reply  
Thread Tools
axis77's Avatar
Senior Member with 660 posts.
 
Join Date: Aug 2004
Location: The Golden State
Experience: Intermediate
25-Mar-2009, 07:45 PM #1
Conficker.C - who do you tell if infected ???
ive been reading about the april 1st deadline, but how do we know if our pc has been infected with this virus, and does patching ms08-067 fix this? or just not allow your pc to send out info or prevent it from being infected??
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
25-Mar-2009, 08:52 PM #2
I haven't seen anything about a 'deadline' but, generally speaking, if you can get to the Windows Update site, your antivirus is still updating, you can run the MS Malicious Software Removal Tool and your Restore points haven't mysteriously disappeared recently, you probably don't have Conficker (yet).

There seems to have been a lot of confusion about the status of the various patches and things like the the Windows Autorun/Autoplay function. I have seen comments in various places about the need to be careful if anyone with access to your computer uses 'external devices' (such as USB memory sticks), which might have been used on another computer.

I recently saw a report about the C variant of Conficker which suggests that it is one nasty piece of work. It's fairly technical and is subject to revision, but you can read it here if you want to; http://mtc.sri.com/Conficker/addendu...-global-impact I think the only thing we can do is to keep everything patched.

EDIT: Just noticed the post referring to this article; http://tech.yahoo.com/blogs/null/128...-come-april-1/ It seems to be a short summary of the technical thing I linked to, but I don't know where the assumption about 1st April comes from. I assume it's because, in the past, some malware has been triggered on that date.
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930

Last edited by TOGG; 26-Mar-2009 at 09:56 AM..
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
26-Mar-2009, 09:54 AM #3
I have now re-read that tech article I posted the link to (which I first saw about a week ago) and this reference to 1st April appears just before the 'Domain Generation Algorithm' section;

"Finally, C introduces a substantial modification of the DGA and query procedure, discussed in Domain Generation Algorithm. The DGA will be activated on 1 April 2009, and before April 1st it will enter a loop that sleeps 24 hours and then rechecks the date via getlocaltime. Prior to entering the April 1st date check, C will sleep for an initial random interval between 30 and 90 minutes. More specifically, this sleep interval is between 30 and 90 minutes if the local hour is after 11 a.m. and before 7 a.m. If the local time is after 8 a.m. and before 11 a.m., the sleep period will be between 2.5 and 3.5 hours. It will then check for Internet connectivity, and if connected will enter the domain generation logic. The next section describes this logic in greater detail."
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
lotuseclat79's Avatar
Distinguished Member with 21,345 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
26-Mar-2009, 12:02 PM #4
Giz Explains: How a Brainy Worm Might Jack the World's PCs on April 1.

See last paragraph for link on what to do if infected in order to get rid of it.

-- Tom
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 08:42 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.