Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop drivers dvd email error excel excel 2003 firefox hard drive hardware hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem processor recovery router safe mode screen slow sound spyware tdlwsp.dll trojan upgrade video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Conficker.C - who do you tell if infected ???

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
axis77's Avatar
Senior Member with 653 posts.
 
Join Date: Aug 2004
Location: The Golden State
Experience: Intermediate
25-Mar-2009, 06:45 PM #1
Conficker.C - who do you tell if infected ???
ive been reading about the april 1st deadline, but how do we know if our pc has been infected with this virus, and does patching ms08-067 fix this? or just not allow your pc to send out info or prevent it from being infected??
TOGG's Avatar
Distinguished Member with 4,901 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
25-Mar-2009, 07:52 PM #2
I haven't seen anything about a 'deadline' but, generally speaking, if you can get to the Windows Update site, your antivirus is still updating, you can run the MS Malicious Software Removal Tool and your Restore points haven't mysteriously disappeared recently, you probably don't have Conficker (yet).

There seems to have been a lot of confusion about the status of the various patches and things like the the Windows Autorun/Autoplay function. I have seen comments in various places about the need to be careful if anyone with access to your computer uses 'external devices' (such as USB memory sticks), which might have been used on another computer.

I recently saw a report about the C variant of Conficker which suggests that it is one nasty piece of work. It's fairly technical and is subject to revision, but you can read it here if you want to; http://mtc.sri.com/Conficker/addendu...-global-impact I think the only thing we can do is to keep everything patched.

EDIT: Just noticed the post referring to this article; http://tech.yahoo.com/blogs/null/128...-come-april-1/ It seems to be a short summary of the technical thing I linked to, but I don't know where the assumption about 1st April comes from. I assume it's because, in the past, some malware has been triggered on that date.
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930

Last edited by TOGG : 26-Mar-2009 08:56 AM.
TOGG's Avatar
Distinguished Member with 4,901 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
26-Mar-2009, 08:54 AM #3
I have now re-read that tech article I posted the link to (which I first saw about a week ago) and this reference to 1st April appears just before the 'Domain Generation Algorithm' section;

"Finally, C introduces a substantial modification of the DGA and query procedure, discussed in Domain Generation Algorithm. The DGA will be activated on 1 April 2009, and before April 1st it will enter a loop that sleeps 24 hours and then rechecks the date via getlocaltime. Prior to entering the April 1st date check, C will sleep for an initial random interval between 30 and 90 minutes. More specifically, this sleep interval is between 30 and 90 minutes if the local hour is after 11 a.m. and before 7 a.m. If the local time is after 8 a.m. and before 11 a.m., the sleep period will be between 2.5 and 3.5 hours. It will then check for Internet connectivity, and if connected will enter the domain generation logic. The next section describes this logic in greater detail."
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
lotuseclat79's Avatar
Distinguished Member with 14,988 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
26-Mar-2009, 11:02 AM #4
Giz Explains: How a Brainy Worm Might Jack the World's PCs on April 1.

See last paragraph for link on what to do if infected in order to get rid of it.

-- Tom
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 09:56 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.