April 1 has come and gone, and the Internet has not disintegrated and no major cyber-attacks were reported. But Conficker still remains a threat. Now don't panic, this doesn't mean cyber-Armageddon could strike at any minute, it just means you need to make sure your computer is fully updated if it isn't already. Feel better? Good, then let's take a look at what's going on.
Why It Ain't Over Yet
The Conficker Working Group -- which is made up of 27 tech companies and agencies including AOL, F-Secure, Facebook, ICANN, Kaspersky, McAffee, Microsoft, Symantec -- says that Conficker, also known as Downup, Downadup, and Kido, is the largest worldwide computer infection since the SQL Slammer in 2003. The CWG estimates anywhere from 3 to 15 million computers are infected worldwide, and says 30 percent of Windows computers across the globe are not updated with the latest patches to protect against Conficker. The virus authors are also still at large and able to communicate with Conficker, although that capability has been significantly reduced.
Problem Spots
As you can see from this map provided by the CWG, Conficker infections in the United States are happening pretty much everywhere you can find an Internet connection. However, despite all that ominous-looking red, only 6 percent of Conficker infections are in North America. The biggest problem areas are actually concentrated in Asia and South America including Vietnam, Brazil, the Philippines, and Indonesia, as well as Algeria.
The hardest hit areas may also have a correlation to the number of unpatched Windows computers since Asia, Eastern Europe, and South America are areas known to have widespread use of pirated Windows software. Since Microsoft automatically blocks illegitimate copies of Windows from receiving critical updates, those computers remain vulnerable to Conficker, thus perpetuating the risk.
What Conficker is Doing
Yesterday, Conficker began its daily exercise of contacting 500 Web sites from a randomly generated list of 50,000 sites. Conficker will continue to do this every day until it receives instructions to do something else. Further instructions could be a simple software update or the infected computers could work as a botnet to commit theft or attack other computer networks. The problem is that while security and IT professionals are working to block Conficker from getting further instructions, they haven't been able to block all Conficker traffic. So some infected machines have gotten through, but luckily further instructions haven't been issued, yet. Conficker's authors may be laying low until publicity surrounding Conficker dies down before contacting their creation.
If Conficker is updated or receives further instructions, that capability could pass between infected machines without further need of a server or Web site, because Conficker uses a peer-to-peer (p2p) protocol to communicate with other infected machines. That's right, Conficker is file-sharing. With p2p, the worm can distribute software updates much faster than if every infected machine had to communicate with a main server.
The Final Countdown?
Does this mean the world could still end? Probably not, and that was never the concern with Conficker despite the doomsday scenarios you may have read. The fact is that most security experts believe that Conficker is just a typical botnet worm that can be used for identity theft or to commit other forms of cybercrime. Conficker is most likely controlled by an organized crime syndicate in Asia, Eastern Europe, or South America, and the group may even rent out Conficker's capabilities if the botnet every becomes active.
Conficker is a threat only if your computer does not have the latest security patches from Microsoft and an up-to-date antivirus program.
source: PCWORLD
Conficker D-Day Arrives; Worm Phones Home (Quietly)
Posted by Unknown | 8:32 PM | Anti Virus | 0 comments »The Conficker worm today has begun to phone home for instructions but has done little else. Conficker was programmed to today begin actively visiting 500 out of 50,000 randomly generated web addresses to receive new instructions on how to behave. Conficker has begun to do this, according to security company F-Secure, but so far no doomsday scenarios have emerged.
Among security experts, the consensus seems to be that very little will happen today. This may be in part because of the high amount of publicity Conficker has received, but then again April 1 is not the first time Conficker has been programmed to change the way it operates. Similar trigger dates have already passed with little change, including January 1, according to according to Phil Porras, a program director with SRI International. Security experts at Symantec, the maker of Norton Antivirus, also believe the threat is overblown and says Conficker today will "start taking more steps to protect itself" and "use a communications system that is more difficult for security researchers to interrupt."
Technology companies and experts across the globe have been working together to halt the spread of Conficker, disrupt its communications and uncover who created the worm. Microsoft has even issued a $250,000 bounty for information leading to the arrest and conviction of Conficker's authors. Despite the security sector's best efforts, very little is known about the origins of Conficker or its purpose. Nevertheless, some breakthroughs have been achieved. On March 30, Security experts with the Honeynet Project discovered a flaw in Conficker that makes it much easier to detect infection. IBM researcher Mark Yayson also believes he has discovered a way to "detect and interrupt the program's activities," according to The New York Times.
