<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpywareRemove Blog &#187; Conficker Worm</title>
	<atom:link href="http://www.spywareremove.com/security/news/conficker-worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spywareremove.com/security</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 20 Nov 2009 16:05:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Conficker Worm Still Managing To Infect 50,000 Computers Each Day</title>
		<link>http://www.spywareremove.com/security/conficker-worm-still-managing-to-infect-50000-computers-each-day/</link>
		<comments>http://www.spywareremove.com/security/conficker-worm-still-managing-to-infect-50000-computers-each-day/#comments</comments>
		<pubDate>Tue, 26 May 2009 19:47:16 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/conficker-worm-still-managing-to-infect-50000-computers-each-day/</guid>
		<description><![CDATA[ <h3 class="posttitle">Everyone, including the media, has passed over Conficker as if it was dead. The infection of 50,000 PC's a-day should be enough proof that Conficker Worm is still far from being dead.</h3>

According to security researchers, <a href="http://www.spywareremove.com/removeConficker.html" title="Conficker Removal Guide">Conficker worm</a> is managing to still infect systems at a rapid rate which includes systems in Fortune 1000 companies. Researchers at Symantec have said Conficker is infected about 50,000 new PC’s each day. Systems located in the U.S., India and Brazil have been hit the hardest which was confirmed in the same report from researchers at Symantec. 

The hype that circulated Conficker worm over two months go, has died down and is almost non-existent. The fact of the matter is, Conficker is still a viable threat and remains to be very active. ]]></description>
			<content:encoded><![CDATA[<h3 class="posttitle">Everyone, including the media, has passed over Conficker as if it was dead. The infection of 50,000 PC&#8217;s a-day should be enough proof that Conficker Worm is still far from being dead.</h3>
<p>According to security researchers, <a href="http://www.spywareremove.com/removeConficker.html" title="Conficker Removal Guide">Conficker worm</a> is managing to still infect systems at a rapid rate which includes systems in Fortune 1000 companies. Researchers at Symantec have said Conficker is infected about 50,000 new PC’s each day. Systems located in the U.S., India and Brazil have been hit the hardest which was confirmed in the same report from researchers at Symantec. </p>
<p>The hype that circulated Conficker worm over two months go, has died down and is almost non-existent. The fact of the matter is, Conficker is still a viable threat and remains to be very active. </p>
<p>Conficker, <a href="http://www.spywareremove.com/removeDownadup.html" title="Downadup Removal Guide">Downadup</a> or <a href="http://www.spywareremove.com/removeKido.html" title="Kido Removal Guide">Kido</a>, first started spreading in late 2008 where it took advantage of the MS087-067 vulnerability within the Microsoft Windows operating system. Since then, Conficker has evolved into several other variants including <a href="http://www.spywareremove.com/removeConfickerB.html" title="Conficker B++ Removal Guide">Conficker.B</a>, <a href="http://www.spywareremove.com/removeConfickerC.html" title="Conficker.C Removal Guide">Conficker.C</a> and even Conficker.E. All versions combined, have managed to infect millions of computers. A good portion of the millions remain to be infected.</p>
<p>Many companies have spent millions of dollars to prevent infections such as Conficker over the course of several years. Even after the preventative measures were put in place, many systems were still infected with Conficker since it’s conception. Conficker is a significant botnet. As you may know with a botnet infection, the creators have a certain degree of control over the infected computers. That means the compromised systems can be instructed to carry out malicious actions at any time.</p>
<h3 class="posttitle">What should be done in the mean-time about Conficker?</h3>
<p>Actions need to be taken to ramp-up prevention and <a href="http://www.spywareremove.com/download/cfremover.exe" title="Free Conficker Removal Tool">removal of the Conficker infection</a> before a viable attack is initiated on the infected systems. Security researchers have continued to warn companies and network administrator groups to take the necessary precautions in lue of Conficker currently not being in the headlines of the news media. If Conficker continues to infect upwards of 50,000 computers a day, just think of the ramifications of an orchestrated attack using the massive botnet formed by all of the compromised PC&#8217;s. This could be one of the biggest attacks that may leave networks infrastructures crippled for months. </p>
<p>Is it possible that the attackers or creators of Conficker purposely waited for the &#8220;calm after the storm&#8221; to initiate their ultimate attack? Do you think we will see a serious attack conducted by Conficker infected machines in the near future? </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/conficker-worm-still-managing-to-infect-50000-computers-each-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Alert: Conficker.C Comes Out of Dormancy Likely to Cause Destruction</title>
		<link>http://www.spywareremove.com/security/alert-confickerc-comes-out-of-dormancy-likely-to-cause-destruction/</link>
		<comments>http://www.spywareremove.com/security/alert-confickerc-comes-out-of-dormancy-likely-to-cause-destruction/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 23:17:39 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/alert-confickerc-comes-out-of-dormancy-likely-to-cause-destruction/</guid>
		<description><![CDATA[ <h3 class="posttitle">Conficker.C has awakened and is starting to cause additional concern of being more dangerous and powerful than ever.</h3>

