Nope this not an April fools joke (later)
Set to morph for a fun day today, on networks etc.
What does it do??
Confiker disables system restore, blocks access to security websites, and downloads additional malware to infected machines and a lot of other stuff.
How not to get it.
Make sure you have applied the patch(s) from M/Soft
http://www.microsoft.com/technet/security/Bulletin/MS08-068.mspx
Prevention better than cure
Disable autorun for flash-floppy-thumb-CD drives etc etc.
If you use OpenDNS then no problems as the infected sites are blocked.
Make sure your AntiVirus/Malware tools etc are up to date.
How do I know I have it ??
Try going to antivirus sites e.g. AVG, ETES, McAffee from you browser and if you canβt get there you may have the worm
OMFG I think I have it
Removal of Win32/Conficker
- Disconnect the infected computer from the network and the Internet.
- Use an uninfected PC to download the respective Windows patches from the following sites: MS08-067 , MS08-068 a MS09-001 .
- Reset your system passwords to admin accounts using more sophisticated ones.
- Download an one-off ESET application (again, using a non-infected PC) which will remove the worm. http://download.eset.com/special/EConfickerRemover.exe
- Install the updated anti-virus program.
- Re-connect the PC to the network and the Internet.
Mags.