Author Topic: Conficker Judgement Day on April 1st  (Read 1786 times)

0 Members and 1 Guest are viewing this topic.

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 7064
Conficker Judgement Day on April 1st
« on: March 24, 2009, 08:20:26 PM »
Bits from Bill
If your machine doesn't already have all the Windows security patches installed, I'd unplug from the Internet on April Fools Day.
Getting a new computer?  If a new un-patched computer arrives on that day I'd wait until the 2nd before connecting it to the Internet.


Complete Article HERE

.....and don't forget, because of time zones, the real danger begins March 31.  ;)
« Last Edit: March 25, 2009, 10:57:36 AM by Bugbatter »



Microsoft MVP - Consumer Security

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 7064
Re: Conficker Judgement Day on April 1st
« Reply #1 on: March 29, 2009, 08:47:58 PM »
In case you missed this evening's CBS report on Conficker, here it is:

The Conficker Worm: What Happens Next?
60 Minutes: Computer Worm Could Receive New Instructions On April 1
http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053_page3.shtml

Thank you Corrine  :)

Microsoft MVP - Consumer Security

Offline Dragan Glas

  • Technical Staff
  • Bronze Member
  • Posts: 61
Re: Conficker Judgement Day on April 1st
« Reply #2 on: March 30, 2009, 06:34:52 PM »
Greetings,

This may prove of interest to the "whitehat" community:

Busted! Conficker's tell-tale heart uncovered

Kindest regards,

Dragan Glas
Quote
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 7064
Re: Conficker Judgement Day on April 1st
« Reply #3 on: March 30, 2009, 07:41:35 PM »
If you need malware removal tools type the URL of your vendor of choice directly into the browser bar and use links on their website. Do not rely on Google search results at this time, as they may have been “optimised”.

Careful what you click on, these Google results are loaded!

Complete Article Here:
http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/

Microsoft MVP - Consumer Security

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 7064
Re: Conficker Judgement Day on April 1st
« Reply #4 on: March 30, 2009, 08:38:38 PM »
      
Sophos Video: Conficker and April 1st

http://www.sophos.com/blogs/gc/g/2009/03/31/video-conficker-april-1st-fuss/

Microsoft MVP - Consumer Security

Offline faith_michele

  • Anti - Phishing Staff
  • Gold Member
  • Posts: 1947
    • A Beacon of Light
Re: Conficker Judgement Day on April 1st
« Reply #5 on: April 01, 2009, 03:24:59 AM »
Here is another removal tool from Sunbelt (free).

Quote
Sunbelt Conficker/Downadup Removal Tool

Version: 1.2, updated: 3/24/2009

The Sunbelt Conficker/Downadup Removal Tool can be used to detect and clean the majority of Conficker/Downadup variants from infected client PCs. It can be run either as a standalone removal tool or as a supplement to VIPRE and CounterSpy.

To do its job, this removal tool must be installed and run on the actual PC that is infected; it cannot clean the worm remotely across a network.

To use the removal tool (SSClean.exe) on an infected PC, do the following:

1. Unzip the file SSClean.exe from Conficker_SSClean.zip into a familiar folder (e.g. My Documents) on an infected PC.
2. Disconnect the infected PC from the network.
3. Run SSClean.exe and click "OK" to begin scanning the system.
4. Reboot the PC when prompted by SSClean.
5. After rebooting run SSClean.exe for a second time.
6. Reboot the PC again as prompted by SSClean.

At this point the PC should be free of the Conficker/Downadup worm. If you continue to see signs of infection, please contact Sunbelt Support for assistance.

Note: You should run SSClean twice to ensure a full removal of the worm. If SSClean crashes while scanning the infected system, simply restart SSClean and scan again.

http://www.sunbeltsecurity.com/DownLoads.aspx
Microsoft Consumer Security MVP, July 2007-June 2010

"Fight your fights, find the grace in all the things that you can't change and help somebody, if you can." Van Zant

A Beacon of Light

Offline AbuIbrahim12

  • Security Expert
  • Bronze Member
  • Posts: 260
    • my website
Re: Conficker Judgement Day on April 1st
« Reply #6 on: April 01, 2009, 06:32:34 AM »
Has the Conficker virus turned out to be an anticipated April fool's day prank after all?