The <a href="http://www.spywareremove.com/removeConfickerC.html" title=Remova Conficker Worm">Conficker worm</a> has come back alive and starting to update through peer-to-peer between infected computers dropping unknown files or programs. The software that is being dropped appears to be a .sys component hiding behind a rootkit. As you may already know with rootkits it could be software that is developed to hid the fact that a system has been compromised. 

Because Conficker is already encrypted to the point where security analyses are not able to figure out all of the details in pinpointing Conficker's next moves, it is difficult to be 100% sure of what Conficker is currently doing as it contacts DNS names. ]]></description>
			<content:encoded><![CDATA[<h3 class="posttitle">Conficker.C has awakened and is starting to cause additional concern of being more dangerous and powerful than ever.</h3>
<p>The <a href="http://www.spywareremove.com/removeConfickerC.html" title=Remova Conficker Worm">Conficker worm</a> has come back alive and starting to update through peer-to-peer between infected computers dropping unknown files or programs. The software that is being dropped appears to be a .sys component hiding behind a rootkit. As you may already know with rootkits it could be software that is developed to hid the fact that a system has been compromised. </p>
<p>Because Conficker is already encrypted to the point where security analyses are not able to figure out all of the details in pinpointing Conficker&#8217;s next moves, it is difficult to be 100% sure of what Conficker is currently doing as it contacts DNS names. </p>
<p>What we do know about Conficker is that during this stage of reactivating or awakening, it has attempted to connect to popular sites such as AOL.com, eBay.com, MSN.com, CNN.com and MySpace.com for conducting a test to see if the infected computer has internet access or not. </p>
<p>On Trendmicro&#8217;s blog it is stated that Conficker will perform the following functions:</p>
<ol>
<li>May 3, 2009, it will stop running.</li>
<li>Runs in random file name and random service name.</li>
<li>Deletes this dropped component afterwards.</li>
<li>Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs.</li>
<li>Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request.</li>
<li>Connects to the following sites:<br />
aol.com<br />
cnn.com<br />
ebay.com<br />
msn.com<br />
Myspace.com</li>
</ol>
<p>We know a lot more about Conficker.C than we did <a href="http://www.spywareremove.com/security/conficker-c-the-april-fools-day-worm/" title="Conficker.C - The April Fool’s Day Worm">before April 1st</a>. Conficker.C still remains to be a mystery when it comes to predicting the damages that it will cause. However, you can check your system to see if you are infected with Conficker or other variants of Conficker including Conficker.C., by simply attempting to navigate to security websites or Microsoft.com. If you cannot view security websites or Microsoft.com then you may have the Conficker worm on your computer. </p>
<p>Do you think Conficker.C will be the one of the word computer infections this year? Are you taking precautionary measures to protect your system from the Conficker Worm by applying MS08-067 update from Microsoft.com? </p>
<p><a href="http://www.spywareremove.com/download/cfremover.exe" title="Free Conficker Removal Tool">Download the Free Conficker removal tool!</a> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/alert-confickerc-comes-out-of-dormancy-likely-to-cause-destruction/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Neeris Worm: A Copycat Conficker Worm Discovered</title>
		<link>http://www.spywareremove.com/security/neeris-worm-a-copycat-conficker-worm-discovered/</link>
		<comments>http://www.spywareremove.com/security/neeris-worm-a-copycat-conficker-worm-discovered/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 18:51:52 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/neeris-worm-a-copycat-conficker-worm-discovered/</guid>
		<description><![CDATA[ <h3 class="posttitle">Conficker infected millions of computers and now another threat called Neeirs Worm is copying the same infection strategies of Conficker.</h3>

