Published on Maximum PC (http://www.maximumpc.com)


This is No Joke: Conficker.C to Strike on April Fools' Day
Created 03/16/2009 - 2:06pm

Maximum IT
    • Cisco Cranks Out iPhone Security App for IT Managers
    • Verizon Puts Together Telehealth Collaboration Services
    • Ciena Coughs Up $530 Million in Cash for a Slice of Nortel Networks

    Sponsored
SEE MORE MAXIMUM IT
News
  • Google's New TiVo Ad Deal Is Good for You, Bad for Networks
  • Deals.Woot Launches, Crowdsources Thriftiness
  • Chrome Now Open for Extension Uploads
  • iPhone Responsible for Half of All Mobile Traffic, Globally
  • Amazon Boosts Kindle Battery Life, Adds Native PDF Reader
SEE MORE NEWS
News

This is No Joke: Conficker.C to Strike on April Fools' Day

Posted 03/16/09 at 05:06:59 PM  by Mark Edward Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Conficker.C's ready to strike on 4-1-09

Just when you might have thought it was safe to start using USB flash drives at work again, the third, and by all accounts, most fiendish version of the Conficker worm that's infected millions of PCs already is set to attack on April 1st, Ars Technica reports. Conficker.C's designed to hide itself even more thoroughly than its older siblings Conficker.A and Conficker.B, using tricks such as:

  • Inserting itself into as many as five Windows-related folders such as System, Movie Maker, Internet Explorer, and others (under a random name, of course)
  • Creating access control entries and locking the file(s)
  • Registers dummy services using a "one (name) from column A, one from column B, and two from column C" method

To find out what happens when Conficker.C strikes, join us after the jump.

Conficker.C's payload makes it harder than ever to recover from being infected:

  • Deactivates Windows Security Center notifications
  • Prevents restart in Safe Mode
  • Prevents Windows Defender from running at system startup
  • Deletes all system restore points
  • Disables various error-reporting and security services
  • Terminates over twenty security-related processes
  • Blocks DNS queries
  • Blocks access to security and antivirus websites
  • And, to top it all off, Conficker.C can choose from a list of 500 domains to contact out of a pool of 50,000 (way up from Conficker.B's 32 out of 250).

See the Win32/Conficker.C writeup at CA's website for complete technical details.

Microsoft, Panda Software, Symantec, and McAfee are just a few of the vendors that have now updated their threat encyclopedias to include Conficker.C (it's sometimes listed as Conficker.B++). Since Conficker.B and the new Conficker.C are designed to block access to antivirus websites, you might want to download removal tools now - just in case. You can get one developed by BitDefender from the Downadup.org website (Downadup is the alternative name for Conficker); however, keep in mind that ArsTechnica isn't certain if it will remove Conficker.C (it will remove older versions).

Naturally, prevention's way better than curing a nasty worm outbreak. To learn more about preventing infections, and for links to additional removal tools, see our previous Conficker articles.

Have you been hit by any Conficker version? Any tips for the rest of us? Hit Comment and pass them along. 

USB flash drives illustration courtesy of BBC.
COMMENTS:11
TAGS: windows, microsoft, Security, update, exploit, vulnerability, worm, MS08-067, Conficker, Downadup
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/news/this_no_joke_confickerc_strike_april_fools_day

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://www.maximumpc.com/tags/Conficker
[3] http://arstechnica.com/security/news/2009/03/confickerc-primed-for-april-fools-activation.ars
[4] http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77976
[5] http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm:Win32/Conficker.C
[6] http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=204292
[7] http://www.symantec.com/en/th/enterprise/security_response/writeup.jsp?docid=2009-030614-5852-99
[8] http://vil.nai.com/vil/content/v_153710.htm
[9] http://www.downadup.org/
[10] http://news.bbc.co.uk/
[11] http://www.maximumpc.com/article/news/conficker_worms_infected_over_9_million_pcs_is_your_work_or_home_pc_one_them
[12] http://www.maximumpc.com/article/news/conficker_worm_shuts_down_french_and_uk_air_forces
[13] http://www.maximumpc.com/article/news/microsoft_hopes_it_has_a_winning_hand_stop_conficker_worm