<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6726300020901758268</id><updated>2011-11-27T16:44:12.908-08:00</updated><category term='prevent kido virus'/><category term='downadup virus'/><category term='confiker virus'/><category term='windows software'/><category term='conficker removal'/><category term='prevent downadup virus'/><category term='worm cleaner'/><category term='windows security'/><category term='conficker worm'/><category term='worm'/><category term='conficker c'/><category term='prevent conficker virus'/><category term='conficker'/><category term='conficker virus'/><category term='downadup'/><category term='prevent confiker virus'/><category term='kido virus'/><title type='text'>Prevent Conficker Virus "aka" Kido and Downadup</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://preventconfickervirus.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6726300020901758268/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://preventconfickervirus.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Axel San Miguel</name><uri>http://www.blogger.com/profile/05945840022421216153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6726300020901758268.post-5134204496713079061</id><published>2009-03-31T11:40:00.000-07:00</published><updated>2009-03-31T11:45:35.043-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker worm'/><category scheme='http://www.blogger.com/atom/ns#' term='windows software'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker removal'/><category scheme='http://www.blogger.com/atom/ns#' term='worm cleaner'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker c'/><category scheme='http://www.blogger.com/atom/ns#' term='windows security'/><category scheme='http://www.blogger.com/atom/ns#' term='downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker'/><title type='text'>Conficker Worm Detection And Removal</title><content type='html'>&lt;p&gt;By now you might have heard about the latest worm that is plaguing &lt;a itxtdid="8523372" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;Internet&lt;/a&gt; users world wide. It goes by the name of Conficker (or Downadup)and comes in the variants A,B and C with c being the most evolved variant. To put it simple: Conficker uses a Windows vulnerability that was discovered in September 2008 and a patch was released by &lt;a itxtdid="523535" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;Microsoft&lt;/a&gt; that fixed it. The first worm that used the vulnerability was discovered in November 2008. &lt;/p&gt; &lt;p&gt;Conficker C will initiate a number of processes on infected host systems including opening a random port which is being used in the distribution process of the worm. The worm will then patch the security hole on the computer system that allowed it to attack the system in first place. This prevents other viruses from exploiting the vulnerability while keeping a backdoor open for newer variants of the Conficker worm. The worm will block certain strings from being accessed on the Internet. &lt;a itxtdid="1193592" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;Domain names&lt;/a&gt; making use of those strings cannot be accessed unless the IP is used to do so. Among the strings are various security companies like microsoft, panda or &lt;a itxtdid="524038" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;symantec&lt;/a&gt; but also generic strings like defender, conficker or anti-. This is to prevent users from accessing websites that contain information and removal instructions about the worm.&lt;/p&gt; &lt;p&gt;While this is surely a nuisance for the user it does mean that the worm itself is not harming the user system in any way other than the methods described above. The real danger comes from the updating mechanism of Conficker C. The worm will try to retrieve new instructions on April 1, 2009. A very sophisticated updating mechanism has been implemented by the author. The worm will generate a list of 50K &lt;a itxtdid="523080" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;domain&lt;/a&gt; names and append a list of 116 &lt;a itxtdid="1193709" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;top level domains&lt;/a&gt; to them. It will then select 500 randomly from the list and try to connect to them. If new instructions are found on one of the urls it will download them and execute them on the computer system. This process will be repeated every 24 hours.&lt;/p&gt; &lt;p&gt;&lt;span id="more-11564"&gt;&lt;/span&gt;The easiest way of detection is by accessing a site like microsoft.com or symantec.com and comparing the results with accessing the site using the IP addresses (207.46.197.32 and 206.204.52.31). While this usually gives a good indication it is better to check the &lt;a itxtdid="646518" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;computer&lt;/a&gt; &lt;a itxtdid="695110" target="_blank" href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#" style="border-bottom: 0.075em solid darkgreen ! important; font-weight: normal ! important; font-size: 100% ! important; text-decoration: underline ! important; padding-bottom: 1px ! important; color: darkgreen ! important; background-color: transparent ! important;" classname="iAs" class="iAs"&gt;system&lt;/a&gt; with tools that have been specifically designed to detect and remove the Conficker variants.&lt;/p&gt;&lt;p&gt;&lt;img src="http://www.ghacks.net/wp-content/uploads/2009/03/conficker_removal-500x167.jpg" alt="conficker removal" title="conficker removal" class="alignnone size-medium wp-image-11563" height="167" width="500" /&gt;&lt;/p&gt;&lt;p&gt;A few tools that can be used to detect and remove Conficker variants are &lt;a href="http://download.eset.com/special/EConfickerRemover.exe"&gt;ESET Conficker Removal Tool&lt;/a&gt;, &lt;a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip"&gt;Downadup from F-Secure&lt;/a&gt; or &lt;a href="http://data2.kaspersky-labs.com:8080/special/KidoKiller_v3.3.3.zip"&gt;KidoKiller by Kaspersky&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;Excellent information about Conficker detection and removal instructions are available at &lt;a href="http://isc.sans.org/diary.html?storyid=5860"&gt;Sans.org&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Information taken from &lt;a href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/"&gt;http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.cyatcom.com/"&gt;&lt;span