<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Volk Defense - Security &#38; Software Discussions &#187; worm</title>
	<atom:link href="http://www.volkdefense.com/tag/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.volkdefense.com</link>
	<description>Assisting In Security</description>
	<lastBuildDate>Fri, 23 Jul 2010 00:57:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Conficker Worm Gone? Or Barely Begun?</title>
		<link>http://www.volkdefense.com/2009/04/05/conficker-worm-gone-or-barely-begun/</link>
		<comments>http://www.volkdefense.com/2009/04/05/conficker-worm-gone-or-barely-begun/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 03:48:42 +0000</pubDate>
		<dc:creator>Gerardo</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[antiworm]]></category>
		<category><![CDATA[conficker.d]]></category>
		<category><![CDATA[kaspersky]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.volkdefense.com/?p=122</guid>
		<description><![CDATA[Much panic that has lead many users to leaving their computers off and even disconnecting their Ethernet cables from their computers from the recent Conficker Worm going around, but has... <a class="meta-more" href="http://www.volkdefense.com/2009/04/05/conficker-worm-gone-or-barely-begun/">Read more <span class="meta-nav">&#187;</span></a>]]></description>
			<content:encoded><![CDATA[<a href="http://www.volkdefense.com/2009/04/05/conficker-worm-gone-or-barely-begun/" title="Link to Conficker Worm Gone? Or Barely Begun?"><img class="wppt_float_left" src="http://www.volkdefense.com/wp-content/uploads/wp-post-thumbnail/qEisd.jpg" alt="" title="" width="540" height="250" /></a><p>Much panic that has lead many users to leaving their computers off and even disconnecting their Ethernet cables from their computers from the recent Conficker Worm going around, but has this worm stopped going around or has it barely begun it destruction to infect many users? This called for many fast released patches by companies such as Microsoft Operating System(s) and also mostly all AntiVirus vendors such as Symantec, AVG, Kaspersky, Trend Micro, etc. But before you think about the virus, how do you know if you haven&#8217;t been infected by it already?<span id="more-122"></span>Finding out if you are infected can be really easy, because the worm does a lot of system changes that prevent you from seeing certain keywords in sites. This is a detailed list of the Conficker Worm:</p>
<p><strong>Name of Security Risk:</strong></p>
<div>Worm:/Conficker.D (Microsoft)</div>
<div>Win32/Conficker.worm.88064 (AhnLab)</div>
<div>Win32.Worm.Downadup.Gen (BitDefender)</div>
<div>Win32/Conficker.C (CA)</div>
<div>Win32/Conficker.X (ESET)</div>
<div>Trojan.Win32.Pakes.ngs (Kaspersky)</div>
<div>W32/Conficker.worm.gen.c (McAfee)</div>
<div>W32/Conficker.D.worm (Panda)</div>
<div>W32/Confick-G (Sophos)</div>
<div>W32.Downadup.C (Symantec)</div>
<p><strong>Summary of what it does:</strong></p>
<div id="attachment_135" class="wp-caption alignleft" style="width: 310px"><a href="http://www.volkdefense.com/wp-content/uploads/2009/04/confickerusmap.jpg"><img class="size-medium wp-image-135" title="confickerusmap" src="http://www.volkdefense.com/wp-content/uploads/2009/04/confickerusmap-300x149.jpg" alt="Conficker US Infection" width="300" height="149" /></a><p class="wp-caption-text">Conficker US Infection</p></div>
