Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop drivers dvd email error excel excel 2003 firefox hard drive hardware hdmi hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem recovery router safe mode screen slow sound spyware tdlwsp.dll trojan vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Security Consultants warn of Conficker Worm To Strike April 1

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 677 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: the 9th wonder :P
27-Mar-2009, 02:25 PM #1
Security Consultants warn of Conficker Worm To Strike April 1
The Conficker worm that has left a trail of destruction in its wake for the last six months is set for a new evolution April 1 that will enable it to stealthily launch a variety of malware attacks unbeknownst to the security community.

Security experts say that the new Conficker variant, which has infected at least 12 million users around the globe since its creation in October, will contain a new update mechanism that will allow it to communicate with its command and control centers to upload new marching orders and launch attacks at will.

Part of the new update will include a refreshed ability to dodge scrutiny from the security community, which has thus far been able to intercept communication between the worm and its domains. After April 1, however, the new Conficker variant will contain code that will prevent the security community from blocking updates.

"The Internet as we know it will still exist," said Paul Henry, security and forensic analyst for Lumension Security. "But what (the security community has) been doing will no longer work after April 1. There's great concern in the security community because they're no longer able to block the command and control communication of this botnet."

Like other renowned worms, Conficker relies on numerous attack vectors to self-replicate and spread, using such techniques as brute force password guessing to propagate throughout a network.

The latest and most sophisticated variant -- Version C -- of the Conficker worm, was renowned for infecting copious networks via peer-to-peer networks and USB drives. It also added numerous defensive measures designed to evade detection and removal by disabling Windows Automatic Updates and Windows Security Center. In addition, version C had the ability to block access to several security vendors' Web sites while rendering numerous antivirus products useless.

Source-http://www.osnn.net/comments.php?shownews=15357
__________________
The care of human life and happiness, and not their destruction, is the first and only object of good government - Thomas Jefferson.
Jason08's Avatar
Jason08 has a Photo Album
Computer Specs
Distinguished Member with 3,622 posts.
 
Join Date: Oct 2008
Location: Near Washington, D.C.
Experience: Advanced in Networking
27-Mar-2009, 08:10 PM #2
Thanks for sharing.
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 677 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: the 9th wonder :P
27-Mar-2009, 11:31 PM #3
I believe something like the variant C affected me.... I really could not go to the security vendors websites, this thing didn't even allow me to use tech support guy, yahoo answers. The malware is designed in such a way that prevents the access of the infected computer to forums which can provide useful and important tips for its removal. I couldn't do much to remove it... I really don't know what I did but it doesn't exist on my pc anymore
__________________
The care of human life and happiness, and not their destruction, is the first and only object of good government - Thomas Jefferson.
perfume's Avatar
perfume has a Photo Album
Computer Specs
Senior Member with 1,585 posts.
 
Join Date: Sep 2008
Location: An Alien,a misfit on Earth
Experience: Intermediate++
28-Mar-2009, 03:47 AM #4
Dear srprashant,
Your original post was excellent! I don't now whether to hug you or slug you,because your presentation was good and at the same time put the fear of God in me!lol. Why did you state your experience as "Beginner"? Should be "intermediate at the least"!

I think peer-to peer now becomes a real,real danger and thank God i did all my downloading from mu-torrent long before the music industry and these malware brains were fast asleep! I did download using mu-torrent(Why hide it?), but stopped long time back!

All the people using any kind of peer -to-peer softwares are really in danger, so please STOP the TEMPTATION TO DOWNLOAD! USE THE LEGAL WAY TO DOWNLOAD,it's cheap and keeps you safe!

__________________
TAKE A BACK UP AND RESTORE, BEFORE IT IS TOO LATE! (MACRIUM REFLECT-FREE) WEBSITE:http://www.macrium.com/reflectfree.asp
TOGG's Avatar
Distinguished Member with 4,901 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
28-Mar-2009, 08:59 AM #5
I don't wish to add to the general paranoia or panic about Conficker C, but there is a very interesting 'Techie' analysis of it here; http://mtc.sri.com/Conficker/addendu...tall-obfuscate

As I understand everything I have read about it so far, nothing dramatic will happen on 1st April, except to computers that are already infected with it. For everybody else, the effects will be felt when this group of infected computers is directed to do whatever the authors of Conficker have in mind.

What that might be is anybody's guess and I for one don't propose to speculate (although the 'usual suspects' would be denial of service attacks and identity theft for financial gain etc.)
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
JamesFrance's Avatar
Member with 77 posts.
 
Join Date: Jun 2007
Location: Languedoc, France
Experience: Never too old to learn
28-Mar-2009, 03:30 PM #6
Most antivirus seem to detect it now:

http://malwareresearchgroup.com/?p=756
golferbob's Avatar
Distinguished Member with 3,730 posts.
 
Join Date: May 2004
Experience: Intermediate
28-Mar-2009, 03:53 PM #7
worm
download and run mcafee stinger. it will take conficker out of your system.


http://www.majorgeeks.com/McAfee_AVE...er__d6157.html
Blackmirror's Avatar
Computer Specs
Distinguished Member with 28,046 posts.
 
Join Date: Dec 2006
Location: uk
Experience: Chocoholic
28-Mar-2009, 04:21 PM #8
The most important thing you can do is keep updated with windows updates and AV /Spyware protection
TOGG's Avatar
Distinguished Member with 4,901 posts.
 
Join Date: Apr 2002
Location: Birmingham, England
28-Mar-2009, 04:54 PM #9
If you aren't already infected Blackmirror is quite right. However, if Conficker is as bad as it is described in the article I linked to, anybody that already has it will not be able to update their AV or download removal tools from the majority of security sites (see the 'Security Product Disablement' section; http://mtc.sri.com/Conficker/addendu...tall-obfuscate )
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 677 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: the 9th wonder :P
29-Mar-2009, 02:25 AM #10
this variant c tries to block ur security products access to its update servers, I guess I deleted the bad entries manually
blitzkreig's Avatar
blitzkreig has a Photo Album
Computer Specs
Senior Member with 677 posts.
 
Join Date: Mar 2009
Location: Mumbai, India
Experience: the 9th wonder :P
29-Mar-2009, 02:28 AM #11
I shouldn't be mentioning this here... but I did try downloading this n*** burning software torrent... this was the root cause of all misery :'(
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 01:47 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.