Conficker C is now dubbed as “April Fool’s Day Worm.” This is a new worm the latest variant of Conficker.A and Conficker.B that will hit the wild on April , 2009. Conficker.C resets all system restore points, deletes any saved system restore points, downloads component files using time-based generated URLs, generates 50,000 URLs and reports back to 500 of them. It sets read only, hidden and system file attributes, generates a file creation/access time-stamp based on kernel132.dll, creates access control entries, and exclusively locks files to restrict access and privileges and to prevent removal.
Other security companies have labeled this same worm Win32/Conficker.D (MS OneCare), W32/Confick-G (Sophos) and Trojan.Win32.Pakes.ngs (Kaspersky). If you’ve got it on your machine, only way you might know is if your computer suddenly accesses one of several popular sites like Ask.com, Baidu, Facebook, Google, Imageshack.us, rapidshare.com, W3.org, or Yahoo!. This is how the worm tests for Internet connectivity. source: BusinessMirror.com.ph
Download: Conficker Worm Removal Tools.
Related posts:
Comments