Sep 08, 2010 - 09:23 PM  
ComTek Computer Services Inc. - Boise, ID.  
 
 

Online

There are 1 visitors and 0 registered users online.

You can log-in or register for a user account here.

Search This Site


Overheard

"If I had eight hours to chop down a tree, I'd spend six sharpening my ax."

-- Abraham Lincoln

The "No Bull" Guide to Conficker

Posted by: Webmaster on Tuesday, March 31, 2009 - 10:23 PM Print article Printer-friendly page  Email to a friend Send this story to someone
Malware Threats

I usually have a pretty good idea of how widespread a particular piece of malware is by the number of incidents of infection that I come across. But when it comes to the Conficker worm (aka Downadup or Kido), I get the feeling that while there’s a lot of hype surrounding this latest bit of malware, actual infections are much lower than some would want you to believe. However, over the past few days the number of enquires I’m getting in relation to Conficker has skyrocketed
Some antivirus companies love to hype malware because it’s a great way to sell security products. While Conficker isn’t new (it’s been around since November last year), the April 1st trigger date gives security firms the opportunity to ratchet up the hype a couple of more notches (and help drive concerned users straight into the hands of cybercriminals). However, it’s important to note that it’s unclear right now as to what will happen come the trigger date. However, what is clear is that you will need to be infected to be at risk of anything happening at all.



It seems that more than half of all Conficker infections are confined to PCs in China, Brazil, Russia, India, and Argentina, so folks in the US and Europe have dodged the bullet … mostly. Given the relatively low number of Conficker infections that I’ve come across, I’d say that the research is spot on.

If you’re running a fully patched system, then you’ve got little to be worried about. If you’re running an antivirus program, then you’ve got a second line of defense. If you’re worried, run a scan with a detection tool (links below). Better to be safe than sorry. Conficker can spread via network shares, leveaging weak passwords, so if you can’t trust the systems you’re connected to, and you know you’re using weak passwords, then your risk of being infected is elevated. Also, Conficker can spread via removable drives by taking advantage of Windows autoplay.

If you’re running a bootleg copy of Windows that’s not patched properly, or you’ve been neglecting to patch up (the security bulletin that’s important here is MS08-067) then there’s a small chance that you could be infected. If you’re worried, run a system scan using one of the following tools:(Or use the HouseCall located on the home page of this site to detect an infection)

If you’re having trouble accessing any of the above links then that could be an indicator that you’re infected because Conficker (specifically Conficker.C) incorporates a domain blocker to prevent infected users from getting help (even accessing Windows Update and Microsoft Update). It’s now important that you use an uninfected PC to download a Conficker removal tool onto a USB drive and clean up the infected PC. Alternatively, you can visit a site run by security firm BitDefender that is, as of the time of writing, not blocked (this site could be added to Conficker’s block list at any time, so there are no guarantees that it will remain open to those who are infected).

After cleaning up the PC, apply the patch and then get on with the rest of your life.

Bottom line … Don’t panic!

Note: by Adrian Kingsley-Hughes of ZDNet
The "No Bull" Guide to Conficker | Log-in or register a new user account | 0 Comments
Comments are statements made by the person that posted them.
They do not necessarily represent the opinions of the site editor.
HOME
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002 by ComTek Computer Services Inc .


Share this page on facebook!

You can syndicate our news using the file backend.php
Page created in 3.2256631851196 seconds.