Results 1 to 3 of 3

Thread: Conficker Virus, How it works

  1. #1
    Senior Administrator hey_moe's Avatar
    Join Date
    Jun 2005
    Location
    Hampton,Va
    Age
    58
    Posts
    4,251

    Post Conficker Virus, How it works

    The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008. Although Microsoft released a patch, it has gone on to infect 3.5m machines. Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft's MS08-067 patch. According to Microsoft, the worm works by searching for a Windows executable file called "services.exe" and then becomes part of that code. It then copies itself into the Windows system folder as a random file of a type known as a "dll". It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service. Once the worm is up and running, it creates an HTTP server, resets a machine's System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker's web site.
    Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down. But Conficker does things differently. Anti-virus firm F-Secure says that the worm uses a complicated algorithm to generate hundreds of different domain names every day, such as mphtfrxs.net, imctaef.cc, and hcweu.org. Only one of these will actually be the site used to download the hackers' files. On the face of it, tracing this one site is almost impossible.
    Please patch yourself up. SOURCE: GURU3D

    Asus Rampage Extreme Motherboard /EVGA AR GeForce GTX 295 1792MB 896 Bit GDDR3 /Corsair 8gig XMS DDR3/Intel Core 2 Extreme QX 9770 Yorkfield OCed 4.2 LGA 775/136W Quad Core / Water Cooled/ 2 WD Raptor 150gig 10,000 rpm Drives in Raid O Mode/WD Raptor 150gig internal back up/400 gig External WD back up Drive/Thermaltake 1200 Watt PS/Sony Dual Layer DVD RD/RW/Plextor DVD/RW/ Thermaltake Kandalf Tower/ Sound Blasters X-FI Platinum / X52 Pro

  2. #2
    warbird861
    Guest
    This is really nasty piece of coding. I got this thing yesterday and took quite some time to take it out. Thank God my antivirus software noticed it and I took it out before any more damage happened.

    I recommend also to update and keep up to date antivirus software.

  3. #3
    SOH Mod Lionheart's Avatar
    Join Date
    Jul 2005
    Location
    The land where dust is manufactured and people are high temp tested!
    Age
    51
    Posts
    11,787
    Thanks for the heads up. Will run a scan this morning.



    Bill
    Humble Poly bender and warrior of Vertices

    <a href=http://www.prepar3d.com target=_blank rel=nofollow>http://www.prepar3d.com</a>

    iMac 24" Alum UniBody; Intel Core Duo 2.80 GHz;
    ATI Radeon HT 2600 XT; 1TB drive; 4 Gigs DDR Ram;
    Apple juice plasma injection system.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 19
    Last Post: January 5th, 2012, 20:12
  2. Win32 Conficker Worm
    By GT182 in forum The NewsHawks
    Replies: 9
    Last Post: April 3rd, 2009, 11:49
  3. Conficker Worm
    By harleyman in forum FSX General Discussion
    Replies: 2
    Last Post: March 31st, 2009, 19:42
  4. Remove your Downadup/conficker infection!
    By Ferry_vO in forum The NewsHawks
    Replies: 10
    Last Post: March 16th, 2009, 19:35
  5. Replies: 5
    Last Post: January 17th, 2009, 11:40

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Avsim - Flightsim - SimFlight - Simviation - iflyonline - CFS IP - Quarter Moon Saloon - Com-Central