There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash dns drive driver drivers error ethernet excel freeze games gaming graphics hard drive hardware hdmi internet java laptop malware memory monitor motherboard network printer problem ram random registry router slow software sound trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Security Consultants warn of Conficker Worm To Strike April 1

Reply  
Thread Tools
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
27-Mar-2009, 03:25 PM #1
Security Consultants warn of Conficker Worm To Strike April 1
The Conficker worm that has left a trail of destruction in its wake for the last six months is set for a new evolution April 1 that will enable it to stealthily launch a variety of malware attacks unbeknownst to the security community.

Security experts say that the new Conficker variant, which has infected at least 12 million users around the globe since its creation in October, will contain a new update mechanism that will allow it to communicate with its command and control centers to upload new marching orders and launch attacks at will.

Part of the new update will include a refreshed ability to dodge scrutiny from the security community, which has thus far been able to intercept communication between the worm and its domains. After April 1, however, the new Conficker variant will contain code that will prevent the security community from blocking updates.

"The Internet as we know it will still exist," said Paul Henry, security and forensic analyst for Lumension Security. "But what (the security community has) been doing will no longer work after April 1. There's great concern in the security community because they're no longer able to block the command and control communication of this botnet."

Like other renowned worms, Conficker relies on numerous attack vectors to self-replicate and spread, using such techniques as brute force password guessing to propagate throughout a network.

The latest and most sophisticated variant -- Version C -- of the Conficker worm, was renowned for infecting copious networks via peer-to-peer networks and USB drives. It also added numerous defensive measures designed to evade detection and removal by disabling Windows Automatic Updates and Windows Security Center. In addition, version C had the ability to block access to several security vendors' Web sites while rendering numerous antivirus products useless.

Source-http://www.osnn.net/comments.php?shownews=15357
__________________
The care of human life and happiness, and not their destruction, is the first and only object of good government - Thomas Jefferson.
Jason08's Avatar
Computer Specs
Distinguished Member with 3,717 posts.
 
Join Date: Oct 2008
Location: Near Washington, D.C.
Experience: Advanced in Networking
27-Mar-2009, 09:10 PM #2
Thanks for sharing.
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
28-Mar-2009, 12:31 AM #3
I believe something like the variant C affected me.... I really could not go to the security vendors websites, this thing didn't even allow me to use tech support guy, yahoo answers. The malware is designed in such a way that prevents the access of the infected computer to forums which can provide useful and important tips for its removal. I couldn't do much to remove it... I really don't know what I did but it doesn't exist on my pc anymore
__________________
The care of human life and happiness, and not their destruction, is the first and only object of good government - Thomas Jefferson.
perfume's Avatar
perfume has a Photo Album
Computer Specs
Account Disabled with 2,011 posts.
 
Join Date: Sep 2008
Location: A DUDE WITH ATTITUDE! ALIEN.
Experience: Intermediate++
28-Mar-2009, 04:47 AM #4
Dear srprashant,
Your original post was excellent! I don't now whether to hug you or slug you,because your presentation was good and at the same time put the fear of God in me!lol. Why did you state your experience as "Beginner"? Should be "intermediate at the least"!

I think peer-to peer now becomes a real,real danger and thank God i did all my downloading from mu-torrent long before the music industry and these malware brains were fast asleep! I did download using mu-torrent(Why hide it?), but stopped long time back!

All the people using any kind of peer -to-peer softwares are really in danger, so please STOP the TEMPTATION TO DOWNLOAD! USE THE LEGAL WAY TO DOWNLOAD,it's cheap and keeps you safe!

TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
28-Mar-2009, 09:59 AM #5
I don't wish to add to the general paranoia or panic about Conficker C, but there is a very interesting 'Techie' analysis of it here; http://mtc.sri.com/Conficker/addendu...tall-obfuscate

As I understand everything I have read about it so far, nothing dramatic will happen on 1st April, except to computers that are already infected with it. For everybody else, the effects will be felt when this group of infected computers is directed to do whatever the authors of Conficker have in mind.

What that might be is anybody's guess and I for one don't propose to speculate (although the 'usual suspects' would be denial of service attacks and identity theft for financial gain etc.)
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
JamesFrance's Avatar
Member with 85 posts.
 
Join Date: Jun 2007
Location: Languedoc, France
Experience: Never too old to learn
28-Mar-2009, 04:30 PM #6
Most antivirus seem to detect it now:

http://malwareresearchgroup.com/?p=756
golferbob's Avatar
Senior Member with 3,870 posts.
 
Join Date: May 2004
Experience: Intermediate
28-Mar-2009, 04:53 PM #7
worm
download and run mcafee stinger. it will take conficker out of your system.


http://www.majorgeeks.com/McAfee_AVE...er__d6157.html
Blackmirror's Avatar
Computer Specs
Distinguished Member with 32,577 posts.
 
Join Date: Dec 2006
Location: uk
Experience: Away with the fairies :)
28-Mar-2009, 05:21 PM #8
The most important thing you can do is keep updated with windows updates and AV /Spyware protection
TOGG's Avatar
Distinguished Member with 5,362 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
28-Mar-2009, 05:54 PM #9
If you aren't already infected Blackmirror is quite right. However, if Conficker is as bad as it is described in the article I linked to, anybody that already has it will not be able to update their AV or download removal tools from the majority of security sites (see the 'Security Product Disablement' section; http://mtc.sri.com/Conficker/addendu...tall-obfuscate )
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
29-Mar-2009, 03:25 AM #10
this variant c tries to block ur security products access to its update servers, I guess I deleted the bad entries manually
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 823 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: still learning
29-Mar-2009, 03:28 AM #11
I shouldn't be mentioning this here... but I did try downloading this n*** burning software torrent... this was the root cause of all misery :'(
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 01:59 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.