Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, April 1, 2009

Conficker-C Worm Solution

National Cyber Alert System

Technical Cyber Security Alert TA09-088A archive

Conficker Worm Targets Microsoft Windows Systems

Original release date: March 29, 2009
Last revised: March 30, 2009
Source: US-CERT
Systems Affected - Microsoft Windows

Solution

Instructions, support and more information on how to manually remove a Conficker/Downadup infection from a system have been published by major security vendors.  Please see below for a few of those sites. Each of these vendors offers free tools that can verify the presence of a Conficker/Downadup infection and remove the worm:

Symantec:

http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99

Microsoft:
http://support.microsoft.com/kb/962007
http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx

Microsoft PC Safety hotline at 1-866-PCSAFETY, for assistance.

US-CERT encourages users to prevent a Conficker/Downadup infection by ensuring all systems have the MS08-067 patch (seehttp://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx), disabling AutoRun functionality (see http://www.us-cert.gov/cas/techalerts/TA09-020A.html), and maintaining up-to-date anti-virus software.

 

Need More Assistance?
Call 
1-800-905-GEEK (4335) Today

Mention Promo Code: APRIL25
and Receive $25.00 Off New Service 


Tuesday, March 31, 2009

Last-minute Conficker survival guide

Tomorrow -- April 1 -- is D-Day for Conficker, as whatever nasty payload it's packing is currently set to activate. What happens come midnight is a mystery: Will it turn the millions of infected computers into spam-sending zombie robots? Or will it start capturing everything you type -- passwords, credit card numbers, etc. -- and send that information back to its masters?

No one knows, but we'll probably find out soon.

Or not. As Slate notes, Conficker is scheduled to go "live" on April 1, but whoever's controlling it could choose not to wreak havoc but instead do absolutely nothing, waiting for a time when there's less heat. They can do this because the way Conficker is designed is extremely clever: Rather than containing a list of specific, static instructions, Conficker reaches out to the web to receive updated marching orders via a huge list of websites it creates. Conficker.C -- the latest bad boy -- will start checking 50,000 different semi-randomly-generated sites a day looking for instructions, so there's no way to shut down all of them. If just one of those sites goes live with legitimate instructions, Conficker keeps on trucking.

Conficker's a nasty little worm that takes serious efforts to bypass your security defenses, but you aren't without some tools in your arsenal to protect yourself.

Your first step should be the tools you already have: Windows Update, to make sure your computer is fully patched, and your current antivirus software, to make sure anything that slips through the cracks is caught.

But if Conficker's already on your machine, it may bypass certain subsystems and updating Windows and your antivirus at this point may not work. If you are worried about anything being amiss -- try booting into Safe Mode, which Conficker prevents, to check -- you should run a specialized tool to get rid of Conficker.

Microsoft offers a web-based scanner (note that some users have reported it crashed their machines; I had no trouble with it), so you might try one of these downloadable options instead: Symantec's Conficker (aka Downadup) tool, Trend Micro's Cleanup Engine, or Malwarebytes. Conficker may prevent your machine from accessing any of these websites, so you may have to download these tools from a known non-infected computer if you need them. Follow the instructions given on each site to run them successfully. (Also note: None of these tools should harm your computer if you don't have Conficker.)

As a final safety note, all users -- whether they're worried about an infection or know for sure they're clean -- are also wise to make a full data backup today.

What won't work? Turning your PC off tonight and back on on April 2 will not protect you from the worm (sorry to the dozens of people who wrote me asking if this would do the trick). Changing the date on your PC will likely have no helpful effect, either. And yes, Macs are immune this time out. 

Yahoo Tech News -  Tue Mar 31, 2009

Thursday, March 26, 2009

A new virus may be set to target computers on April Fool’s Day.

Wired PR News – A new malware threat may prove to be the most destructive one seen in a while. As reported on Yahoo! Tech Buzz, the Conficker C worm is expected to be set to attack on April 1, and has led to the rush of security experts seeking ways to lesson it’s potential impact. As noted in the report, the Conficker was first given widespread attention in January of this year after initially surfacing in the latter part of 2008. It is said to have affected more than nine million computers. The Conficker C is the third version of the malware to be released. Microsoft has reportedly offered a $250,000 reward to those who may have information leading to the worm’s source or writer. Individuals are cautioned to help protect their PCs by taking steps such as updating anti-malware software. 

Call us today to make sure that you have the virus protection you need!

Computer Repair and Solutions for your Home and Business

MAKE SURE YOUR COMPUTER IS NOT AT RISK!