iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Removing Confounding Conficker
Search:
[ insider_reports_insider ]

Removing Confounding Conficker



SecurityProNews
Staff Writer
2009-01-23

SecurityProNews: Insider Reports Insider Reports RSS Feed


If you're one of an estimated ten million afflicted with the Conficker worm, SecureWorks has proffered a workaround to clean it off your system.

Removing Confounding Conficker
Removing Confounding Conficker

Conficker, also known as Downadup, Kido, and Conflicker, is a particularly nasty and smart virus spreadable via popular USB devices-you know, those little, tartish gadgets that flit from computer to computer without a thought?

Turns out, in addition to installing itself, copying itself, adjusting the Windows TCP/IP settings, and spreading itself to all removable/network devices, Conficker also disables Windows cleanup and detection services, deletes system restore points, blocks Internet access to Microsoft.com and other security service sites, and waits three hours before trying to download additional code from 250 different domain names generated and set up daily.

You'll know you're infected because network drives have hidden autorun.inf files, you're locked out of network logins because of too many failed attempts, and you can't access Microsoft.com.

The good news is, SecureWorks says it's treatable. Here's their workaround if none of your security software works and you can't get to the security sites you need:

Conficker/Downadup Removal:

· Use a proxy server to download Microsoft's Malicious Software Removal Tool (MSRT) from the following URL:

http://www.microsoft.com/security/malwareremove/default.mspx

· Or, if no proxy is available, a workaround is needed. One can use a direct link to the MSRT on Microsoft's content delivery network server. Since this is a third party hosting company, their domain name is not on the blocked list, so one can substitute "mscom-dlcecn.vo.llnwd.net" for "download.microsoft.com" in the MSRT URL. The URL would then be:

http://mscom-dlcecn.vo.llnwd.net/download/4/A/A/4AA524C6-239D-47FF-860B-5B397199CBF8/windows-kb890830-v2.6.exe.

· Or, F-Secure also has a removal tool available, however the f-secure.com domain is in the blocked list of domain names above. Using an IP address instead of the hostname will bypass the worm's blocking routines, so that tool could be downloaded by infected systems at this URL:

ftp://193.110.109.53/anti-virus/tools/beta/f-downadup.zip.

· Run the automated removal tool to eliminate Conficker/Downadup



About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds