Faster Computers Forums
FasterComputers.com
Quick Member Login:
Forgot password?
Forum Sponsors:
becomeasponsor



Test your Internet connection speed

becomeasponsor
Forum Statistics:
Forum Members: 152
Total Threads: 279
Total Posts: 1,225


There are 5 users
currently browsing forums.
You don't appear to be registered. Click here to register
Search the forums:

Faster Computers Forums » Hardware Forums » Internet, Networking, and Security » Conficker Virus

Notices

Reply
 
LinkBack Thread Tools Display Modes
Old 04-02-2009, 03:56 PM   #1 (permalink)
Noob Member
 
Join Date: Apr 2009
Posts: 2
solarin69 is on a distinguished road

Default Conficker Virus

Hello. Just thought I'd open this thread since I'm being paranoid thinking about this. Prevention is better than cure you know. Anyone could tell me something that I can use to protect my computers? In case you didn't see my intro I'm a computer shop owner so I really need to know. Hope anyone can help.
solarin69 is offline   Reply With Quote
Old 04-03-2009, 12:18 AM   #2 (permalink)
Noob Member
 
Join Date: Apr 2009
Posts: 8
jason is on a distinguished road

Default

I use Norton Internet Security. The automatic updates assure that you always up to date on your virus definitions.
jason is offline   Reply With Quote
Old 04-03-2009, 11:50 PM   #3 (permalink)
Noob Member
 
Join Date: Mar 2009
Posts: 24
knight is on a distinguished road

Default

Well there are some simple steps that you can follow in order to keep the viruses at check. The best thing is to update the antivirus frequently which is very important and the second thing is to avoid browsing webpages and websites which are known to contain trojan and other harmful malicious softwares like keyloggers.
knight is offline   Reply With Quote
Old 04-04-2009, 11:15 AM   #4 (permalink)
Member
 
Join Date: Apr 2009
Posts: 40
sphinx is on a distinguished road

Default

Hi solarin69! Wow, that is really risky. My brother also runs a computer shop but the number of units are low so we can still maintain our PCs. You might want to run a scan every week or so to make sure that your computers are all clean.
sphinx is offline   Reply With Quote
Old 04-04-2009, 12:01 PM   #5 (permalink)
Member
 
Join Date: Apr 2009
Posts: 34
singer246 is on a distinguished road

Default

Identifying and removing Conficker

There’s been a lot of talk about how Conficker is going to create havoc on April 1. Conficker, formally named W32/Conficker.worm, began infecting systems at the end of 2008 by exploiting a vulnerability in Microsoft Windows. Since then McAfee has seen two more variants of this worm and many binaries – files ready to load into memory and execute – that carry the worm’s malicious payload. Conficker.C is the latest variant. Its “call-home protocol” will change on Wednesday, April 1, and may entail an update with some as-yet unknown functionality.

McAfee already offers protection from the Conficker worm in its endpoint and network products, and Microsoft has issued a security patch for the vulnerability that the Conficker family has used to propagate. Yet many computer users continue to worry about infection. The information below will help you understand more about the worm, the steps you can take to clean an infected system, and measures to prevent reinfection.
What is the Conficker worm?

Conficker.C is the most recent variant of the Conficker worm. Exposure to Conficker.C is limited to systems that are still infected with the earlier variants, Conficker.A and Conficker.B, which operate by exploiting the MS08-067 vulnerability in Microsoft Windows Server Service. If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. Conficker combats efforts at eradication by creating scheduled tasks and/or using autorun.inf files to reactivate itself.
McAfee has identified thousands of binaries that carry the Conficker payload. Depending on the specific variant, the worm may spread via LAN, WAN, web, or removable drives, and by exploiting weak passwords. Conficker disables several important system services and security products, and downloads arbitrary files. Computers infected with the worm become part of an “army” of compromised computers and could be used to launch attacks on websites, distribute spam, host phishing websites, or carry out other malicious activities.
How to tell if your system is infected
Symptoms of Conficker infection include the following:

•Access to security-related sites is blocked
•Users are locked out of the directory
•Traffic is sent through port 445 on non-Directory Service (DS) servers
•Access to admininistrator shared drives is denied
•Autorun.inf files are placed in the recycled directory, or trash bin

Steps to remove Conficker and prevent re-infection
We recommend customers take the following steps to remove W32/Conficker.worm and prevent it from spreading:
1.Install Microsoft Security Update MS08-067: http://www.microsoft.com/technet/sec.../MS08-067.mspx

2.Clean the infected systems, and reboot
Use anti-malware solutions such as McAfee VirusScan Plus or ToPS for Endpoint to clean the infection. Use behavioral detection techniques like the buffer overflow protection in Host IPS to prevent future infections. This is important because Conficker can propagate via portable media such as infected USB drives. As the media are accessed, the system processes autorun.inf and executes the attack. For more information, read McAfee Avert Labs’ document “Combating Conficker Worm.”

3.Identify other systems at risk of infection
You need to identify which systems are at risk. The list includes systems that either are not patched against Microsoft vulnerability MS08-067 or do not have proactive protection controls to mitigate the vulnerability. McAfee Vulnerability Manager and ePolicy Orchestrator can identify systems that are vulnerable and not protected.

4.Limit the threat’s ability to propagate
Using network IPS at strategic points in your network will quickly limit the ability of the threat to spread. This gives you time to either update your client anti-virus signatures or modify policies to block the threat using the behavioral controls.
singer246 is offline   Reply With Quote
Old 04-04-2009, 12:26 PM   #6 (permalink)
Member
 
Join Date: Mar 2009
Posts: 99
bammer is on a distinguished road

Default

HI solarin, my friend has a computer shop also and same problem with you...i dont know if this is a good advice but he used a Deep Freeze...it minimizes his agony from reformatting,(i think almost every other day)...
bammer is offline   Reply With Quote
Old 04-07-2009, 09:15 AM   #7 (permalink)
Member
 
Join Date: Apr 2009
Posts: 40
sphinx is on a distinguished road

Default

Quote:
Originally Posted by bammer View Post
HI solarin, my friend has a computer shop also and same problem with you...i dont know if this is a good advice but he used a Deep Freeze...it minimizes his agony from reformatting,(i think almost every other day)...
Every other day!? That's so much a hassle!

@singer246: Please also include the source of this information. Thanks.
sphinx is offline   Reply With Quote
Old 05-08-2009, 01:44 AM   #8 (permalink)
Noob Member
 
Join Date: Apr 2009
Posts: 20
aftertaste is on a distinguished road

Default

I haven't been hit by this controversial virus. It seems that its' just a hoax in my opinion. It was released during april 1. But even if it was, its not that devastating as you can just reformat or do something about it.
aftertaste is offline   Reply With Quote
Old 05-11-2009, 11:39 AM   #9 (permalink)
Member
 
Ricardo's Avatar
 
Join Date: Apr 2009
Posts: 56
Ricardo is on a distinguished road

Default

So do you think this virus is lying dormant and waiting for a later date to do something?

In my case, I've had no problems since I've been using the Norton software that's offered by my ISP.

My last issue was with the sasser worm back in 2004.
__________________
This Twisted History
Ricardo is offline   Reply With Quote
Old 06-05-2009, 09:47 AM   #10 (permalink)
HDD
Noob Member
 
Join Date: Jun 2009
Posts: 20
HDD is on a distinguished road

Default

I think the only thing you can do is reformat your computer so that it will be in good shape again.
HDD is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -4. The time now is 06:09 PM.
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd. Copyright © FasterComputers.com