Conficker Worm Strikes Again
Sunday, January 18th, 2009
Back in October, Microsoft released a patch, MS08-067 , that would block the Conficker.A worm in a special update.
Over the last couple of weeks, a new variant of this worm has been affecting customers. Microsoft detected it as Worm:Win32/Conficker.B. In addition to exploiting MS08-067 (the patch from October), this variant also uses other propagation methods; it tries to copy itself to network shares by guessing their passwords. If the password is weak, it may succeed. It also tries to spread via removable media like thumb or jump drives.
In the last few days, including January 15, 16, and 17. It has infected more than 3.5 million computers worldwide. And, it is spreading rapidly.
- Shared computers with weak passwords may get infected by the worm
- External hard disks and USB sticks may get infected by the worm
- Computers without the latest patches and updates may get infected by the worm
It is important that you update all of the computers on your business or home network that are running the any version of the Windows operating system immediately, including Windows XP, Vista, and Server Operating systems. The update will block Conficker.B from infecting your computers if it has not already!
If you have been infected by Conficker, I have a link below that will allow you to download the Microsoft Malicious Software Removal Tool directly from Savemybutt to get rid of it.
However, because the warm blocks not only the Microsoft site, but also, most major security sites, including Norton, McAfee, Trend Micro, AVG, and Avast. You will have to download the removal tool from my site on the infected machine (because it is not blocked) or onto a clean machine that is not on your network, and then install it on all machines in your network. This MUST be run, and all computers on your network, because it spreads over your network to other machines.
Click here to download the Microsoft Malicious Software Removal Tool directly from this site. Savemybutt is not be blocked by the worm. Run it on EVERY computer on your network!
Also known as by different security companies:
TA08-297A (other)
CVE-2008-4250 (other)
VU827267 (other)
Win32/Conficker.A (Computer Associates)
Mal/Conficker-A (Sophos)
Trojan.Win32.Agent.bccs (Kaspersky)
W32.Downadup.B (Symantec)
List of word, character strings, websites, and domains that are blocked (that we know of).
virus
spyware
malware
rootkit
defender
microsoft
symantec
norton
mcafee
trendmicro
sophos
panda
etrust
networkassociates
computerassociates
f-secure
kaspersky
jotti
f-prot
nod32
eset
grisoft
drweb
centralcommand
ahnlab
esafe
avast
avira
quickheal
comodo
clamav
ewido
fortinet
gdata
hacksoft
hauri
ikarus
k7computing
norman
pctools
prevx
rising
securecomputing
sunbelt
emsisoft
arcabit
cpsecure
spamhaus
castlecops
threatexpert
wilderssecurity
windowsupdate