<p>Win32/Conficker.D is  a variant of <a href="http://www.microsoft.com/security/portal/Entry.aspx?name=Win32/Conficker">Win32/Conficker</a>.  Conficker.D infects the local computer, terminates services, blocks access to  numerous security related Web sites and downloads arbitrary code.  Conficker.D can relay command instructions to other Conficker.D infected  computers via built-in peer-to-peer (P2P) communication. This variant does not  spread to removable drives or shared folders across a network (as with previous  variants). Conficker.D is installed by previous variants of  Win32/Conficker.</p>
<p>Other variants of  Win32/Conficker  infect computers across a network by exploiting a vulnerability in the Windows  Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it  could allow remote code execution when file sharing is enabled. It may also  spread via removable drives and weak administrator passwords.</p>
<p><strong>System Changes</strong></p>
<p>Users may not be able to run applications containing the following strings:</p>
<table style="height: 58px;" border="0" cellspacing="0" cellpadding="0" width="578">
<tbody>
<tr>
<td>autoruns</td>
<td>avenger</td>
<td>confick</td>
<td>downad</td>
<td>filemon</td>
<td>gmer</td>
<td>hotfix</td>
</tr>
<tr>
<td>mrt.</td>
<td>mrtstub</td>
<td>ms08-06</td>
<td>procexp</td>
<td>procmon</td>
<td>regmon</td>
<td>regmon</td>
</tr>
<tr>
<td>unlocker</td>
<td>wireshark</td>
<td>klwk</td>
<td>mbsa.</td>
<td>kido</td>
<td>kb958</td>
<td>tcpview</td>
</tr>
<tr>
<td>kb890</td>
<td>sysclean</td>
</tr>
</tbody>
</table>
<p>Users may not be able to browse certain security-related Web sites with URLs  that contain any of the following strings:</p>
<table style="height: 233px;" border="0" cellspacing="0" cellpadding="0" width="578">
<tbody>
<tr>
<td>agnitum</td>
<td>ahnlab</td>
<td>anti-</td>
<td>antivir</td>
<td>arcabit</td>
<td>avast</td>
<td>avgate</td>
</tr>
<tr>
<td>avira</td>
<td>bothunter</td>
<td>castlecops</td>
<td>ccollomb</td>
<td>centralcommand</td>
<td>clamav</td>
<td>comodo</td>
</tr>
<tr>
<td>computerassociates</td>
<td>conficker</td>
<td>cpsecure</td>
<td>cyber-ta</td>
<td>defender</td>
<td>downad</td>
<td>drweb</td>
</tr>
<tr>
<td>dslreports</td>
<td>emsisoft</td>
<td>esafe</td>
<td>eset</td>
<td>etrust</td>
<td>ewido</td>
<td>f-prot</td>
</tr>
<tr>
<td>f-secure</td>
<td>fortinet</td>
<td>free-av</td>
<td>freeav</td>
<td>gdata</td>
<td>grisoft</td>
<td>hackerwatch</td>
</tr>
<tr>
<td>hacksoft</td>
<td>hauri</td>
<td>ikarus</td>
<td>freeav</td>
<td>gdata</td>
<td>grisoft</td>
<td>hackerwatch</td>
</tr>
<tr>
<td>jotti</td>
<td>k7computing</td>
<td>kaspersky</td>
<td>kido</td>
<td>malware</td>
<td>mcafee</td>
<td>microsoft</td>
</tr>
<tr>
<td>mirage</td>
<td>msftncsi</td>
<td>msmvps</td>
<td>mtc.sri</td>
<td>networkassociates</td>
<td>nod32</td>
<td>norman</td>
</tr>
<tr>
<td>norton</td>
<td>onecare</td>
<td>panda</td>
<td>pctools</td>
<td>prevx</td>
<td>ptsecurity</td>
<td>quickheal</td>
</tr>
<tr>
<td>norton</td>
<td>onecare</td>
<td>panda</td>
<td>pctools</td>
<td>prevx</td>
<td>ptsecurity</td>
<td>quickheal</td>
</tr>
<tr>
<td>removal</td>
<td>rising</td>
<td>rootkit</td>
<td>safety.live</td>
<td>securecomputing</td>
<td>sophos</td>
<td>spamhaus</td>
</tr>
<tr>
<td>spyware</td>
<td>sunbelt</td>
<td>symantec</td>
<td>technet</td>
<td>threat</td>
<td>threatexpert</td>
<td>trendmicro</td>
</tr>
<tr>
<td>trojan</td>
<td>virscan</td>
<td>virus</td>
<td>wilderssecurity</td>
<td>windowsupdate</td>
</tr>
</tbody>
</table>
<p>Users may experience a Web browser time-out error when attempting to access URLs  containing the following strings:</p>
<table style="height: 58px;" border="0" cellspacing="0" cellpadding="0" width="578">
<tbody>
<tr>
<td>avg.</td>
<td>avp.</td>
<td>bit9.</td>
<td>ca.</td>
<td>cert.</td>
<td>gmer.</td>
<td>kav.</td>
</tr>
<tr>
<td>llnw.</td>
<td>llnwd.</td>
<td>msdn.</td>
<td>procexp</td>
<td>msft.</td>