Since the Conficker worm was discovered in October 2008, the malware has only received programming updates from its author and worked to infect other computers. Conficker is believed to have infected 10 million computers worldwide mostly in Asia, Europe and South America. According to IBM, only 6 percent of North American computers have been infected.
While today may be a non-event, Conficker could be used to create harm in the future. Possiblities include a massive botnet, which would give Conficker's authors control over millions of computers worldwide. The botnet could then be used to attack corporate or government networks, commit identity theft, or deliver massive amounts of spam. Security experts warn that all Windows users must make sure their operating system and antivirus programs are up to date with the latest patches and virus protections. So far, Windows is the only operating system known to be vulnerable to Conficker.
source: PCWORLD
Here are our picks for no-cost ways to protect your PC, including Avast Home Edition, SpywareBlaster, and more.
Your PC is under attack on all fronts.
These eight free downloads and services will help you beat back the bad guys with antivirus and antispyware programs, personal firewalls, and even a program that can detect whether your Web site is under attack.
BEST BET Avast Home Edition: The big names in security software charge you big bucks for big suites full of big, bloated software. It scans your system for malware and kills what it finds, and gives you seven different types of "shields" to keep you safe from harm, such as one for protecting you from dangers that might be lurking on Web sites (such as drive-by downloads), one for guarding against peer-to-peer attacks, another that stops instant messaging threats, and so on. And it does all that, amazingly enough, without taking up much RAM or system resources.
a-Squared HiJackFree: Spyware is notorious for evading even the most rigorous cleaners, which is why you need more than one antispyware utility on your PC. HiJackFree is a great download to use in concert with your main antispyware program for extra protection. Rather than offering a live shield, it checks your system for spyware and then eradicates it. For the geeky, it offers a lot more as well, such as tools for viewing what programs are using your TCP ports, and for examining programs that run on startup.
Attack Trace: Worried that the bad guys are targeting your Web site? This free service checks to see if your site is under attack.
Comodo EasyVPN Home: This download allows you to create secure peer-to-peer networks over the Internet for sharing information, chatting, and so on. Everything is encrypted, so no one else will be able to snoop on what you're doing.
EULAlyzer: Hidden in some end-user license agreements (EULAs) are indicators that the software may be spyware, or that it might invade your privacy in other ways. This downloadable analyzer examines EULAs and warns you about dangers.
Online Armor Personal Firewall: This is the best personal firewall you've never heard of. It provides solid protection, but unobtrusively. Lots of firewalls bug you constantly when you first install them, asking about any program that wants to access the Internet. This software starts out by allowing known safe applications to access the Web and bothers you only about the programs it's unsure about. It also has a clever "Safer mode" that will allow certain apps to run with stripped-down privileges.
SpywareBlaster: With this downloadable antispyware utility, you can make sure you don't get infected in the first place rather than scanning for and killing spyware after it hits your machine. It works differently from most competitors by restricting the actions that potentially dangerous Web sites can perform when you visit them. It also protects against dangerous ActiveX controls, and keeps tracking cookies off your PC.
SuperAntiSpyware: Here's an excellent antispyware tool that does a thorough job of scanning your system for dangers, and then whacks any it finds. This download scans not just your files and memory, but also your Registry. It doesn't offer real-time protection, though.
source: www.pcworld.com
Symantec is warning Web users that searching for information on computer viruses such as Conficker could put them at risk of unintentionally downloading the virus on to their PC.
Conficker targets a flaw in Windows Server and despite Microsoft releasing an emergency patch and urging all Web users to download it, many machines remain unprotected.
According to the security vendor, searching for 'conficker' in a number of the Web's most popular search engines brings up a number of hoax Websites that actually host the virus and infect any users that navigate to the site.
Symantec warns Web users the best course of action is to use software that will block Web pages such as these from being visited.
"Be careful with the links you follow. A sincere effort of keeping abreast with the latest security information might contain some unwelcome surprises," the security firm added.
A third version of the virus was also discovered this month and security researchers believe it may cause problems on April Fools Day.
"It's set to go off April 1, 2009 and Conficker will generate 50,000 URLS daily," said Computer Associates director of threat research, Don DeBolt.