style="text-decoration: underline;"&gt;For more tips and tricks go to http://www.cyatcom.com&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6726300020901758268-5134204496713079061?l=preventconfickervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://preventconfickervirus.blogspot.com/feeds/5134204496713079061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://preventconfickervirus.blogspot.com/2009/03/conficker-worm-detection-and-removal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6726300020901758268/posts/default/5134204496713079061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6726300020901758268/posts/default/5134204496713079061'/><link rel='alternate' type='text/html' href='http://preventconfickervirus.blogspot.com/2009/03/conficker-worm-detection-and-removal.html' title='Conficker Worm Detection And Removal'/><author><name>Axel San Miguel</name><uri>http://www.blogger.com/profile/05945840022421216153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6726300020901758268.post-2443335079057726880</id><published>2009-03-30T08:53:00.000-07:00</published><updated>2009-03-30T17:23:36.663-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='prevent confiker virus'/><category scheme='http://www.blogger.com/atom/ns#' term='prevent conficker virus'/><category scheme='http://www.blogger.com/atom/ns#' term='confiker virus'/><category scheme='http://www.blogger.com/atom/ns#' term='downadup virus'/><category scheme='http://www.blogger.com/atom/ns#' term='prevent kido virus'/><category scheme='http://www.blogger.com/atom/ns#' term='prevent downadup virus'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker virus'/><category scheme='http://www.blogger.com/atom/ns#' term='kido virus'/><title type='text'>5 tips to prevent infection from the Conficker virus.</title><content type='html'>&lt;h2&gt;What is the Conficker or Downadup worm virus?&lt;/h2&gt;&lt;br /&gt;Well, is a new virus that is spreading like wildfire all over the Internet and has infected millions of PCs around the world.&lt;br /&gt;&lt;br /&gt;Conficker or Downadup is a worm that propagates on local and network drives by taking advantage of the Microsoft Windows Server Service RPC &lt;a href="http://vil.nai.com/vil/content/v_vul40728.htm" target="_blank"&gt;MS08-067&lt;/a&gt; Handling Remote Code Execution Vulnerability. W32.Downadup can create its own Service on Windows to run itself each time Windows is started.&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;If your PC is acting weird and presents some of this symptoms:&lt;/h2&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Users being locked out of directory&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Access to admin shares denied&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Scheduled tasks being created&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Access to security related web sites is blocked.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;Then your PC might be infected, go to &lt;a href="http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe"&gt;http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDownadup.exe&lt;/a&gt; and download this tool to remove the Downadup "aka"Conficker "aka" Kido virus by following this steps:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt; Stop all your running programs.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Disconnect from your internet connection by disabling your network card or removing the cable from your PC.  If you are connected to the internet wireless then turn off your wireless connection.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Disable System Restore (Windows XP)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Find the tool you just download FixDownadup.exe and run it.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;If you see that the tool didn't remove the worm or didn't find anything, restart your PC in Safe Mode and run the tool again to make sure your PC is clean.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Restart your PC in normal mode again and make sure to enable System Restore.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Enable your network card or plug in your cable to reestablish your internet connection.  If it was wireless turn it on.&lt;/li&gt;&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;h2&gt;5 Tips to prevent from getting infected with the Conficker Virus:&lt;/h2&gt;&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Run a live update from your prefer anti virus program to make sure you have the latest updates.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Run a full scan from your anti virus to make sure their is nothing else molesting your computer.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Run your windows update to download all the critical updates from Microsoft.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Don't open any suspicious email and don't enter any suspicious website.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Make sure you have installed in your updates the MS patch KB958644&lt;/li&gt;&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;img class="alignnone" title="MS patch kb958644" src="http://cyatcom.com/blogimages/kb958644.png" alt="" height="330" width="524" /&gt;&lt;br /&gt;&lt;br /&gt;for more information about this post and other tips and tricks go to &lt;a href="http://cyatcom.com/blog/index.php/5-tips-to-prevent-infection-from-the-downadup-akaconficker-aka-kido-worm-virus"&gt;http://www.cyatcom.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6726300020901758268-2443335079057726880?l=preventconfickervirus.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://preventconfickervirus.blogspot.com/feeds/2443335079057726880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://preventconfickervirus.blogspot.com/2009/03/5-tips-to-prevent-infection-from.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6726300020901758268/posts/default/2443335079057726880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6726300020901758268/posts/default/2443335079057726880'/><link rel='alternate' type='text/html' href='http://preventconfickervirus.blogspot.com/2009/03/5-tips-to-prevent-infection-from.html' title='5 tips to prevent infection from the Conficker virus.'/><author><name>Axel San Miguel</name><uri>http://www.blogger.com/profile/05945840022421216153</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
