<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>HowToRemoveConficker.com</title>
	<atom:link href="http://www.blog.howtoremoveconficker.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.blog.howtoremoveconficker.com</link>
	<description>Bloggin to remove conficker from the planet earth.</description>
	<pubDate>Sun, 03 May 2009 15:45:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Remove Conficker Worm (Removal Instructions) &#124; 411 on Spyware</title>
		<link>http://www.blog.howtoremoveconficker.com/?p=31</link>
		<comments>http://www.blog.howtoremoveconficker.com/?p=31#comments</comments>
		<pubDate>Fri, 24 Apr 2009 02:03:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.blog.howtoremoveconficker.com/?p=31</guid>
		<description><![CDATA[ Remove Conficker Worm (Removal Instructions) &#124; 411 on Spyware
Posted using ShareThis
   ]]></description>
			<content:encoded><![CDATA[<!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	--><div style='float:left'><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://www.blog.howtoremoveconficker.com/?p=31&amp;t=Remove+Conficker+Worm+%28Removal+Instructions%29+%7C+411+on+Spyware&amp;s=normal' height='80' width='52' frameborder='0' scrolling='no'></iframe></td></table></div><p><a href=http://www.411-spyware.com/conficker-worm-removal>Remove Conficker Worm (Removal Instructions) | 411 on Spyware</a></p>
<p>Posted using <a href="http://sharethis.com">ShareThis</a></p>
<div><table> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://www.blog.howtoremoveconficker.com/?p=31&amp;title=Remove+Conficker+Worm+%28Removal+Instructions%29+%7C+411+on+Spyware&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><iframe src='http://widgets.dzone.com/links/widgets/zoneit.html?url=http://www.blog.howtoremoveconficker.com/?p=31&amp;title=Remove+Conficker+Worm+%28Removal+Instructions%29+%7C+411+on+Spyware&amp;t=2 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=Remove+Conficker+Worm+%28Removal+Instructions%29+%7C+411+on+Spyware;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://www.blog.howtoremoveconficker.com/?feed=rss2&amp;p=31</wfw:commentRss>
		</item>
		<item>
		<title>Protecting Against the Rampant Conficker Worm</title>
		<link>http://www.blog.howtoremoveconficker.com/?p=30</link>
		<comments>http://www.blog.howtoremoveconficker.com/?p=30#comments</comments>
		<pubDate>Fri, 24 Apr 2009 02:00:25 +0000</pubDate>
		<dc:creator>erblogger</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.blog.howtoremoveconficker.com/?p=30</guid>
		<description><![CDATA[ Protecting Against the Rampant Conficker Worm
Posted using ShareThis
   ]]></description>
			<content:encoded><![CDATA[<!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	--><div style='float:left'><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://www.blog.howtoremoveconficker.com/?p=30&amp;t=Protecting+Against+the+Rampant+Conficker+Worm&amp;s=normal' height='80' width='52' frameborder='0' scrolling='no'></iframe></td></table></div><p><a href=http://www.pcworld.com/article/157876/protecting_against_the_rampant_conficker_worm.html>Protecting Against the Rampant Conficker Worm</a></p>
<p>Posted using <a href="http://sharethis.com">ShareThis</a></p>
<div><table> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://www.blog.howtoremoveconficker.com/?p=30&amp;title=Protecting+Against+the+Rampant+Conficker+Worm&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><iframe src='http://widgets.dzone.com/links/widgets/zoneit.html?url=http://www.blog.howtoremoveconficker.com/?p=30&amp;title=Protecting+Against+the+Rampant+Conficker+Worm&amp;t=2 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=Protecting+Against+the+Rampant+Conficker+Worm;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://www.blog.howtoremoveconficker.com/?feed=rss2&amp;p=30</wfw:commentRss>
		</item>
		<item>
		<title>Symptoms of the Conficker virus.</title>
		<link>http://www.blog.howtoremoveconficker.com/?p=25</link>
		<comments>http://www.blog.howtoremoveconficker.com/?p=25#comments</comments>
		<pubDate>Mon, 20 Apr 2009 12:22:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.blog.howtoremoveconficker.com/?p=25</guid>
		<description><![CDATA[ 
&#8220;Spyware Protect 2009&#8243; pop ups.


