<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; conficker worm</title>
	<atom:link href="http://www.ghacks.net/tag/conficker-worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 03:24:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Test Possible Conficker Infection In Your Web Browser</title>
		<link>http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/</link>
		<comments>http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 13:12:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[computer worm]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker detection]]></category>
		<category><![CDATA[conficker eye chart]]></category>
		<category><![CDATA[conficker worm]]></category>
		<category><![CDATA[remove conficker]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/</guid>
		<description><![CDATA[While the Conficker worm did not have the serious impact many assumed it would have on April 1 it is still a threat as millions of computer systems are infected with it. We covered Conficker worm detection and removal instructions in March and would like to add the easiest way of detecting a possible Conficker [...]]]></description>
			<content:encoded><![CDATA[<p>While the Conficker worm did not have the serious impact many assumed it would have on April 1 it is still a threat as millions of computer systems are infected with it. We covered <a href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/">Conficker worm detection and removal</a> instructions in March and would like to add the easiest way of detecting a possible Conficker infection on a computer system.</p>
<p>One of the traits of the Conficker worm is the blocking of url strings. This includes urls of antivirus companies, Microsoft and support sites that could aid users in removing the Conficker worm from a computer system. Users with the worm cannot open the websites in their web browser anymore and this is the exact concept of the<a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html"> Conficker Eye Chart</a>. It displays six images on the website. Three images from urls that are not blocked by Conficker and three that are blocked.</p>
<p>If the web browser is displaying all six urls it is very likely that Conficker has not infected the computer system. If only the safe three images are displayed an infection with the C variant of Conficker is likely while the display of four images hints at A and B variants of Conficker.</p>
<p><span id="more-11711"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/04/conficker_detection-500x357.jpg" alt="conficker detection" title="conficker detection" width="500" height="357" class="alignnone size-medium wp-image-11710" /></p>
<p>The major benefit of this Conficker detection test is its simplicity. It takes only a web browser and a few seconds to test if the computer system has been infected. It is still a good idea to confirm the findings by using a software detection program which you can find <a href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/">here</a>.</p>

	Tags: <a href="http://www.ghacks.net/tag/computer-security/" title="computer security" rel="tag">computer security</a>, <a href="http://www.ghacks.net/tag/computer-worm/" title="computer worm" rel="tag">computer worm</a>, <a href="http://www.ghacks.net/tag/conficker/" title="conficker" rel="tag">conficker</a>, <a href="http://www.ghacks.net/tag/conficker-detection/" title="conficker detection" rel="tag">conficker detection</a>, <a href="http://www.ghacks.net/tag/conficker-eye-chart/" title="conficker eye chart" rel="tag">conficker eye chart</a>, <a href="http://www.ghacks.net/tag/conficker-worm/" title="conficker worm" rel="tag">conficker worm</a>, <a href="http://www.ghacks.net/tag/remove-conficker/" title="remove conficker" rel="tag">remove conficker</a>, <a href="http://www.ghacks.net/tag/virus/" title="virus" rel="tag">virus</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/" title="Conficker Worm Detection And Removal (March 31, 2009)">Conficker Worm Detection And Removal</a> (8)</li>
	<li><a href="http://www.ghacks.net/2008/09/15/which-programs-should-i-run-to-scan-a-computer-for-malicious-software/" title="Which Programs Should I Run To Scan A Computer For Malicious Software? (September 15, 2008)">Which Programs Should I Run To Scan A Computer For Malicious Software?</a> (13)</li>
	<li><a href="http://www.ghacks.net/2009/05/20/what-you-should-do-after-buying-a-new-computer-system/" title="What You Should Do After Buying A New Computer System (May 20, 2009)">What You Should Do After Buying A New Computer System</a> (18)</li>
	<li><a href="http://www.ghacks.net/2008/11/22/us-military-bans-removable-media-to-stop-computer-worm/" title="US Military Bans Removable Media To Stop Computer Worm (November 22, 2008)">US Military Bans Removable Media To Stop Computer Worm</a> (2)</li>
	<li><a href="http://www.ghacks.net/2007/01/01/test-your-anti-virus-program/" title="Test your Anti-virus program (January 1, 2007)">Test your Anti-virus program</a> (10)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Conficker Worm Detection And Removal</title>
		<link>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/</link>
		<comments>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 11:17:48 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker c]]></category>
		<category><![CDATA[conficker removal]]></category>