As the April fool's day eve has gone by, there aren't any reports of any malicious action having taken place. However, experts are saying that it may not be the time yet to lay back and relax....

http://www.techtree.com/India/News/April_1_is_Here_Wheres_Conficker/551-100668-582.html
http://www.efluxmedia.com/news_Confickerc_April_1_Activation_Goes_By_Quietly_36448.html

A lot has already been written about Conficker. There had been excellent analysis reports published by SRI, The Honeynet Project and others. Vinay Mahadik and I would like to present some findings on the network aspects of the Conficker.C behavior.

We setup a small testbed that had a machine infected with Conficker.C in a controlled environment; and another Linux box that was customized for packet mangling. This enabled us to intercept or mangle the packets exchanged between the infected machine and the outside world. We monitored the activity of the infected host over several days. We classify the test into two phases: Pre- April 1st and the April 1st phase.
....

Full article:  http://www.trustedsource.org/blog/216/ConfickerC-Over-The-Wire

« Last Edit: April 01, 2009, 06:39:07 AM by AbuIbrahim12 »
My Blog    Startups@Ease

"if everyone had to think outside the box, maybe it was the box that needed fixing."
-- Malcolm Gladwell on Mckinsey & Company

Offline AbuIbrahim12

  • Security Expert
  • Bronze Member
  • Posts: 260
    • my website
Re: Conficker Judgement Day on April 1st
« Reply #7 on: April 01, 2009, 06:43:20 AM »
Removal tools from other vendors:
Sophos:  http://www.sophos.com/support/knowledgebase/article/54457.html
Kaspersky:  http://support.kaspersky.com/faq/?qid=208279973
ESET:   http://www.eset.eu/encyclopaedia/conficker_aa_trojan_win32_agent_bbof_w32_downadup_b_w32_conficker_worm_gen_a
F-secure:   http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml
Symantec:   http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99
Mcafee:   http://majorgeeks.com/McAfee_AVERT_Stinger_Conficker__d6157.html
Trendmicro:  https://securecloud.com/support/sysclean
Ahnlab:  http://global.ahnlab.com/global/file_removeal_down.jsp?filename=12371830475821&down_filename=v3conficker.zip
MSRT:   http://www.microsoft.com/security/malwareremove/default.mspx

More info:
http://isc.sans.org/diary.html?storyid=5860
My Blog    Startups@Ease

"if everyone had to think outside the box, maybe it was the box that needed fixing."
-- Malcolm Gladwell on Mckinsey & Company

Offline quietman7

  • Microsoft® MVP
  • Malware Removal Mentors
  • Silver Member
  • Posts: 1078
Re: Conficker Judgement Day on April 1st
« Reply #8 on: April 01, 2009, 11:14:45 AM »
There are reports of some spam "April Fools" hoaxes circulating attempting to alarm users.
http://www.f-secure.com/weblog/archives/00001645.html
http://blog.trendmicro.com/strange-april-foolsd-day-prank/
Microsoft MVP - Consumer Security 2007-2013

Offline faith_michele

  • Anti - Phishing Staff
  • Gold Member
  • Posts: 1947
    • A Beacon of Light
Re: Conficker Judgement Day on April 1st
« Reply #9 on: April 08, 2009, 04:22:08 AM »
Interesting -

Conficker Fears spread fake AV products -

Gary Warner, 7 April 2009

http://garwarner.blogspot.com/2009/04/conficker-fears-spread-fake-av-products.html
Microsoft Consumer Security MVP, July 2007-June 2010

"Fight your fights, find the grace in all the things that you can't change and help somebody, if you can." Van Zant

A Beacon of Light