date of April 1 virus conficker aka downadup aka kido latest official released. According to this new type of anti-virus company Kaspersky Russia is different from the previous variants. Conficker download updates to itself from some web sites change. He also uses the local network as a path to obtain updates. And do not forget, conficker have a mechanism to turn off security features.
As we know before, conficker spread using the MS08-067 slit on MsWindows. Users who have not mempatchnya (menambal) cleft is very vulnerable exposed to this virus. Update Kido made in March and began yesterday actively the new system on 1 April 2009 is considered more difficult. What do Kido, with command over 50,000 domain random per day, the criminals make the action difficult to predict. In fact, the computer network of the victim Kido aka Downadup this can be used to perform the attack Distributed Denial of Service (DDoS). In addition, the botnet can be used to perform action data theft and spam to spread.
Following ways to clean the virus conficker, quoted from here:
Cleaning the entire computer and server
1. Install the patch from Microsoft that the rift MS08-067, MS08-068, MS09-001.
2. Make sure that the local administrator account password can not be easily diterka-password must consist of at least 6 characters which is a mix between capital letters and non-capital, numbers and special characters such as punctuation.
3. Turn off features that run the file in a USB flash disk automatically.
Peranti KKiller.exe can be run locally on the computer that is infected or run a remote bantukan with Kaspersky Administration Kit.
To Delete The Local
1. KKiller_v3.4.3.zip Download and extract the package to a folder in the computer that is infected.
2. Run the file KKiller.exe. When the scan is complete, bsia command prompt window appears on the screen. To me, that minimize the window, press any ombol. So that the window is closed automatically, it is suggested KKiller.exe gar run with the parameter "-y".
3. Wait until the scan selesai.Bila Agnitum Outpost Firewall installed on computers that run KKiller.exe, restart after KKiller.exe.
4. Make a full scan on the computer with Kaspersky Anti-Virus.
To Delete the Administration Kit
1. KKiller_v3.4.3.zip Download and extract the contents into a folder.
2. In the console Administration Kit, create installation packages for KKiller.exe. In the package installation, select "Make installation package for speficied executable file." In the box "command line executable file (optional)" any posts of the parameters "-y" to the console window is closed automatically after the process is complete.
3. Create a task for remote installation can be done globally or only a certain group. Run the task. KKiller.exe can be run on all computers in the network.
4. When KKiller.exe work is completed, scan the computer using Kaspersky Anti-Virus.Kalau Agnitum Outpost Firewall is installed on the computer, restart the PC after KKiller.exe used. To obtain additional information, run KKiller.exe with additional parameter "-help".
Clearing the way Newest Virus Conficker
Reviewed by Captain CooL
on Monday, July 27, 2009
Rating: 4.5
0 comments:
Post a Comment