<td>nai.</td>
<td>sans.</td>
</tr>
</tbody>
</table>
<p>If you are unable to access any websites such as Symantec or Microsoft&#8217;s Website or even the Windows Update on your desktop, chances are that you are infected by the Conficker Worm.</p>
<p>Removing the infection can be really tricky, you can visit different vendors to your liking (if you so happen to like Symantec over Kaspersky, or Kaspersky over TrendMicro, etc, etc.). Here are some links where you can get removal programs to get rid of the worm, however you will have to visit with an uninfected computer, if you are reading this you shouldn&#8217;t be infected due to certain words I&#8217;ve used in this post that the Worm blocks:</p>
<ul>
<li><a href="http://www.symantec.com/norton/theme.jsp?themeid=conficker_worm#infected" target="_blank">Symantec Conficker Removal Tool </a></li>
<li><a href="http://support.microsoft.com/kb/962007" target="_blank">Microsoft Removal Tool</a></li>
<li><a href="http://www.sophos.com/products/free-tools/conficker-removal-tool.html">Sophos Removal Tool</a></li>
<li><a href="http://www.trendmicro.com/ftp/products/pattern/spyware/fixtool/SysClean-WORM_DOWNAD.zip" target="_blank">TrendMicro Removal Tool</a></li>
<li><a href="http://data2.kaspersky-labs.com:8080/special/KKiller_v3.4.1.zip" target="_blank">Kaspersky Removal Tool</a></li>
</ul>
<p>You should use these removal tools to take off Conficker Variants, especially made for the Newest created one, off your computer. You would have to download this tool using an uninfected computer, then apply it on infected computer.</p>
<p>Why has the Conficker Worm been so &#8220;important&#8221; to pay attention to over the past few days? Because of several things:</p>
<ul>
<li>It avoids detection, it is &#8220;evolving&#8221; as we speak</li>
<li>It uses P2P to update itself from its creators</li>
<li>Mass infection has already occurred</li>
<li>Encryption on the worm is very strong and hard to crack</li>
</ul>
<p>With so much talk going around with the Conficker Worm, it has been already <a href="https://www.virustotal.com/analisis/2be239a72ff7431595269526273c747c" target="_blank">detected by most anti viruses</a>, but the threat is still going on and on and still infecting more users online. There has also been rumors online about a possible conspiracy with the virus. Since Microsoft was pretty quick with a patch for their system after the virus went global, it raised <a href="http://www.pcworld.com/article/162477/conficker_worm_not_finished_yet.html" target="_blank">some suspicious about Microsoft&#8217;s</a> possible plan to take down pirated versions of Microsoft Windows. Whether that is true or not? You decide.</p>
<p>With the Conficker already detected on most anti viruses, many IT researchers haven&#8217;t been able to block all incoming traffic from Conficker. If conficker is updated or recieves further intructions, that capability could pass between infected machines without the need of a server or website. This is done with P2P (Peer-to-Peer) networking instead which allows to file share faster than if they had to communicate with a main server. This makes the Conficker Worm update much faster on the infected machine and makes it harder to block and remove off your system.</p>
<p>Many of you shouldn&#8217;r worry. Conficker is only a threat if you computer does not have the latest security patches from Microsoft and is up-to-date with an antivirus program. Stay safe everyone!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.volkdefense.com/2009/04/05/conficker-worm-gone-or-barely-begun/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
