Conficker dossier
Name of the threat: Conficker
Alias: Conflicker, Confiker
Year of Birth: 2008
Buggies: Downup, Downadup, Kido
Faith: Virus
Distinguished features:
Conficker A uses HTTP for its distribution and downloads itself from trafficconverter.biz. Confickers A, B, C, D are downloaded daily from any of 250 pseudorandom domains over 8 top-level domains. Conficker B came out on the Web stage on December,29, 2009. Conficker B creates DLL-based AutoRun trojan on attached removable drives. Conficker B and Conficker C use dictionary attack on ADMIN shares as their infection vector. Conficker D hasn’t its own infection vector alike Hepatite D, but Conficker D patches MS08-067 to open reinfection backdoor in Server service and creates named pipe to receive URL from remote host, then downloads from URL. Blocking DNS lookups and disabling autoupdate can help to prevent your computer against Conficker B and C, but Conficker D does an in-memory patch of DNSAPI.DLL to block lookups of anti-malware related web sites.
Record of service:
- Conficker agitated network death in many business and state organizations.
- The French Navy was attacked on the 15th of January, 2009 and was hardly recovered after several aircrafts were forced to land on several airbases in France.
- The UK Ministry of Defence reported about the Conficker worm in their administative networks.
- Various Royal Navy warships and Royal Navy submarines, and hospitals across the city of Sheffield turned to be down under Conficker’s attack.
- The unified armed forces of the Federal Republic of Germany reported about Conficker virus in their network on 2 February of 2009.
- British House of Commons has been attacked with Conficker a little while since, as British newspaper reports.
Victims: MS08-067 vulnerability in Server service is the main target of Conficker A and there is no simple way to escape this type of Conficker.
Sentence: Complete Conficker Elimination
Conficker Removal Tool
Let's proceed to the main issue of the agenda - Conficker removal. There are two best ways to remove Conficker:
- Get rid of Conficker and Downup together with all known malware with the help of True Sword
- Download Conficker Removal Tool, created specially against Conficker and Downup invasion





Comments
Write New Comment ▼
Write New Comment
Sorry! This knol's owner(s) have blocked you from editing, making suggestions, or commenting here.