* Sponsored Resource:Improve your productivity and simplify your tasks with these tech gadgets.
* Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
* Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
* Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
* Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Macworld

License: Free
Operating Systems: Windows Vista, Windows 95, Windows Me, Windows 2000, Windows NT, Windows XP, Windows 98
Additional Requirements: Windows 95/98/Me/NT/2000/XP/Vista
Limitations: No limitations
Avast Home Edition is a complete ICSA & Checkmark certified antivirus, Checkmark certified anti-spyware & anti-rootkit package. Avast includes the following components: On demand scanner with skinnable simple interface, just select what do you want to scan in which way and press the Play button; On access scanner, special providers to protect the most of available e-mail clients; Instant messaging--ICQ, Miranda; Network traffic--intrusion detection, lightweight firewall; P2P protection for Kazaa, BitTorrent; Web shield--monitors and filters all HTTP traffic; NNTP scanner--scans all Usenet Newsgroup traffic and all operations with files on PC; Boot time scanner--scans disks in the same way and in the same time as Windows CHKDSK does.
Version 4.8.1335.90205 brings many improvements in the scanning engine as well as performance optimizations.
You'll have to register (free) on the publisher site to be able to continue using this program after 60 days.
you can download on avast
source : www.avast.com and www.download.com
License: Free
Operating Systems: Windows Vista, Windows XP, Windows 2000
Additional Requirements: Windows 2000/XP/Vista
Limitations: No limitations
AVG Free Edition is the well-known antivirus protection tool. AVG Free is available free of charge to home users for the life of the product. Rapid virus database updates are available for the lifetime of the product, thereby providing the high level of detection capability that millions of users around the world trust to protect their computers. AVG Free is easy to use and will not slow your system down (low system resource requirements. Highlights include automatic update functionality, the AVG Resident Shield, which provides real-time protection as files are opened and programs are run, free Virus Database Updates for the lifetime of the product, and AVG Virus Vault for safe handling of infected files.
Version 8.0.233 includes wide array of bug fixes and improvements, included a revamped UI that allows easier management via keyboard.
you can donwload free.avg.com
source : www.download.com/ and free.avg.com
With Global Effort, a New Type of Worm Is Slowed
Posted by Unknown | 5:12 AM | Anti Virus | 0 comments »
There have been big computer worm outbreaks before, but nothing quite like Conficker.
First spotted in November, the worm had soon infected more computers than any worm in recent years. By some estimates it is now installed on more than 10 million PCs. But ever since its first appearance, it has been strangely quiet. Conficker infects PCs and spreads around networks, but it doesn't do anything else. It could be used to launch a massive cyberattack, crippling virtually any server on the Internet, or it could be leased out to spammers in order to pump out billions upon billions of spam messages. Instead, it sits there, a massive engine of destruction waiting for someone to turn the key.
Until recently, many security researchers simply didn't know what the Conficker network was waiting for. On Thursday, however, an international coalition revealed that they had taken unprecedented steps to keep the worm separate from the command-and-control servers that could control it. The group is comprised of security researchers, technology companies, domain name registrars who have joined forces with the Internet Corporation for Assigned Names and Numbers (ICANN), which oversees the Internet's Domain Name System.
Researchers had taken apart Conficker's code and discovered that it uses a tricky new technique to phone home for new instructions. Each day, the worm generates a fresh list of about 250 random domain names such as aklkanpbq.info. It then checks those domains for new instructions, verifying their cryptographic signature to ensure that they were created by Conficker's author.
When Conficker's code was first cracked, security experts snatched up some of these randomly generated domains, creating what are known as sinkhole servers to receive data from hacked machines and observe how the worm worked. But as the infection became more widespread, they began registering all of the domains -- close to 2,000 per week -- taking them out of circulation before criminals had a chanc. If ever the bad guys tried to register one of these command-and-control domains, they would have found that they'd already been taken, by a fictional group calling itself the "Conficker Cabal." Its address? 1 Microsoft Way, Redmond Washington.
This is a new kind of cat-and-mouse game for researchers, but it has been tested a few times over the past few months. In November, for example, another group used the technique to take control of domains used by one of the world's largest botnet networks, known as Srizbi, cutting it off from its command-and-control servers.
With thousands of domains, however, this tactic can become time consuming and expensive. So with Conficker, the group has identified and locked up names using a new technique, called domain pre-registration and lock.