A worm, which is now about 4 years old, called Neeris worm, is copying Conficker's attack strategies which could potentially infect millions of computers. Not much is known about the Neeris Worm, which dates back to May 2005. Neeris Worm is exploiting the same MS08-067 vulnerability that Microsoft patched back in October 2008 at the time of Conficker emerging into the wild. 

<a href="http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/" title="Conficker, Downadup, and Kido Worm Infects Millions of Computers Worldwide">Conficker used the MS08-067 vulnerability to infect computers</a> and it was a very effective method as it was able to infect 12 million or more computers around the world and giving everyone a big scare especially from the <a href="http://www.spywareremove.com/removeConfickerC.html" title="Conficker.C Removal Guide">Conficker.C variant</a>. The Conficker.C variant proved to be not as effected as many feared before the date of April 1st which marked the day that it would start contacting its controllers. ]]></description>
			<content:encoded><![CDATA[<h3 class="posttitle">Conficker infected millions of computers and now another threat called Neeirs Worm is copying the same infection strategies of Conficker.</h3>
<p>A worm, which is now about 4 years old, called Neeris worm, is copying Conficker&#8217;s attack strategies which could potentially infect millions of computers. Not much is known about the Neeris Worm, which dates back to May 2005. Neeris Worm is exploiting the same MS08-067 vulnerability that Microsoft patched back in October 2008 at the time of Conficker emerging into the wild. </p>
<p><a href="http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/" title="Conficker, Downadup, and Kido Worm Infects Millions of Computers Worldwide">Conficker used the MS08-067 vulnerability to infect computers</a> and it was a very effective method as it was able to infect 12 million or more computers around the world and giving everyone a big scare especially from the <a href="http://www.spywareremove.com/removeConfickerC.html" title="Conficker.C Removal Guide">Conficker.C variant</a>. The Conficker.C variant proved to be not as effected as many feared before the date of April 1st which marked the day that it would start contacting its controllers.</p>
<h3 class="posttitle">In what other way is Neeris simular to Conficker Worm?</h3>
<p>The Neeris Worm is now updated using the same methods of Conficker to spread such as using the autorun.inf file where it is able to worm its way onto and from the root directory of a USB drive or other USB storage based devices. Basically this process spreads the infection onto a system silently when it is connected to a computer that is not infected. </p>
<p>Because Neeirs worm, from the research of many security firms, has many of the same characteristics of Conficker, it is believed that the makers of Conficker and Neeirs have joined forces. Neeirs starting showing up on the radar screen again with the new infection methods as early as March 31st and into April 1st. Is this a coincidence that it coincides with the April 1st date that Conficker was supposed to start performing malicious actions? </p>
<p>To add to the mystery of Neeirs worm is the fact that it is not downloaded by any Conficker variant and no proof that it is actually related to Conficker.C&#8217;s April 1 activation. Also, Neeris Worm, being 4 years old now, was never added or fingerprinted to be a parasite detected by Microsoft&#8217;s Malicious Software Removal Tool. Why did Microsoft overlook this worm? Is it possible that the Neeirs worm is yet another scare tactic just like Conficker.C&#8217;s and it will not causing any harm? This is very possible but it is still wise to apply the MS08-067 vulnerability patch to your system to prevent infection from the Neeirs worm and Conficker Worm variants. </p>
<p>Do you fear that we have not seen the last of Conficker Worm or its methods for infecting computers? Do you think that a worm such as Neeirs will emerge as a serious threat finishing what Conficker started? </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/neeris-worm-a-copycat-conficker-worm-discovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker.C &#8211; The April Fool&#8217;s Day Worm</title>
		<link>http://www.spywareremove.com/security/conficker-c-the-april-fools-day-worm/</link>
		<comments>http://www.spywareremove.com/security/conficker-c-the-april-fools-day-worm/#comments</comments>
		<pubDate>Sun, 29 Mar 2009 20:46:30 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/conficker-c-the-april-fools-day-worm/</guid>
		<description><![CDATA[ <h3 class="posttitle">Everyone is wondering what April 1st will bring when it comes to the Conficker.C Worm</h3>

As you may have remembered, <a href="http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/" title="Conficker, Downadup, and Kido Worm Infects Millions of Computers Worldwide">Conficker Worm</a> has been a serious epidemic ever since it affected millions of computers during the last few months. The newest variant, Conficker.C, is expected to start performing malicious actions on April 1st but researchers do not know what exactly will take place. 
	