Internet Explorer redirects to page displaing false virus attack message.


Can&#8217;t visit any known antivirus sites. (e.g. Norton, anyways I didn&#8217;t find Norton&#8217;s conficker removal tool much effective)


USB Flash drive not detecting.


Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender, and Error Reporting Services are disabled.


The network is congested.



If you are [...]]]></description>
			<content:encoded><![CDATA[<!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	--><div style='float:left'><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://www.blog.howtoremoveconficker.com/?p=25&amp;t=Symptoms+of+the+Conficker+virus.&amp;s=normal' height='80' width='52' frameborder='0' scrolling='no'></iframe></td></table></div><ul>
<li>&#8220;Spyware Protect 2009&#8243; pop ups.</li>
</ul>
<ul>
<li>Internet Explorer redirects to page displaing false virus attack message.</li>
</ul>
<ul>
<li>Can&#8217;t visit any known antivirus sites. (e.g. Norton, anyways I didn&#8217;t find Norton&#8217;s conficker removal tool much effective)</li>
</ul>
<ul>
<li>USB Flash drive not detecting.</li>
</ul>
<ul>
<li>Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender, and Error Reporting Services are disabled.</li>
</ul>
<ul>
<li>The network is congested.</li>
</ul>
<p><span id="more-25"></span></p>
<ul>
<li>If you are being locked out of directory.</li>
</ul>
<ul>
<li>If you are being denied access to shared admin.</li>
</ul>
<ul>
<li>Computer lockup policies being reset and unusable.</li>
</ul>
<ul>
<li>The domain controls being over cloaked and overworked by an unusual amount of requests from various outside packet sources.</li>
</ul>
<ul>
<li>A large amount of unknown traffic coming to all local area networks.</li>
</ul>
<p>Your Solution to all these problem is Malwarebytes&#8217; Anti-Malware. Read article &#8220;<a href="index.php?option=com_content&amp;view=article&amp;id=6:dont-let-qconferq-get-you-&amp;catid=1:conficker">Remove Conficker in 7 Steps</a>&#8221;</p>
<p><a href="http://www.howtoremoveconficker.com/index.php?option=com_phocadownload&amp;view=category&amp;id=9:software&amp;Itemid=2" target="_blank">a.  Malwarebytes&#8217; Anti-Malware </a></p>
<p><a href="http://www.howtoremoveconficker.com/index.php?option=com_phocadownload&amp;view=category&amp;id=10:denfination-updates&amp;Itemid=2" target="_blank">b.  Malwarebytes&#8217; Anti-Malware Database (Definition Update Patch)</a></p>
<p>For more info from Microsoft visit the following link</p>
<p><a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker" target="_blank">http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker<br />
</a></p>
<p>Note: We don&#8217;t profit If you download any tools we recommend on our site. Right now we recommend Malwarebytes&#8217; Anti-Malware because we have tested it and its truly effect.</p>
<div><table> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://www.blog.howtoremoveconficker.com/?p=25&amp;title=Symptoms+of+the+Conficker+virus.&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><iframe src='http://widgets.dzone.com/links/widgets/zoneit.html?url=http://www.blog.howtoremoveconficker.com/?p=25&amp;title=Symptoms+of+the+Conficker+virus.&amp;t=2 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=Symptoms+of+the+Conficker+virus.;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://www.blog.howtoremoveconficker.com/?feed=rss2&amp;p=25</wfw:commentRss>
		</item>
		<item>
		<title>Remove Conficker in 7 Steps.</title>
		<link>http://www.blog.howtoremoveconficker.com/?p=8</link>
		<comments>http://www.blog.howtoremoveconficker.com/?p=8#comments</comments>
		<pubDate>Sat, 18 Apr 2009 20:38:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.blog.howtoremoveconficker.com/?p=8</guid>
		<description><![CDATA[ Do you get Spyware Protect 2009 popup, which looks something like this?

Then the bad news is that you have been infected with CONFICKER VIRUS.
Please don’t panic as HowToRemoveConficker.com is here to rescue your computer.
Follow these simple steps to remove conficker. 