By dividing up the work of identifying and locking out Conficker's domains, the group has only kept the worm in check, not dealt it a fatal blow, said Andre DiMino, co-founder of The Shadowserver Foundation, a cybercrime watchdog group. "This is really the first key effort at this level that has the potential to make a substantial difference," he said. "We'd like to think we've had some effect in crippling it."
This is uncharted territory for ICANN, the group responsible for managing the Internet's address system. In the past, ICANN has been criticized for being slow to use its power to revoke accreditation from domain name registrars who have been widely used by criminals. But this time it's getting praise for relaxing rules that made it hard to lock down domains and for bringing together the group's participants.
"In this specific case they greased the wheels so that things would move quickly," said David Ulevitch, founder of OpenDNS. "I think they should be commended for that. ... It's one of the first times that ICANN has really done something positive."
The fact that such a diverse group of organizations are all working together is remarkable, said Rick Wesson, CEO of network security consultancy Support Intelligence. "That China and America cooperated to defeat a malicious activity on a global scale... that's serious. That's never happened," he said.
ICANN did not return calls seeking comment for this story and many of the participants in the Conficker effort, including Microsoft, Verisign and the China Internet Network Information Center (CNNIC) declined to be interviewed for this article.
Privately, some participants say that they do not want to draw attention to their individual efforts to combat what may well be an organized cybercrime group. Other say that because the effort is so new, it is still premature to discuss tactics.
Whatever the full story, the stakes are clearly high. Conficker has already been spotted on government and military networks and has been particularly virulent within corporate networks. One slip-up, and Conficker's creators could reprogram their network, giving the computers a new algorithm that would have to be cracked and giving them an opportunity to use these computers for nefarious purposes. "We have to be 100 percent accurate," Wesson said. "And the battle is a daily battle."
source : PCWORLD

Conficker, also known as Downup, Downadup and Kido, is a computer worm that surfaced in October 2008 and targets the Microsoft Windows operating system.[1] The worm exploits a known vulnerability in the Windows Server service used by Windows 2000, Windows XP, Windows Vista, Windows Server 2003 and Windows Server 2008.[2] Linux and Macintosh systems are unaffected as the virus only targets Windows software.
Origin of name
The name "Conficker" is a German pun, meaning "program that manipulates the configuration," and pronounced like the English word "configure." "Configuration" is typically abbreviated "config." Conficker is constructed from the first five letters of "configuration," while adding four letters to the end so as to end with "ficker", a vulgar nominalized form of the German transitive verb ficken, which is common German for the English "fuck".
Operation
The Conficker worm spreads itself primarily through a buffer overflow vulnerability in the Server Service on Windows computers. The worm uses a specially crafted RPC request to execute code on the target computer.
When executed on a computer, Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting. It then connects to a server, where it receives further orders to propagate, gather personal information, and downloads and installs additional malware onto the victim's computer. The worm also attaches itself to certain Windows processes such as svchost.exe, explorer.exe and services.exe.
Payload
The A variant of Conficker will create an HTTP Server and open a random port between 1024 and 10000. If the remote machine is exploited successfully, the victim will connect back to the HTTP server and download a worm copy. It will also reset System Restore Points, and download files to the target computer.
Symptoms of infection
* Account lockout policies being reset automatically.
* Certain Microsoft Windows services such as Automatic Updates, Background Intelligent Transfer Service (BITS), Windows Defender and Error Reporting Services are automatically disabled.
* Domain controllers respond slowly to client requests.
* System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.
* On websites related with antivirus software, Windows system updates cannot be accessed.
In addition, the worm launches a brute force dictionary attack against administrator passwords to help it spread through ADMIN$ shares, making choice of sensible passwords advisable.
Impact
By January 16, 2009, antivirus software vendor F-Secure reported that Conficker had infected almost 9 million PCs.[9][10] The New York Times reported that Conficker had infected 9 million PCs by January 22, 2009, while The Guardian estimated 3.5 million infected PCs.[11][12] As of January 26, 2009, Conficker had infected more than 15 million computers, making it one of the most widespread infections in recent times.
Another antivirus software vendor Panda Security reported that of the 2 million computers analyzed through ActiveScan, around 115,000 (6%) were infected with this malware.
Conficker is reported to be one of the largest botnets created because 30 percent of Windows computers do not have the Microsoft Windows patch released in October 2008.