Currently one thing that has been determined and verified about Conficker.C is that it is hard-coded with the date of April 1st, April Fool's day.  Security researchers expect that April Fool's day will be more than just a hoax when the Conficker.C worm starts to contact its controllers, which will give the worm instructions to carry out on infected computers around the world. ]]></description>
			<content:encoded><![CDATA[<h3 class="posttitle">Everyone is wondering what April 1st will bring when it comes to the Conficker.C Worm</h3>
<p>As you may have remembered, <a href="http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/" title="Conficker, Downadup, and Kido Worm Infects Millions of Computers Worldwide">Conficker Worm</a> has been a serious epidemic ever since it affected millions of computers during the last few months. The newest variant, <a href="http://www.spywareremove.com/removeConfickerC.html" title="Conficker.C">Conficker.C</a>, is expected to start performing malicious actions on April 1st but researchers do not know what exactly will take place. </p>
<p>Currently one thing that has been determined and verified about Conficker.C is that it is hard-coded with the date of April 1st, April Fool&#8217;s day.  Security researchers expect that April Fool&#8217;s day will be more than just a hoax when the Conficker.C worm starts to contact its controllers, which will give the worm instructions to carry out on infected computers around the world. </p>
<p>The original Conficker Worm and other previous variations such as <a href="http://www.spywareremove.com/removeConfickerB.html" title="Conficker B++">Conficker B++</a>, also known as <a href="http://www.spywareremove.com/removeDownadup.html" title="Downadup">Downadup</a> or <a href="http://www.spywareremove.com/removeKido.html" title="Kido">Kido</a>, built a botnet mostly through the exploitation of the MS08-067 vulnerability in Windows. Since then Conficker has been upgraded to deviate past many roadblocks put in place to limit the spread of Conficker. Conficker.C adds these defensive measures so that it protects itself from detection and removal eventually affecting even more computers. </p>
<h3 class="posttitle">What else do we know about Conficker.C?</h3>
<p>Conficker.C disables Windows Automatic Updates and the Windows Security Center. Other variants of Conficker, Conficker.A and Conficker.B, have been dissected and understood to the point where we know what malicious actions it performs. Many security firms are able to provide tools to effectively remove all variants of Conficker including Conficker.C because of the knowledge gained from Conficker.A and Conficker.B during the time that millions of computers were infected with this malevolent worm. Conficker.C is also known to detect and kill SysInternals&#8217; Process Explorer program and other search-and-destory programs such as SysClean. Knowing this has may prompt many computer users and experts to be certain that their security software is actively working.</p>
<p>On April 1st, Conficker.C is expected to contact about 50,000 domains and then start downloading either particular instructions or malicious files. It remains to be a mystery as to what the bots will do on this day. Conficker.C may have been able to spread by avoiding the DNS actions put in place to limit or stop the spread of Conficker.A and Conficker.B.</p>
<h3 class="posttitle">What are people doing now to prepare for April 1st when Conficker.C starts its malicious actions?</h3>
<p>Many security firms are advising computer users to keep all software up-to-date including applying all patches and security updates for Windows from Microsoft. In addition, computer users are asked that they make sure that their security software is up-to-date and properly working. Because Conficker is known to disable security software or certain software updates, it may be best to actually make sure that your software is operating and not inactive.  </p>
<p>Conficker.C is by far one of the most advanced computer malware infections mainly because no one is really able to crack it yet. Security firms are still clueless as to what Conficker.C will do and this alone makes Conficker.C a potentially dangerous worm that should not be taken lightly by anyone especially when April Fool&#8217;s day rolls around.</p>
<p>What are your plans for April 1st &#8211; April Fool&#8217;s Day? Will you be reading the latest information about Conficker.C or do you plan on sharing an April Fool&#8217;s Day joke about your computer crashing because of Conficker? It may not be that funny if that really does happen. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/conficker-c-the-april-fools-day-worm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Serious Affects: Conficker Infection Grounded French Air Force</title>
		<link>http://www.spywareremove.com/security/serious-affects-conficker-infection-grounded-french-air-force/</link>
		<comments>http://www.spywareremove.com/security/serious-affects-conficker-infection-grounded-french-air-force/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 23:24:19 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/serious-affects-conficker-infection-grounded-french-air-force/</guid>
		<description><![CDATA[ <h3 class="posttitle">Conficker Worm is still on the loose while upgraded to launch new attacks with Conficker B++</h3>