1. Unplug the internet cable from the infected PC.
2. Right Click on TASK BAR [...]]]></description>
			<content:encoded><![CDATA[<!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	--><div style='float:left'><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://www.blog.howtoremoveconficker.com/?p=8&amp;t=Remove+Conficker+in+7+Steps.+&amp;s=normal' height='80' width='52' frameborder='0' scrolling='no'></iframe></td></table></div><p style="text-align: left;">Do you get Spyware Protect 2009 popup, which looks something like this?</p>
<p style="text-align: left;"><img class="alignnone size-medium wp-image-9" title="spywareprotect2009" src="http://www.blog.howtoremoveconficker.com/wp-content/uploads/2009/04/spywareprotect2009.jpg" alt="spywareprotect2009" width="300" height="193" /></p>
<p>Then the bad news is that you have been infected with CONFICKER VIRUS.</p>
<p>Please don’t panic as HowToRemoveConficker.com is here to rescue your computer.</p>
<p><strong>Follow these simple steps to remove conficker. </strong></p>
<p>1. Unplug the internet cable from the infected PC.</p>
<p>2. Right Click on TASK BAR (Bar which holds your START BUTTON) and select Task Manager.</p>
<div class="im">
<p><span id="more-8"></span></div>
<p>3. Click on &#8220;Processes&#8221; tab and look for SYSGUARD(or something similar or alien). If you find it, select it and CLICK on END PROCESS. This will immediately close all the Spyware Protect 2009 popup.</p>
<p>4. This is a temporary fix and if you restart your machine it will come back again. So we need to remove it from registry. So now we need to run the magic software called &#8221;Malwarebytes&#8217; Anti-Malware&#8221; which is available on our site. The links are below, download and install the software and also download its definition to update it as you will have to leave the infected PC disconnected from internet so in order to have the latest definition you need to manually install this patch. To download this software you can quickly plug in the internet cable and remove it once it downloads from the links below.</p>
<div class="im">
<p><a href="http://howtoremoveconficker.com/index.php?option=com_phocadownload&amp;view=category&amp;id=9:software&amp;Itemid=2" target="_blank">a.  Malwarebytes&#8217; Anti-Malware </a></p>
<p><a href="http://howtoremoveconficker.com/index.php?option=com_phocadownload&amp;view=category&amp;id=10:denfination-updates&amp;Itemid=2" target="_blank">b.  Malwarebytes&#8217; Anti-Malware Database (Definition Update Patch)</a></p>
<p>5. Now once you have downloaded, installed and updated the definition by installing the patch it’s recommended that you run the Malwarebyte in safe mode.</p></div>
<p>6. When you click on Malwarebyte’s it will give you two options Quick or Full Scan. Go for Full scan, this will take about 30 min and then it will show the results and will ask you to remove the infected files.</p>
<p>7. You will also have to restart the machine in order to completely remove all infected files.</p>
<p>BINGO! YOU SHOULD BE ALL RIGHT NOW.</p>
<p>If this doesn’t work then you need to reinstall your machine.</p>
<p>For further help please email us at <a href="mailto:help@howtoremoveconficker.com" target="_blank">help@howtoremoveconficker.com</a></p>
<div><table> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://www.blog.howtoremoveconficker.com/?p=8&amp;title=Remove+Conficker+in+7+Steps.+&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><iframe src='http://widgets.dzone.com/links/widgets/zoneit.html?url=http://www.blog.howtoremoveconficker.com/?p=8&amp;title=Remove+Conficker+in+7+Steps.+&amp;t=2 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=Remove+Conficker+in+7+Steps.+;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://www.blog.howtoremoveconficker.com/?feed=rss2&amp;p=8</wfw:commentRss>
		</item>
		<item>
		<title>What is Conficker?</title>
		<link>http://www.blog.howtoremoveconficker.com/?p=3</link>
		<comments>http://www.blog.howtoremoveconficker.com/?p=3#comments</comments>
		<pubDate>Mon, 13 Apr 2009 15:15:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.blog.howtoremoveconficker.com/?p=3</guid>
		<description><![CDATA[ Conficker (It&#8217;s short for CONFIGURATION F@#%ER!), also known as Downup, Downadup and Kido, is a computer worm that surfaced in October 2008 and targets the Microsoft Windows operating system. The worm exploits a previously patched vulnerability in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server [...]]]></description>
