Confiker Worm nice April 1st prezzie (not)

Nope this not an April fools joke (later) :slight_smile:
Set to morph for a fun day today, on networks etc.

What does it do??

Confiker disables system restore, blocks access to security websites, and downloads additional malware to infected machines and a lot of other stuff.

How not to get it.
Make sure you have applied the patch(s) from M/Soft
http://www.microsoft.com/technet/security/Bulletin/MS08-068.mspx

Prevention better than cure :slight_smile:
Disable autorun for flash-floppy-thumb-CD drives etc etc.
If you use OpenDNS :slight_smile: then no problems as the infected sites are blocked.
Make sure your AntiVirus/Malware tools etc are up to date.

How do I know I have it ??
Try going to antivirus sites e.g. AVG, ETES, McAffee from you browser and if you can’t get there you may have the worm

OMFG I think I have it :slight_smile:

Removal of Win32/Conficker

  1. Disconnect the infected computer from the network and the Internet.
  2. Use an uninfected PC to download the respective Windows patches from the following sites: MS08-067 , MS08-068 a MS09-001 .
  3. Reset your system passwords to admin accounts using more sophisticated ones.
  4. Download an one-off ESET application (again, using a non-infected PC) which will remove the worm. http://download.eset.com/special/EConfickerRemover.exe
  5. Install the updated anti-virus program.
  6. Re-connect the PC to the network and the Internet.

Mags.