It is pretty serious when a virus infection has the ability to penetrate a military network and then ground an Air Force fleet. That is pretty much what happened to the French Air Force lately when the Conficker worm was used to penetrate the French military networks which then grounded the French Air Force.

This instance of Conficker may be a laughing matter for some but this is serious business considering that a military force was unable to function as normal due to Conficker causing serious havoc.  ]]></description>
			<content:encoded><![CDATA[<h3 class="posttitle">Conficker Worm is still on the loose while upgraded to launch new attacks with Conficker B++</h3>
<p>It is pretty serious when a virus infection has the ability to penetrate a military network and then ground an Air Force fleet. That is pretty much what happened to the French Air Force lately when the <a href="http://www.spywareremove.com/removeWin32ConfickerAA.html" title="Win32/Conficker.AA Removal Guide">Conficker worm</a> was used to penetrate the French military networks which then grounded the French Air Force.</p>
<p>This instance of Conficker may be a laughing matter for some but this is serious business considering that a military force was unable to function as normal due to Conficker causing serious havoc. </p>
<p>It just goes to show that the Conficker Worm infection, or Downadup, has literally spread to millions and is actually affecting many networks around the world. Now researchers estimate 10.5 million computers are infected with Conficker. Even still, a new variant of the Conficker worm was recently discovered dubbed Conficker B++.</p>
<p>Conficker B++ is a new version of the well known Conficker worm infection that seems to be very similar in nature but has new techniques for downloading software giving its creators a new level of flexibility for what they do with the infected machines. If you are not familiar with Conficker then you must known that it is known to basically turn infected computers into zombies were they are under the control of the hackers that originate the attack. In many cases the compromised systems are programmed to send spam, log keystrokes or even launch DoS (denial of service) attacks.</p>
<p>Unfortunately it may be expected to see Conficker B++ spread on a mass scale just like the original Conficker worm or Downadup infection. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/serious-affects-conficker-infection-grounded-french-air-force/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker, Downadup, and Kido Worm Infects Millions of Computers Worldwide</title>
		<link>http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/</link>
		<comments>http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 22:46:25 +0000</pubDate>
		<dc:creator>ghostrider01</dc:creator>
				<category><![CDATA[Conficker Worm]]></category>

		<guid isPermaLink="false">http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/</guid>
		<description><![CDATA[ <h3 class="posttitle">The Conficker Worm has caused a serious worldwide epidemic by infecting close to 10 million computers around the world.</h3>

Some security researchers and news publications have deemed the Conficker Worm “a new digital plaque” and that is just what it is if you consider the fact that is has infected almost 10 million computers worldwide. There is still speculation as to who may have programmed this infection and what may take place with any newer versions in the future. 

We have laid out several details about the Conficker worm including a link to complete removal instructions that guides you through a process on how to remove Conficker Worm from your computer. ]]></description>
			<content:encoded><![CDATA[<p> According to security researchers, the Conficker Worm has caused a serious worldwide epidemic by infecting close to 10 million computers around the world.</p>
<p>Security researchers and news publications have deemed the Conficker Worm &#8220;a new digital plaque&#8221; and that is just what it is if you consider the fact that is has infected almost 10 million computers worldwide. There is still speculation as to who may have programmed this infection and what may take place with any newer versions in the future. </p>
<p>We have laid out several details about the Conficker worm including a link to a removal tool that helps you automatically remove the Conficker Worm from your computer.</p>
<h3 class="posttitle">Removal of Conficker Worm</h3>
<p>Conficker worm can be successfully removed from a Windows system. The free Conficker Removal Tool listed below is recommended so that all directory locations of the worm can be identified and then safely removed from the affected system. </p>
<h4 class="posttitle">Free Conficker Removal Tool (Recommended)</h4>
<table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="100%" height="50">
<tr>
<td width="7%">
<a href="/download/cfremover.exe" title="Download Conficker Removal Tool"><img border="0" src="/images/download-icon-red.png" width="38" height="38"></a></td>
<td width="186%"><b><br />
<a href="/download/cfremover.exe" title="Download Conficker Removal Tool"><span style="font-size:11pt;">Download Free Conficker Removal Tool.</span></a></b></td>
</tr>
</table>
<ul>
<li>Press the &#8220;Proceed&#8221; button in the program to start the first step on removing Conficker.</li>
<li>Continue the step-by-step instructions until you&#8217;ve successfully removed the Conficker Worm.</li>
</ul>
<h3 class="posttitle">Conficker Worm Aliases</h3>
<p>Conficker, Conficker Worm, Win32/Conficker, Win32/Conficker.A, Win32/Conficker.AA,, Downadup, W32.Downadup.</p>
<h3 class="posttitle">Type of Computer Infection</h3>
<p>Conficker had been classified as a Worm that exploits the MS08-067 vulnerability so that it may spread. </p>
<h3 class="posttitle">Affected Computers</h3>
<p>Conficker is known to affect personal computers and network systems running the Windows operating system. Versions of the Windows operating system affected include Windows 2000, Windows NT, Windows XP, Windows Server 2003 and Windows Vista. </p>
<h3 class="posttitle">Conficker Worm Symptoms</h3>
<p>Conficker worm may drop copies of itself onto the following files:</p>
<p>%Temp%\[Random].dll<br />
%System%\[Random].tmp<br />
%Temp%\[Random].tmp<br />
%Program Files%\Internet Explorer\[Random].dll<br />
%Program Files%\Movie Maker\[Random].dll<br />
%All Users Application Data%\[Random].dll </p>
<p>In addition to affecting the files above, Conficker may perform the following malicious actions:</p>
<ul>
<li>Block access to security related web sites.</li>
<li>Block access to other domains related to Conficker repair or removal information such as certain Microsoft pages.</li>
<li>Create additional autorun.inf files.</li>
<li>Create scheduled tasks.</li>
<li>Create registry keys in specific files and registry keys with empty permissions.</li>
<li>Perform a network portscan on port 445.</li>
<li>Disable security services that may be running on the infected system.</li>
</ul>
<p><strong>The following registry entries may be modified by the Conficker infection:</strong></p>
<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\&#8221;ServiceDll&#8221; = &#8220;Path to worm&#8221;<br />
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\&#8221;ImagePath&#8221; = %SystemRoot%\system32\svchost.exe -k netsvcs</p>
<h3 class="posttitle">Method of Infection</h3>
<p>The Conficker worm creates a copy of itself in a variable location in the %System% directory for Windows. The default installation directory for Conficker for different versions Windows are as follows:</p>
<ul>
<li>Windows NT and Windows 2000 &#8211; C:\Winnt\System32</li>
<li>Windows 95, 95, ME &#8211; C:\Windows\System</li>
<li>Windows XP and Windows Vista &#8211; C:\Windows\System32</li>
</ul>
<h3 class="posttitle">How does Conficker Spread?</h3>
<p>Conficker exploits the Microsoft server service vulnerability MS08-067 which was first reported back in October of 2008. The patch applied by Microsoft in October 2008 does not eliminate the threat of the current Conficker worm infection. Conficker is also known to be spread through USB flash drives or over networked systems. </p>
<h3 class="posttitle">Conficker Worm Payload</h3>
<p>Conficker has the ability to download and execute arbitrary files. After Decebember 1st, 2008, Conficker connects to the domain trafficconverter.biz to download and execute a malicious file from the location <em>http://trafficconverter.biz/<censored>/loadadv.exe.</em> The infection attempts to access certain domain names listed below. [source: ca.com]</p>
<p>ahayw.info<br />
ajcminmqpeu.com<br />
anosb.biz<br />
aqgcurmt.net<br />
bdfbobhuls.com<br />
bjmqxoxbmyq.org<br />
bszeu.info<br />
cfcpreiwtgx.net<br />
cpfgbuwqv.biz<br />
cukpubgb.net<br />
dconkp.com<br />
dpxzsrjhsn.org<br />
dtyqryfi.biz<br />
dviwvh.net<br />
dwmpveim.info<br />
dxnlypjjxp.biz<br />
eaguzulxdr.org<br />
ekrohmqa.info<br />
eoblibwqaig.info<br />
epvzvuah.info<br />
ethogxkt.net<br />
euwqeixq.biz<br />
exxcpxm.net<br />
eyjayqmwxxo.org<br />
ezhvnjlvuk.org<br />
fdzwsak.net<br />
gatkcy.org<br />
gceqy.info<br />
ggcnqnr.info<br />
gkmdbporqmp.biz<br />
gmtgpb.org<br />
guiahproe.info<br />
gxepchol.net<br />
gztql.net<br />
haqrcz.com<br />
hkqrhqev.com<br />
hndrijmu.org<br />
hvxmlcc.org<br />
idahdfyojhz.com<br />
ipbdwihw.info<br />
iquvtfhm.net<br />
irhtphctgn.com<br />
ivouyvxaf.net<br />
jfvyipo.info<br />
jhhwydtk.com<br />
jjbuafs.info<br />
jptplynb.org<br />
jutsyu.com<br />
kagvjo.com<br />
kfzksydrct.org<br />
khvdkdjnrhr.biz<br />
ktivtbse.net<br />
lbori.com<br />
ltxbrwfosrg.net<br />
mhjhb.com<br />
mtqcpiwod.biz<br />
nsjmewgdb.com<br />
ntshnjyxfh.net<br />
nxphotp.com<br />
ocykqj.biz<br />
oenjrcaly.net<br />
oororgpkbp.com<br />
ozlqvnkiq.net<br />
palrw.org<br />
pmotqmf.com<br />
pvuxb.info<br />
qffszcfgyzn.org<br />
qfoilcqp.com<br />
qjafgfp.net<br />
rfduzjbztg.biz<br />
riuvunis.info<br />
rlbidexd.org<br />
rntbogfz.biz<br />
rtkrhxsp.biz<br />
ruolomicarp.org<br />
rxytvgkapvw.biz<br />
safxg.net<br />
sdxkcnzcvhd.org<br />
shbyxebiec.biz<br />
srsoeggve.org<br />
tbkmloh.net<br />
tezjm.net<br />
tilazlfn.com<br />
tqlxquy.org<br />
trxho.org<br />
uiiwmmgr.com<br />
upyuqxpmlxt.net<br />
vdunf.net<br />
vtewiyny.info<br />
vuahzmvf.biz<br />
vweoof.org<br />
wkjhjr.com<br />
xehlydgan.net<br />
xmmzcsqm.biz<br />
xtjejduc.org<br />
xxwoteojg.biz<br />
xytbvkrqhu.info<br />
ybhufq.net<br />
yenhbrt.biz<br />
yfczve.info<br />
ylfamhcgn.net<br />
ylzbgyorfy.org<br />
ysxbkquj.info<br />
ythekdrar.net<br />
yudxsol.org<br />
yzbvrteij.biz<br />
yzpjvpkdtq.biz<br />
zjxuw.org<br />
zpqhr.biz<br />
zuuroktw.biz<br />
zzkjecmf.com</p>
<p>A reference file from <em>http://www.maxmind.com/<censored>/GeoIP.dat.gz</em> is also accessed by Conficker.</p>
<p><strong>Note:</strong> Security researchers have also discovered that Conficker has backdoor functionality which may have aided in the vast spread of Conficker among millions of computers around the world. In this process Conficker starts a HTTP server on the affected computer by opening a random port. This process allows a copy of Conficker to be downloaded by target systems.</p>
<p><strong>We want to know if you have experienced the Conficker Worm. Post your experienced below.</strong> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spywareremove.com/security/conficker-downadup-kido-worm-infects-millions-of-computers/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