			<content:encoded><![CDATA[<!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	--><div style='float:left'><table> <td><iframe src='http://digg.com/api/diggthis.php?w=new&amp;u=http://www.blog.howtoremoveconficker.com/?p=3&amp;t=+What+is+Conficker%3F+&amp;s=normal' height='80' width='52' frameborder='0' scrolling='no'></iframe></td></table></div><p align="justify">Conficker (It&#8217;s short for CONFIGURATION F@#%ER!), also known as Downup, Downadup and Kido, is a computer worm that surfaced in October 2008 and targets the Microsoft Windows operating system. The worm exploits a previously patched vulnerability in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, Windows 7 Beta, and Windows Server 2008 R2 Beta. The worm has been unusually difficult for network operators and law enforcement to counter because of its combined use of advanced malware techniques.</p>
<p align="justify">Although the origin of the name &#8220;conficker&#8221; is not known with certainty, Internet specialists and others have speculated that it is a German portmanteau fusing the term &#8220;configure&#8221; with &#8220;ficken&#8221;, the German word for &#8220;fuck.&#8221; Microsoft analyst Joshua Phillips describes &#8220;conficker&#8221; as a rearrangement of portions of the domain name &#8220;trafficconverter.biz&#8221;</p>
<p><span id="more-3"></span></p>
<h3 class="mw-headline">Operation</h3>
<p align="justify">Four main variants of the Conficker worm are known and have been dubbed Conficker A, B, C and D. They were discovered 21 November 2008, 29 December 2008, 20 February 2009, and 4 March 2009, respectively.</p>
<h3 class="mw-headline">Initial infection</h3>
<ul>
<li>Variants A and B exploit a vulnerability in the Server Service on Windows computers, in which an already-infected source computer uses a specially-crafted remote procedure call request to force a buffer overflow and execute shellcode on the target computer. On the source computer, the worm runs an <span class="mw-redirect">HTTP server</span> on a port between 1024 and 10000; the target shellcode connects back to this HTTP server to download a copy of the worm in DLL form, which it then runs as a service via svchost.exe.</li>
<li>Variant B can remotely execute copies of itself through the ADMIN$ share on computers visible over NetBIOS. If the share is password-protected, it will attempt a brute force attack, potentially generating large amounts of network traffic and tripping user account lockout policies.</li>
<li>Variant B places a copy of itself on any attached removable media (such as USB flash drives), from which it can then infect new hosts through the Windows AutoRun mechanism.</li>
</ul>
<p align="justify"><a title="Payload_propagation" name="Payload_propagation"></a></p>
<h3 class="mw-headline">Payload propagation</h3>
<p align="justify">The worm has several mechanisms for pushing or pulling executable payloads over the network. These payloads have, so far, been used by variants A, B and C to replace themselves with variant D, which does not infect new hosts over NetBIOS or through removable media.</p>
<p align="justify">To prevent payloads from being hijacked, variant A payloads are RC4-encrypted with a 512-bit key and RSA signed with a 1024-bit key; the payload is unpacked and executed only if the signature verifies with a public key embedded in the worm. Variant B increases the size of the RSA key to 4096 bits.</p>
<ul>
<li>Variant A generates a list of 250 domain names every day across five Top-level domains (TLD). The domain names are generated from a pseudo-random number generator seeded with the current date to ensure that every copy of the worm generates the same names each day. The worm then attempts an HTTP connection to each domain name in turn, expecting from any of them a signed payload. Variant B increases the number of TLDs to eight.</li>
<li>To counter the worm&#8217;s use of pseudorandom domain names, ICANN and several <span class="mw-redirect">TLD</span> registrars began in February 2009 a coordinated barring of transfers and registrations for these domains.<sup> </sup>Variant D contains code to sidestep these countermeasures by daily generating a pool of 50000 domains across 110 TLDs, from which it randomly chooses 500 to attempt for that day. This new pull mechanism (which was disabled until April 1) is unlikely to propagate payloads to more than 1% of infected hosts per day, but is expected to function as a seeding mechanism for the worm&#8217;s peer-to-peer network.</li>