		<category><![CDATA[conficker worm]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows software]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worm cleaner]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/</guid>
		<description><![CDATA[By now you might have heard about the latest worm that is plaguing Internet users world wide. It goes by the name of Conficker (or Downadup)and comes in the variants A,B and C with c being the most evolved variant. To put it simple: Conficker uses a Windows vulnerability that was discovered in September 2008 [...]]]></description>
			<content:encoded><![CDATA[<p>By now you might have heard about the latest worm that is plaguing Internet users world wide. It goes by the name of Conficker (or Downadup)and comes in the variants A,B and C with c being the most evolved variant. To put it simple: Conficker uses a Windows vulnerability that was discovered in September 2008 and a patch was released by Microsoft that fixed it. The first worm that used the vulnerability was discovered in November 2008. </p>
<p>Conficker C will initiate a number of processes on infected host systems including opening a random port which is being used in the distribution process of the worm. The worm will then patch the security hole on the computer system that allowed it to attack the system in first place. This prevents other viruses from exploiting the vulnerability while keeping a backdoor open for newer variants of the Conficker worm. The worm will block certain strings from being accessed on the Internet. Domain names making use of those strings cannot be accessed unless the IP is used to do so. Among the strings are various security companies like microsoft, panda or symantec but also generic strings like defender, conficker or anti-. This is to prevent users from accessing websites that contain information and removal instructions about the worm.</p>
<p>While this is surely a nuisance for the user it does mean that the worm itself is not harming the user system in any way other than the methods described above. The real danger comes from the updating mechanism of Conficker C. The worm will try to retrieve new instructions on April 1, 2009. A very sophisticated updating mechanism has been implemented by the author. The worm will generate a list of 50K domain names and append a list of 116 top level domains to them. It will then select 500 randomly from the list and try to connect to them. If new instructions are found on one of the urls it will download them and execute them on the computer system. This process will be repeated every 24 hours.</p>
<p><span id="more-11564"></span>The easiest way of detection is by accessing a site like microsoft.com or symantec.com and comparing the results with accessing the site using the IP addresses (207.46.197.32 and 206.204.52.31). While this usually gives a good indication it is better to check the computer system with tools that have been specifically designed to detect and remove the Conficker variants.</p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/03/conficker_removal-500x167.jpg" alt="conficker removal" title="conficker removal" width="500" height="167" class="alignnone size-medium wp-image-11563" /></p>
<p>A few tools that can be used to detect and remove Conficker variants are <a href="http://download.eset.com/special/EConfickerRemover.exe">ESET Conficker Removal Tool</a>, <a href="ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip">Downadup from F-Secure</a> or KidoKiller by Kaspersky.</p>
<p>Excellent information about Conficker detection and removal instructions are available at <a href="http://isc.sans.org/diary.html?storyid=5860">Sans.org</a>.</p>

	Tags: <a href="http://www.ghacks.net/tag/conficker/" title="conficker" rel="tag">conficker</a>, <a href="http://www.ghacks.net/tag/conficker-c/" title="conficker c" rel="tag">conficker c</a>, <a href="http://www.ghacks.net/tag/conficker-removal/" title="conficker removal" rel="tag">conficker removal</a>, <a href="http://www.ghacks.net/tag/conficker-worm/" title="conficker worm" rel="tag">conficker worm</a>, <a href="http://www.ghacks.net/tag/downadup/" title="downadup" rel="tag">downadup</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a>, <a href="http://www.ghacks.net/tag/worm/" title="worm" rel="tag">worm</a>, <a href="http://www.ghacks.net/tag/worm-cleaner/" title="worm cleaner" rel="tag">worm cleaner</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/22/windows-process-blocker-spkiller/" title="Windows Process Blocker SPKiller (March 22, 2009)">Windows Process Blocker SPKiller</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/03/18/windows-process-blocker/" title="Windows Process Blocker (March 18, 2009)">Windows Process Blocker</a> (9)</li>
	<li><a href="http://www.ghacks.net/2009/04/06/test-possible-conficker-infection-in-your-web-browser/" title="Test Possible Conficker Infection In Your Web Browser (April 6, 2009)">Test Possible Conficker Infection In Your Web Browser</a> (5)</li>
	<li><a href="http://www.ghacks.net/2007/12/21/security-and-privacy-complete-2/" title="Security and Privacy Complete (December 21, 2007)">Security and Privacy Complete</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/17/microsoft-security-essentials-leaks/" title="Microsoft Security Essentials Leaks (June 17, 2009)">Microsoft Security Essentials Leaks</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/31/conficker-worm-detection-and-removal/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
