{"id":194,"date":"2009-04-25T07:35:28","date_gmt":"2009-04-25T02:05:28","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=194"},"modified":"2009-04-25T07:35:58","modified_gmt":"2009-04-25T02:05:58","slug":"conficker-virus-%e2%80%93-a-simple-check","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/conficker-virus-%e2%80%93-a-simple-check\/","title":{"rendered":"Conficker Virus \u2013 A simple check"},"content":{"rendered":"<p align=\"justify\"><strong>Conficker<\/strong>, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in October 2008. The worm uses a combination of advanced malware techniques which has made it difficult to counter.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">Experts say it is the <strong><em>worst infection since the SQL Slammer<\/em><\/strong>. Estimates of the number of computers infected range from almost 9 million PCs to 15 million computers, however a conservative minimum estimate is more like 3 million which is more than enough to cause great harm.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><!--more--><\/p>\n<p>Recent estimates of the number of infected computers have been more notably difficult because of changes in the propagation and update strategy of recent variants of the worm.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">The potential scale of infection is large because 30 percent of Windows computers do not have the Microsoft Windows patch released in October 2008 to block this vulnerability.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">Five variants of the Conficker worm are known and have been dubbed Conficker A, B, C, D and E. They were discovered 21 November 2008, 29 December 2008, 20 February 2009, 4 March 2009 and 7 April 2009, respectively.\u00a0<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">The Conficker worm spreads itself primarily through a buffer overflow vulnerability in the Server Service on Windows computers. The worm uses a specially crafted RPC request to execute code on the target computer.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">It receives further instructions by connecting to a server or peer and receiving a binary update. The instructions it receives may include to propagate, gather personal information and to download and install additional malware onto the victim&#8217;s computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe.<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">Joe Stewart from SecureWorks has worked out an easy <strong>EyeChart<\/strong> for a <strong><em>quick check on whether your computer is infected by Conficker<\/em><\/strong>.\u00a0 The EyeChart can be accessed at<\/p>\n<p><a href=\"https:\/\/www.confickerworkinggroup.org\/infection_test\/cfeyechart.html\">https:\/\/www.confickerworkinggroup.org\/infection_test\/cfeyechart.html<\/a>.<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">And in case you are infected, check out the official <strong>Removal Tools<\/strong> at<\/p>\n<p><a href=\"https:\/\/www.confickerworkinggroup.org\/wiki\/pmwiki.php\/ANY\/RepairTools#toc4\">https:\/\/www.confickerworkinggroup.org\/wiki\/pmwiki.php\/ANY\/RepairTools#toc4<\/a><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\">And in case you are not infected, either thank your stars or thank your IT manager for keeping your network well patched.<strong>\u263a<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in October 2008. The worm uses a combination of advanced malware techniques which has made it difficult to counter. \u00a0 Experts say it is the worst infection since the SQL Slammer. Estimates of &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/conficker-virus-%e2%80%93-a-simple-check\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Conficker Virus \u2013 A simple check&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12,10],"tags":[],"class_list":["post-194","post","type-post","status-publish","format-standard","hentry","category-itsec","category-microsoft"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-38","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}