<li>Variant C creates a named pipe, over which it can push URLs for downloadable payloads to other infected hosts on a local area network.</li>
</ul>
<p align="justify"><a title="Effect" name="Effect"></a></p>
<h3 class="mw-headline">Effect</h3>
<p align="justify">Upon infection, the worm saves a copy of its DLL form to a random filename in the Windows system folder, then arranges to load itself thereafter at boot as a system service with a randomly generated name.</p>
<p align="justify">Variant C of the worm resets System Restore points and disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. Processes matching a predefined list of antiviral, diagnostic or system patching tools are watched for and terminated. An in-memory patch is also applied to the system <span class="mw-redirect">resolver</span> DLL to block lookups of hostnames related to antivirus software vendors and the Windows Update service.</p>
<p align="justify"><a title="Symptoms" name="Symptoms"></a></p>
<h2 class="mw-headline">Symptoms</h2>
<ul>
<li>Account lockout policies being reset automatically.</li>
<li>Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services disabled.</li>
<li><span class="mw-redirect">Domain controllers</span> responding slowly to client requests.</li>
<li>Congestion on local area networks.</li>
<li>Web sites related to antivirus software or the Windows Update service becoming inaccessible.</li>
</ul>
<p><a title="Automated_detection" name="Automated_detection"></a></p>
<h3 class="mw-headline">Automated detection</h3>
<p align="justify">The worm makes several in-memory patches to NetBIOS-related DLLs in order to open re-infection backdoors. On 27 March 2009, security researcher Dan Kaminsky discovered that this gave infected hosts a detectable signature when scanned remotely. Signature updates for a number of network scanning applications are now available including <span class="mw-redirect">NMap</span> and Nessus.</p>
<p align="justify"><a title="Impact" name="Impact"></a></p>
<h3 class="mw-headline">Impact</h3>
<p align="justify">Conficker is believed to be the worst computer worm infection since SQL Slammer in 2003. Estimates of the number of computers infected range from almost 9 million PCs to 15 million computers.<sup> </sup>The initial rapid spread of the worm has been attributed to the number of Windows computers—estimated at 30%—which have yet to apply the Microsoft MS08-067 patch.</p>
<p align="justify">Another antivirus software vendor, Panda Security, reported that of the 2 million computers analyzed through ActiveScan, around 115,000 (6%) were infected with this malware.</p>
<p align="justify">Intramar, the French Navy computer network, was infected with Conficker in 15 January 2009. The network was subsequently quarantined, forcing aircraft at several airbases to be grounded because their flight plans could not be downloaded.</p>
<p align="justify">The UK Ministry of Defence reported that some of its major systems and desktops were infected. The worm has spread across administrative offices, <em>NavyStar/N*</em> desktops aboard various Royal Navy warships and Royal Navy submarines, and hospitals across the city of Sheffield reported infection of over 800 computers.</p>
<p align="justify">On 2 February 2009, the Bundeswehr reported that about one hundred of their computers were infected.</p>
<p align="justify">A memo from the British Director of Parliamentary ICT informed the users of the House of Commons on 24 March 2009 that it had been infected with the worm. The memo, which was subsequently leaked, called for users to avoid connecting any unauthorized equipment to the network.</p>
<p align="justify"><a title="Response" name="Response"></a></p>
<h2 class="mw-headline">Response</h2>
<p align="justify">On February 12, 2009, Microsoft announced the formation of a technology industry collaboration to combat the effects of Conficker. Organizations involved in this collaborative effort include Microsoft, Afilias, ICANN, <span class="mw-redirect">Neustar</span>, <span class="mw-redirect">Verisign</span>, <span class="mw-redirect">CNNIC</span>, Public Internet Registry, Global Domains International, Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from <span class="mw-redirect">Georgia Tech</span>, The Shadowserver Foundation, Arbor Networks, and Support Intelligence.</p>
