Channeltimes.com | CXOtoday.com | Techtree.com Jan 22, 2010
Newsletter
Search
Home TrendsTech 4 YouAdvisorLearning CurveViewpointKnow IT User CaseBizleaderQ&AOpinionTech TermsEventsMailbox
 
Oracle Database
11g security & Compliance
LG Electronic's offers innovative SMB (Small & Medium Business) Solutions
   Home >Know It> Online

Guidelines to Safeguard Against Conficker
By Enterpriser Staff | Apr 01, 2009 1452 hrs IST
This Article:

In the midst of concerns about the possiblity of the Conficker worm spreading over networks today, McAfee has prepared a set of guidelines for PC-users to take proactive steps against becoming victims of the infection. The security technology company has also provided detection and removals tools on its website. Here are some basic steps on how to detect a Conficker infection and what one can do to prevent or remove the worm. Also included are additional tips and links to removal tools provided by other anti-virus software providers.

The Conficker worm (also known as Downup/Downadup/Kido) takes advantage of a security flaw in Microsoft's Windows operating system to spread itself. Microsoft provided an emergency fix for this vulnerability last October (Security Update MS08-067). Many systems remained unpatched or were not well protected with adequate security software. According to estimates provided to McAfee, Conficker has been managed to extend its footprint by infecting as many as 12 million Windows computers.

There are have been reports that a variant of the worm, Conficker.C, may activate on April 1 and begin another round of infections on Windows computers. Taking advantage of the vulnerability, infected computers can be controlled remotely and made to launch attacks on Web sites, distribute spam, or host phishing Web sites. Just like any other worm infection, Conficker is not easily detected and also disables security software.

Symptoms of a Conficker Infection

- Access to security-related sites is blocked
- Users are locked out of the directory
- Traffic is sent through port 445 on non-Directory Service (DS) servers
- Access to admininistrator shared drives is denied
- Autorun.inf files are placed in the recycled directory, or Recycle Bin

Detect, Remove and Prevent Infection
- It is imperative to install Microsoft's patch which is available on the Security Update MS08-67 page -- this will prevent the worm from reinstalling itself. Install this patch on Windows-based computers in the network.

- McAfee has released a free tool that will help detect the presence of Conficker on multiple computers. ConTest can be downloaded from http://www.mcafee.com/us/enterprise/confickertest.html

- Symantec recommends users to turn off 'autorun' so as to prevent the infected file from executing. This will reduce the possibility of getting infected by flash drives. Symantec's removal tool is available on their Removal Tools page.
F-Secure provides a detailed report on the infection and a tool for removing Conficker.
Sophos has also created a removal tool on its website.

- Microworld recommends that administrators apply password policies in network groups to mitigate infections caused by Conficker/Downadup. Users can also try the Microworld Free AntiVirus Toolkit Utility (MWAV) to scan for viruses and infections. The utility includes the ability to detect and remove the Conficker worm. If a user's PC is already infected, download the utility to an uninfected flash drive and run the tool on the computer. This utility does not need to be installed, it will directly run on the computer. 

- If access to security-related sites is blocked, users must search download McAfee's 'Avert stinger' tool for removing Conficker from an uninfected computer and save it on a USB pen drive. The Avert stinger tool is available for download at http://www.mcafee.com/us/threat_center/conficker.html

- Install an up to date anti-malware solution is also recommended to detect any future infections.

- Network administrators and IT helpdesk professionals can use the detailed documentation called Protecting yourself from the Conficker worm with Network Security Platform from the McAfee website.

Also Read:
New Windows Worm Causing a Stir
Conficker Worm Continues to Wreak Havoc
F-Secure Releases Removal Tool for Network Worm

Share and Connect   del.icio.us del.icio.us   Digg.com Digg.com   Myweb MyWeb   Newsvine.com Newsvine.com
Post your comment on “Have you installed the Microsoft Security Update?”
Comment :  
Name :  
Company :    
City :  
E-mail :  
Word verification : Type the characters you see in the picture below.  
   
      
  Characters are not case-sensitive  
 
 


Articles
Comments More
I have land in Kottayam town near Tiruvanjur, which can be rented out ..
- Sudeep Nair, Anonymous
Dear Sir, i have a open plot near road side 1450 sq.ft. and want to give ..
- B G PATEL, SELF
Dear Sir, i have 1450 sq.ft open plot, road touch. In HALOL - PANCHMAHAL ..
- B GPATEL, SIDE BUSINESS
hi sir i want uto install a tower on my land in ludhiana centre of punjab ..
- saurabh, puri
hi sir i want uto install a tower on my land in ludhiana.. 9855253221 vivek puri
- vivek, puri

 
    Channeltimes.com CXOtoday.com Techtree.com
About the NetworkChapters FeedbackSite MapContact Us