BEWARE!! Worm Alert ! Confliker – next one after Slammer!!

Win32/Conficker is a worm that spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability ( CVE-2008-4250 / CIVN-2008-170 ).  If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled.

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

Win32/Conficker disables a number of system services such as Windows Automatic Update, Windows Security Center, Windows Defender and Windows Error Reporting and Internet connection sharing service.

It propogates by creating an autorun.inf file on all mapped drives so that it automatically executed as soon as the drive becomes accessible.

Screenshot of the autorun.inf file is pictured below(source :SANS)


Up on execution the autoplay window will pop up as given below

The first part, "Install or run program" is there because the autorun.inf file containing the shellexecute keyword. However, the text comes from the Action keyword and the icon is extracted from shell32.dll (the 4th icon in the file) which is the standard folder icon which will run the worm

The worm also monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network request timed out thereby restricting users from updating their security software from those websites.

Find the details: 

Use these FREE Removel Tools to prevent and clean up the system from the worm:

Prevention is better than cure. The following actions are advised in order to prevent infection from this Worm:

  • Disable autoplay/autorun features on all drives and devices.
  • Refer the following articles for relevant steps and patches:
  • Block ports 139 and 445 at the perimeter.
  • Install and maintain updated anti-virus software at gateway and desktop level
  • Install and maintain Desktop Firewall and block the ports which are not required
  • Use caution when opening attachments and accepting file transfers
  • Use caution when clicking on links to web pages
  • Refer the following Guidance articles from Microsoft for protection against Conficker worm.



    12 thoughts on “BEWARE!! Worm Alert ! Confliker – next one after Slammer!!”

    1. Acer travelmate 2420 series Battery Acer white aspire one zg5 Battery Apple 17 inch powerbook g4 Battery Apple a1189 Battery Asus a2000 Battery Asus a2500h Battery Asus a3000 Battery Asus a32-f5 Battery Asus a32-s5 Battery Asus a4 Battery Asus a4000 Battery Asus a42-a3 Battery Asus a42-a4 Battery Asus a42-v6 Battery Asus a42-w1 Battery Asus f3 Battery laptop batteries Asus f5 Battery Dell latitude c400 Battery Dell inspiron b120 Battery Dell inspiron b130 Battery Dell latitude d610 Battery Dell rn873 Battery Gateway 12msb Battery Dell vostro 1000 Battery Dell xps m1210 Battery Gateway 8msb Battery Gateway 8msbg Battery Compaq pavilion dv2000 Battery Compaq pavilion dv6000 Battery Compaq v6000 Battery Dell 1501 Battery Dell inspiron 1300 Battery Dell e1505 Battery Dell gd761 Battery Dell gk479 Battery Dell inspiron 1525 Battery Dell inspiron 2000 Battery Dell inspiron 2100 Battery Dell inspiron 2200 Battery Dell inspiron 5100 Battery Dell inspiron 5160 Battery Dell d400 Battery Dell d5318 Battery Clevo d400 Battery

    2. Compaq dv1000 Battery Compaq dv2000 Battery Compaq dv2200 Battery Compaq dv4000 Battery Compaq dv6000 Battery Compaq dv6500 Battery Compaq hstnn-db42 Battery Compaq n600 Battery Compaq n600c Battery Compaq n610 Battery Compaq n610c Battery Compaq nc4200 Battery Toshiba pa3285u-1bas Battery Toshiba pa3285u-1brs Battery Toshiba pa3285u-3bas Battery Toshiba pa3331u-1brs Battery Toshiba pa3395u-1brs Battery Toshiba pa3399u-1bas Battery Toshiba pa3399u-1brs Battery Toshiba pa3399u-2bas Battery Toshiba pa3399u-2brs Battery Toshiba pa3420u Battery Toshiba pa3421u-1brs Battery Toshiba pa3456u-1brs Battery Toshiba pa3465u-1brs Battery Toshiba pa3533u-1bas Battery Toshiba pa3533u-1brs Battery Toshiba pa3534u-1bas Battery Toshiba pa3535u-1bas Battery Toshiba pa3535u-1brs Battery Hp pavilion dv2000 Battery Hp pavilion dv6000 Battery Toshiba pa3285u-3brs Battery Sony vgp-bps2 Battery Apple a1185 Battery Apple a1185 black Battery Apple a1185 white Battery Sony vgp-bps2a Battery Sony vgp-bps2b Battery Sony vgp-bps2c Battery Toshiba pa3536u Battery Toshiba pa3536u-1brs Battery Hp 510 Battery Hp 6735 Battery Hp 7400 Battery Hp b1900 Battery

    Leave a Comment

    Fill in your details below or click an icon to log in: Logo

    You are commenting using your account. Log Out / Change )

    Twitter picture

    You are commenting using your Twitter account. Log Out / Change )

    Facebook photo

    You are commenting using your Facebook account. Log Out / Change )

    Google+ photo

    You are commenting using your Google+ account. Log Out / Change )

    Connecting to %s