
Conficker – How do I protect myself?—ESET Knowledgebase. Preventing Infection.
A - Download Microsoft security patches. If you do not wish to download all Windows updates but want to ensure that you are at least protected against the Win. Conficker threats, download and install the patches (KB9. KB9. 57. 09. 7 and KB9.
Microsoft Security Bulletins: B - Disable Autorun and Autoplay (Windows XP and Windows Vista)You may want to disable the Autorun and Autoplay features in your Windows system to prevent malicious software makers from abusing these security flaws. USB drives and other removable media, which are accessed by the Autorun/Autoplay functionalities each time (by default) you connect them to your computer, are the most frequently used virus carriers these days.
Delete Conficker.C from Windows Vista : Take Down Conficker.C. Remove Malware Tips & Guidelines >. Also detected as. Remove difficult malware; Avoid tech support phone scams; See and search the latest threats; Find answers to other. Detect and Remove the Conficker Worm (Virus) Windows Guides reader littlelooloo asked the following: I had a question about this worm that is supposed to wreak havoc. Consolidated information customers can use to protect their systems and recover infected systems. Windows Vista; Security & privacy; 1272 views How to remove conficker/sandbox virus. Hi, I am pretty sure that I.
W32/Conficker worm is a computer worm/virus that spreads itself by attempting to make numerous connections to computers across the network, seeking systems that do. Conficker Removal Conficker: How to prevent it and remove it. The Conficker/Downadup worm, which first surfaced in 2008.
Microsoft Windows Autorun and Autoplay are features that were at first intended to simplify running CD content by automatically: (i) executing the Autorun. Autorun vulnerability(ii) opening a pop- up window with available actions (some of which may be hostile triggers taken over from a malicious Autorun. Autoplay vulnerability. Some terms used in the steps below may slightly differ, depending on your browser.
Disable. Autorun. Click Save. Confirm any prompts to save the registry file. Click OK to finish. While this disables the Autorun functionality completely, the Autoplay feature will continue to pop- up, however, it will exclude the potentially dangerous Autorun. You must keep in mind that these preventive security measures do not eradicate potential malware infections.
We recommend strict caution when opening/executing/clicking any unknown files! If double- clicking the file does not run bring up the Registry editor dialog window, right- click the file icon, select Properties and edit the filename on the General tab to ensure the last four strings of the filename are . Confirm any prompts to save your changes.

B2 - How to re- enable Autorun and Autoplay (Windows XP and Windows Vista). If you need to undo the changes you have made following the instructions in section B (above) right- click this link to download the Reenable. Autorun. reg file and repeat the instructions from section B (above) only this time use the Reenable. Autorun. reg file. Install all patches. Note that the infiltration can spread through shared folders.(i.) Press CTRL+ALT+DELETE, and then click Change password..(ii.) Type your old password, type your new password, type your new password again to confirm it, and then press ENTER. If you don't have an ESET product (3.
PC) and run our free stand- alone cleaner: http: //download. ESETConficker. Cleaner. To verify that the stand- alone cleaner removed the Conficker threat, rerun the stand- alone cleaner and then run a scan with your ESET product. After successfully running the ESET stand- alone cleaner, we recommend that you read the following Microsoft article for information about important security patches and recommended group changes.

If the ESET stand- alone cleaner does not fully remove the Conficker threat, the Microsoft article above also contains manual Conficker removal instructions. For maximum protection against future threats, make sure your operating system is patched according to Microsoft's recommendations and that your ESET product is up to date.
Important! To find further information on protecting yourself against the Conficker worm please refer to our ESET blog entry. Cleaning Steps (Network). Use NMap to locate infected machines.
If you suspect that a Conficker infection is in place on computers in your network, you can use the free utility NMap to detect infected clients using the following commands: To scan your network: nmap - PN - T4 - p. However, Microsoft Windows Server 2.
Audit Policy . This is the culprit, or one of the culprits, that is trying to infect other computers. If Conficker is still showing threats after all machines are patched, then there is either an unpatched machine still remaining or ESET is not installed and updated on a machine.
Worm: Win. 32/Conficker. BInstallation. Worm: Win. Conficker. B tries to copy itself in the Windows system folder as a hidden DLL file using a random name.
