date of April 1 virus conficker aka downadup aka kido latest official released. According to this new type of anti-virus company Kaspersky Russia is different from the previous variants. Conficker download updates to itself from some web sites change. He also uses the local network as a path to obtain updates. And do not forget, conficker have a mechanism to turn off security features.
As we know before, conficker spread using the MS08-067 slit on MsWindows. Users who have not mempatchnya (menambal) cleft is very vulnerable exposed to this virus. Update Kido made in March and began yesterday actively the new system on 1 April 2009 is considered more difficult. What do Kido, with command over 50,000 domain random per day, the criminals make the action difficult to predict. In fact, the computer network of the victim Kido aka Downadup this can be used to perform the attack Distributed Denial of Service (DDoS). In addition, the botnet can be used to perform action data theft and spam to spread.
Following ways to clean the virus conficker, quoted from here:
Cleaning the entire computer and server
1. Install the patch from Microsoft that the rift MS08-067, MS08-068, MS09-001.
2. Make sure that the local administrator account password can not be easily diterka-password must consist of at least 6 characters which is a mix between capital letters and non-capital, numbers and special characters such as punctuation.
3. Turn off features that run the file in a USB flash disk automatically.
Peranti KKiller.exe can be run locally on the computer that is infected or run a remote bantukan with Kaspersky Administration Kit.
To Delete The Local
1. KKiller_v3.4.3.zip Download and extract the package to a folder in the computer that is infected.
2. Run the file KKiller.exe. When the scan is complete, bsia command prompt window appears on the screen. To me, that minimize the window, press any ombol. So that the window is closed automatically, it is suggested KKiller.exe gar run with the parameter "-y".
3. Wait until the scan selesai.Bila Agnitum Outpost Firewall installed on computers that run KKiller.exe, restart after KKiller.exe.
4. Make a full scan on the computer with Kaspersky Anti-Virus.
To Delete the Administration Kit
1. KKiller_v3.4.3.zip Download and extract the contents into a folder.
2. In the console Administration Kit, create installation packages for KKiller.exe. In the package installation, select "Make installation package for speficied executable file." In the box "command line executable file (optional)" any posts of the parameters "-y" to the console window is closed automatically after the process is complete.
3. Create a task for remote installation can be done globally or only a certain group. Run the task. KKiller.exe can be run on all computers in the network.
4. When KKiller.exe work is completed, scan the computer using Kaspersky Anti-Virus.Kalau Agnitum Outpost Firewall is installed on the computer, restart the PC after KKiller.exe used. To obtain additional information, run KKiller.exe with additional parameter "-help".
Home » Posts filed under worm
Worm Downadup, mem-block sites in Antivirus
In fact since a few days this opportunity to read / get information about the worm Downadup on some blogs about the security / virus / antivirus, but I leave it because the news only dikira normal worm. But the fact that many proclaim about this worm because the worm was "terrible" and sophisticated.
Based on estimates of F-Secure, a new worm variant has been menginfeksi almost 9 million computers in just 4 days time. Amount not less for the long worm that has not appeared.
Original name is Worm Worm: W32/Downadup.gen have different names and aliases, such as: W32/Conficker.worm.gen (Symantec), Mal / Conficker (Sophos), Worm: Win32/Conficker (Microsoft). In addition, also known by the name Conflicker and Kido (example name: Worm: W32/Downadup.gen! A, Net-Worm.Win32.Kido.ih). This category includes Worm Malware running on Windows 32-bit, that is called the W32.
Distribution of worm
The spread of this worm through various ways, such as the Network / network share or on a weak password, can also be spread by creating a file autorun.inf which triggered the copykan to Flashdisk USB (drive) or other removable media. So should the windows autorun feature is turned off to prevent the addition of various other viruses.
world-map
Worm exploit this rift security for Windows menginfeksi victims, like the previous article What's with the Windows Security Update MS08-067. Worm will create a folder with a random name in the directory RECYCLER (the Recycle Bin is used to store the file that was deleted) also duplicate themselves in various other places.
Effect Downadup Worm
And that this may make me write this article, some visitors ebsoft written comments that they can not open the antivirus sites, and may cause this is a worm.
This worm is able to change / add a function of internal windows (TCP) to block access to sites security (security / antivirus), with a filter that has the characters address / text specific. And to eliminate the effect is not easy, because it may be spelled already low level programming level.
Worm is designed to protect themselves from detection by using anti-virus techniques that are used infrequently, protect themselves from the effort to remove, turn off windows update, restore point prior to infection, kill a certain network traffic, to optimize the features of Windows Vista to facilitate the distribution, is able to inject explorer . exe, svchost.exe and services.exe and other.
Sites on the block quite a lot, including the web using the text as follows (in the block can always display the message or Time Out when opening the site):
* Virus
* Spyware
* Malware
* Rootkit
* Defender
* Microsoft
* Symantec
* Norton
McAfee *
* Trendmicro
* Sophos
* Panda
* Etrust
* F-secure
* Kaspersky
* F-Prot
* NOD32
* Eset
* Grisoft
* Avast
* Avira
* Comodo
* Clamav
* Norman
* Pctools
* Rising
* Sunbelt
* Threatexpert
* Wilderssecurity
* Windowsupdate
* AVP
* Avg
It also sites other security.
Based on estimates of F-Secure, a new worm variant has been menginfeksi almost 9 million computers in just 4 days time. Amount not less for the long worm that has not appeared.
Original name is Worm Worm: W32/Downadup.gen have different names and aliases, such as: W32/Conficker.worm.gen (Symantec), Mal / Conficker (Sophos), Worm: Win32/Conficker (Microsoft). In addition, also known by the name Conflicker and Kido (example name: Worm: W32/Downadup.gen! A, Net-Worm.Win32.Kido.ih). This category includes Worm Malware running on Windows 32-bit, that is called the W32.
Distribution of worm
The spread of this worm through various ways, such as the Network / network share or on a weak password, can also be spread by creating a file autorun.inf which triggered the copykan to Flashdisk USB (drive) or other removable media. So should the windows autorun feature is turned off to prevent the addition of various other viruses.
world-map
Worm exploit this rift security for Windows menginfeksi victims, like the previous article What's with the Windows Security Update MS08-067. Worm will create a folder with a random name in the directory RECYCLER (the Recycle Bin is used to store the file that was deleted) also duplicate themselves in various other places.
Effect Downadup Worm
And that this may make me write this article, some visitors ebsoft written comments that they can not open the antivirus sites, and may cause this is a worm.
This worm is able to change / add a function of internal windows (TCP) to block access to sites security (security / antivirus), with a filter that has the characters address / text specific. And to eliminate the effect is not easy, because it may be spelled already low level programming level.
Worm is designed to protect themselves from detection by using anti-virus techniques that are used infrequently, protect themselves from the effort to remove, turn off windows update, restore point prior to infection, kill a certain network traffic, to optimize the features of Windows Vista to facilitate the distribution, is able to inject explorer . exe, svchost.exe and services.exe and other.
Sites on the block quite a lot, including the web using the text as follows (in the block can always display the message or Time Out when opening the site):
* Virus
* Spyware
* Malware
* Rootkit
* Defender
* Microsoft
* Symantec
* Norton
McAfee *
* Trendmicro
* Sophos
* Panda
* Etrust
* F-secure
* Kaspersky
* F-Prot
* NOD32
* Eset
* Grisoft
* Avast
* Avira
* Comodo
* Clamav
* Norman
* Pctools
* Rising
* Sunbelt
* Threatexpert
* Wilderssecurity
* Windowsupdate
* AVP
* Avg
It also sites other security.
Labels:
worm