PDA

View Full Version : Conficker Worm- Prepare & Protect!


Moke
03-31-2009, 08:19 PM
Any further info from our girlie geeks would be most appeciated!

No one knows, but we'll probably find out soon.

Or not. As Slate notes, Conficker is scheduled to go "live" on April 1, but whoever's controlling it could choose not to wreak havoc but instead do absolutely nothing, waiting for a time when there's less heat. They can do this because the way Conficker is designed is extremely clever: Rather than containing a list of specific, static instructions, Conficker reaches out to the web to receive updated marching orders via a huge list of websites it creates.

Conficker.C -- the latest bad boy -- will start checking 50,000 different semi-randomly-generated sites a day looking for instructions, so there's no way to shut down all of them. If just one of those sites goes live with legitimate instructions, Conficker keeps on trucking.

Conficker's a nasty little worm that takes serious efforts to bypass your security defenses, but you aren't without some tools in your arsenal to protect yourself.

Your first step should be the tools you already have: Windows Update (http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us),
to make sure your computer is fully patched, and your current antivirus
software, to make sure anything that slips through the cracks is caught.

But if Conficker's already on your machine, it may bypass certain subsystems and updating Windows and your antivirus at this point may not work. If you are worried about anything being amiss -- try booting into Safe Mode, which Conficker prevents, to check -- you should run a specialized tool to get rid of Conficker.

Microsoft offers a web-based scanner (http://onecare.live.com/site/en-us/default.htm?s_cid=sah)(note that some users have reported it crashed their machines; I had no trouble with it), so you might try one of these downloadable options instead: Symantec's Conficker (http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99) (aka Downadup) tool, Trend Micro's Cleanup Engine (http://www.trendmicro.com/download/dcs.asp), or Malwarebytes (http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html).

Conficker may prevent your machine from accessing any of these websites, so you may have to download these tools from a known non-infected computer if you need them. Follow the instructions given on each site to run them successfully. (Also note: None of these tools should harm your computer if you don't have Conficker.)

As a final safety note, all users -- whether they're worried about an infection or know for sure they're clean -- are also wise to make a full data backup today.

What won't work? Turning your PC off tonight and back on on April 2 will not protect you from the worm (sorry to the dozens of people who wrote me asking if this would do the trick). Changing the date on your PC will likely have no helpful effect, either.

And yes, Macs are immune this time out.

Niki
03-31-2009, 08:24 PM
:wtf:

So what am I supposed to so? :slow:

Niki
03-31-2009, 08:25 PM
:cry:

Lisa
03-31-2009, 08:29 PM
Cliff's crazy ass sister was talking about this today.

:stars:

Screw it. If it messes things up, I will reload.

Alie
03-31-2009, 08:30 PM
I'm skeered. I never download those updates :cry:

Niki
03-31-2009, 08:32 PM
I always do. I'm fully updated.

Does that mean I'm safe?

Diamond_lv
03-31-2009, 08:35 PM
Thanks Moke!

:slow: I have Windows One Care for my so called computer security and had an update this weekend, but checked Windows Update again! I need my own Help Desk Network for my home computer!

Moke
03-31-2009, 08:44 PM
I'm updated and I updated my antivirus today. Other than that........so not freaking out. I save everything to my external drive.

Niki
03-31-2009, 09:11 PM
*has procrastinated getting an external drive*

:omg:

Allison
03-31-2009, 09:38 PM
From what I gather, from the email notices my corporate IT guys have sent out, as long as you're updated and your AV is updated - you should be good.

Samantha
03-31-2009, 10:05 PM
well really its just suppose to be a world wide april fools joke which is why it was sent out april 1st however they are sending out warnings as a percausion

Samantha
03-31-2009, 10:13 PM
what my internet/security provider sent
What is the Conficker virus? A new worm virus set to launch April 1 as an April Fool’s joke, but security experts predict that it’s more hype than a serious threat.

Niki
03-31-2009, 10:27 PM
The stuff I've just read says that if you can open the Symantec or McAfee websites, you most likely do not have the worm. If the sites won't load for you...:nono:

Allison
03-31-2009, 10:37 PM
It probably is some sort of joke, but doesn't hurt me to run the updates just to be safe.

Mrs Sarah
03-31-2009, 10:38 PM
Thanks, Moke.

Niki
03-31-2009, 10:39 PM
It probably is some sort of joke, but doesn't hurt me to run the updates just to be safe.

:word:

Mary Ann
03-31-2009, 10:40 PM
I just ran my Kaspersky updates, so I'm good there. Now I guess I need to check for Microsoft updates.