If it fails, it can then try to copy itself with the same parameters in the following folders: It creates the following registry entry to ensure that its dropped copy is run every time Windows starts: In subkey: HKCU\Software\Microsoft\Windows\Current. Version\Run. Sets value: . It then tries to connect to the target PC using each user name and the following weak passwords: 0. Adminadminadminadministratoranythingasddsaasdfghasdsaasdzxcbackupboss. PCcontrollercookiecustomerdatabasedefaultdesktopdomainexampleexchangeexplorerfilefilesfoofoobarfoofooforeverfreedomfuckgameshome. Internetintranetjobkillerletitbeletmein.
Loginlotuslove. 12. Passwordprivatepublicpw. If Win. 32/Conficker. B successfully accesses the target PC, for example, if a combination of any of the user names and one of the above passwords gives the worm write privileges to the PC, it copies itself to an accessible admin share as ADMIN\System. Remote scheduled job. After infecting a PC remotely, Win.
Conficker. B creates a remotely schedule job with the command rundll. Mapped and removable drives. Worm: Win. 32/Conficker.
B can drop a copy of itself in all mapped and removable drives using a random file name. The worm creates a folder in the root of these drives named RECYCLER (in Windows XP and previous versions, the folder RECYCLER references the Recycle Bin). Next, the worm copies itself as the following: < drive: > \RECYCLER\S- %d- %d- %d- %d%d%d- %d%d%d- %d%d%d- %d\< random letters>. Where %d is a randomly chosen letter.
The worm also drops a corresponding autorun. Autoplay is enabled.
This autorun. inf file is detected as Worm: Win. Conficker. B! inf. The image below illustrates how a user could potentially launch the worm when accessing an infected share: Note that the language in the first option suggests the user could 'Open folder to view files' however the option is under 'Install or run program', an indication that opening the folder will actually run an application. Another hint that the action is to run the worm is the text 'Publisher not specified'. The highlighted choice under 'General options' in the image above would let a user to view the share and not run the worm copy.
MS0. 8- 0. 67 HTTP 'call back'Worm: Win. Conficker. B spreads to PCs that are not yet patched against a vulnerability in the Windows Server service (SVCHOST. EXE). If the vulnerability is successfully exploited, the worm instructs the target PC to download a copy of the worm from the host PC via HTTP protocol using the random port between 1. The vulnerability is documented in Microsoft Security Bulletin MS0. Payload. Changes system settings.
Worm: Win. 32/Conficker. B changes system settings so that the user cannot view hidden files. It does this by changeing the following registry entry: In subkey: HKLM\SOFTWARE\Microsoft\Windows\Current.
Version\explorer\Advanced\Folder\Hidden\SHOWALLSets value: . The dropped file is detected as Trojan: Win. NT/Conficker. B. Disables TCP/IP tuning, stops and disables services. Win. 32/Conficker. B disables Windows Vista TCP/IP auto- tuning by running the following command: netsh interface tcp set global autotuning=disabled.
This worm stops several important services, like the following: Windows Security Center Service (wscsvc) – notifies users of security settings (for example, Windows update, Firewall and Anti. Virus)Windows Update Auto Update Service (wuauserv)Background Intelligence Transfer Service (BITS) – used by Windows Update to download updates using idle network bandwidth. Windows Defender (Win. Defend)Error Reporting Service (ersvc) – sends error reports to Microsoft to help improve user experience. Windows Error Reporting Service (wersvc)Win. Conficker. B deletes the registry key for Windows Defender, disabling it from running when the system starts.
In subkey: HKLM\Software\Microsoft\Windows\Current. Version\Run. Deletes value: . The generated URL has a domain name that is based on the current system date. It uses one of the following top level domains.
For example, aaovt. The generated domain name is first converted to the dot notation, for example, aaovt. This generated IP address is then used for the URL, according to the following pattern: http: //< pseudo- random generated IP> /search? Some examples of the constructed URLs are as follows: aaovt.
It checks the system date if it is January 1, 2. It also checks the following websites for the date, presumably for verification: baidu. Additional Information. The name of this threat was derived by selecting fragments of the domain 'trafficconverter. Worm: Win. 32/Conficker. A: (fic)(con)(er) => (con)(fic)(+k)(er) => conficker.
Analysis by Jireh Sanico.