<p align="justify"><a title="From_Microsoft" name="From_Microsoft"></a></p>
<h3 class="mw-headline">From Microsoft</h3>
<p align="justify">As of 13 February 2009, Microsoft is offering a $250,000 <span class="mw-redirect">USD</span> reward for information leading to the arrest and conviction of the individuals behind the creation and/or distribution of Conficker.</p>
<p align="justify"><a title="From_registrars" name="From_registrars"></a></p>
<h3 class="mw-headline">From registrars</h3>
<p align="justify">ICANN has sought preemptive barring of domain transfers and registrations from all <span class="mw-redirect">TLD</span> registrars affected by the Conficker C domain generator. Those which have taken action include:</p>
<ul>
<li>On 24 March 2009, CIRA, the Canadian Internet Registration Authority, locked all previously-unregistered .ca domain names expected to be generated by Conficker C over the next 12 months.</li>
<li>On 31 March 2009, <span class="mw-redirect">NASK</span>, the Polish <span class="mw-redirect">ccTLD</span> registrar, locked over 150,000 .pl domains expected to be generated by Conficker C over the coming 5 weeks. NASK has also warned that worm traffic may unintentionally inflict a <span class="mw-redirect">DDoS</span> attack to legitimate domains which happen to be in the generated set.</li>
</ul>
<p align="justify"><a title="Removal" name="Removal"></a></p>
<h3 class="mw-headline">Removal</h3>
<p align="justify">On 15 October 2008, Microsoft released an emergency out-of-band patch to fix vulnerability MS08-067, which the worm exploits to spread. The patch applies only to <span class="mw-redirect">Windows XP SP 2</span>, <span class="mw-redirect">Windows XP SP 3</span>, Windows 2000 SP4 and Windows Vista; <span class="mw-redirect">Windows XP SP 1</span> and earlier are no longer supported.</p>
<p align="justify">Microsoft has since released a removal guide for the worm, and recommends using the current release of its Malicious Software Removal Tool to remove the worm, then applying the patch to prevent re-infection.</p>
<p align="justify"><a title="Third_parties" name="Third_parties"></a></p>
<h3 class="mw-headline">Third parties</h3>
<p align="justify">Third-party anti-virus software vendors BitDefender, Enigma Software, ESET, F-Secure, Symantec, Sophos, and Kaspersky Lab have released detection updates to their products and are able to remove the worm. McAfee and AVG are able to remove it with an on-demand scan.</p>
<p align="justify"><a title="US_federal_agencies" name="US_federal_agencies"></a></p>
<h3 class="mw-headline">US federal agencies</h3>
<p align="justify">The United States Computer Emergency Readiness Team (CERT) recommends disabling AutoRun to prevent Variant B of the worm from spreading through removable media, but describes Microsoft&#8217;s guidelines on disabling Autorun as being &#8220;not fully effective&#8221;. CERT has instead provided its own guide for disabling AutoRun. CERT has also made a network-based tool for detecting Conficker-infected hosts available to federal and state agencies.</p>
<p align="justify">
<p align="justify"><span style="color: #808080;">The above article is originally created on Wikipedia.org (<a href="http://en.wikipedia.org/wiki/Conficker">http://en.wikipedia.org/wiki/Conficker</a>) </span></p>
<div><table> <td><iframe src='http://www.reddit.com/button_content?newwindow=1&amp;url=http://www.blog.howtoremoveconficker.com/?p=3&amp;title=+What+is+Conficker%3F+&amp;t=1 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><iframe src='http://widgets.dzone.com/links/widgets/zoneit.html?url=http://www.blog.howtoremoveconficker.com/?p=3&amp;title=+What+is+Conficker%3F+&amp;t=2 ' height='18' width='120' scrolling='no' frameborder='0' ></iframe></td> <td><script type="text/javascript"><!--yahooBuzzArticleHeadline=+What+is+Conficker%3F+;//--></script><script type="text/javascript" src="http://d.yimg.com/ds/badge2.js" badgetype=small-votes></script></td></table></div><!-- This is a HTML comment, it will not display in any page. Feel free to remove this comment if it cause any inconvenient to you.
	Thanks for using digg digg, please visit http://www.mkyong.com/blog/digg-digg-wordpress-plugin for any comments and ideas, 
	
    Author : Yong Mook Kim
    Website : http://www.mkyong.com
	-->]]></content:encoded>
			<wfw:commentRss>http://www.blog.howtoremoveconficker.com/?feed=rss2&amp;p=3</wfw:commentRss>
		</item>
	</channel>
</rss>