The U.K. Ministry of Defence reported that some of its major systems and desktops are infected. The worm has spread across administrative offices, NavyStar/N* desktops aboard various Royal Navy warships and Royal Navy submarines, and Hospitals across the city of Sheffield reported infection of over 800 computers.
Experts say it is the worst infection since the SQL Slammer.
As of February 13 2009, Microsoft is offering a $250,000 USD Reward for information leading to the arrest and conviction of hackers behind the creation and or distribution of Conficker.
[edit] Patching and removal
On 15 October 2008 Microsoft released a patch (MS08-067) to fix the vulnerability.[20] Removal tools are available from Microsoft,[21] Symantec[22] and Kaspersky Lab while McAfee[23] can remove it with an on demand scan.[24] Since the virus can spread via USB drives that trigger AutoRun, disabling the AutoRun feature for external media through modifying the Windows Registry is recommended.[25] While Microsoft has released patches for the later Windows XP Service Packs 2 and 3 and Windows 2000 SP4 and Vista, it has not released any patch for Windows XP Service Pack 1 or earlier versions (excluding Windows 2000 SP4), as the support period for these service packs has expired.
[edit] Technology industry collaboration to combat Conficker
On February 12, 2009, Microsoft announced the formation of a technology industry collaboration to combat the effects of Conficker. Organizations involved in this collaborative effort include Microsoft, Afilias, ICANN, Neustar, Verisign, CNNIC, Public Internet Registry, Global Domains International, Inc., M1D Global, AOL, Symantec, F-Secure, ISC, researchers from Georgia Tech, The Shadowserver Foundation, Arbor Networks and Support Intelligence.
Microsoft is trying to put some pressure on the criminals responsible for the worst Internet worm outbreak in years, offering a $250,000 reward for information leading to the arrest and conviction of Conficker's creators.[26]
Microsoft's reward offer stems from the company's recognition that the Conficker worm is a criminal attack. Microsoft wants to help the authorities catch the criminals responsible for it. Residents of any country are eligible for the reward, according to the laws of that country, because Internet viruses affect the Internet community worldwide. Individuals with information about the Conficker worm should contact their international law enforcement agencies.
ICANN is the global coordinating body for domain names. Afilias is the registry operator for .INFO domains and the service provider for Public Interest Registry's .ORG domains worldwide. Neustar runs .BIZ, Verisign is the largest registry and runs .COM and .NET, and CNNIC runs .CN.
source: wikipedia
If this happen to yours computer attack by conficker, make your computer can't connect to network. But don't worry you can remove step by step.
1. Put off yours computer from network include LAN and WIFI.
2. Shutdown system restore on yours computer(Vista and XP only)
Start-->Program-->accessories-->system tool-->System restore.
after you inside turn off system restore for all drive.
for next step...read more
3. Turn off any service on your computer, you can use tool from Norman by free. you can download here
4. Delete service svchost.exe on your computer is that make by conficker.
5. Delete Schedule Task that make by conficker (C:-WINDOWS-Tasks).
6. Delete Registry string that make by conficker, for easy you can copy this script to notepad and install.
[Version]
Signature="$Chicago$"
Provider=Vaksincom Oyee
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[UnhookRegKey]
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, Hidden, 0x00000001,1
HKCU, Software-Microsoft-Windows-CurrentVersion-Explorer-Advanced, SuperHidden, 0x00000001,1
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Explorer-Advanced-Folder-Hidden-SHOWALL, CheckedValue, 0x00000001,1
HKLM, SYSTEM-CurrentControlSet-Services-BITS, Start, 0x00000002,2
HKLM, SYSTEM-CurrentControlSet-Services-ERSvc, Start, 0x00000002,2
HKLM, SYSTEM-CurrentControlSet-Services-wscsvc, Start, 0x00000002,2
HKLM, SYSTEM-CurrentControlSet-Services-wuauserv, Start, 0x00000002,2
[del]
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, dl
HKCU, Software-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, dl
HKLM, SOFTWARE-Microsoft-Windows-CurrentVersion-Applets, ds
HKLM, SYSTEM-CurrentControlSet-Services-Tcpip-Parameters, TcpNumConnections
give this file with "repair.inf". To run this file right click choose run.
7. For optimal remove this virus and make your computer not infected again, you should use update anti virus and pacth yours computer with http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx