0
skymama

Question about the conficker/downadup worm

Recommended Posts

IT Guys...I got this e-mail concerning this worm. Is it true? Anything else we should check or do, besides updating the anti-virus definitions and doing a check?

Quote

Open up Windows Updates, wait for it to go thru its typical rigamarole, then click on "review history" You're looking for KB958644. It was released a few months ago, so you may have to scroll back a bit. KB 958644 is supposed to protect Windows PC's from this worm.


She is Da Man, and you better not mess with Da Man,
because she will lay some keepdown on you faster than, well, really fast. ~Billvon

Share this post


Link to post
Share on other sites

Should have asked me earlier on this one :D

Microsoft Security fix MS08-067 is what this KB refers to. The patch covers a vulnerability in the Server service for Windows. The first generation of Conficker used this exploit to cause a buffer overflow on the system and then become infected. Starting with the second generation it uses this hole on the system as well as any open network shares since it introduced an autorun component also. Basically any USB drive could be infected, open shares on the network could hold the virus, etc.

The steps needed to protect yourself from this virus (its a few weeks old already) is to install the MS security updates, do a FULL scan of your system using the latest AV signatures and make sure that it is scanning the memory since this is a memory resident virus that can execute completely from the overflowed memory space. Scan all your USB drives and anything on the network also.

Yesterday is history
And tomorrow is a mystery

Parachutemanuals.com

Share this post


Link to post
Share on other sites

That first paragraph...WHOOSH! Right over my head! :ph34r:

I can handle the second paragraph though. Thanks!

She is Da Man, and you better not mess with Da Man,
because she will lay some keepdown on you faster than, well, really fast. ~Billvon

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

0