Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Conficker Virus - MS patch

Thread Tools
 
Search this Thread
 
Old 20 January 2009, 07:44 PM
  #1  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default Conficker Virus - MS patch

For windows xp - http://www.microsoft.com/downloads/d...displaylang=en

Estimates are 9m infections but it hasnt been activated yet.
Old 20 January 2009, 11:23 PM
  #2  
Midlife......
Scooby Regular
iTrader: (2)
 
Midlife......'s Avatar
 
Join Date: Feb 2004
Posts: 11,583
Likes: 0
Received 2 Likes on 2 Posts
Default

I read about this .........anything for Vista

Shaun
Old 20 January 2009, 11:42 PM
  #3  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Run windows update and forget about it. Fixed since last year.
Old 21 January 2009, 08:57 AM
  #5  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

probabily the only people getting hit by this are the ones running a dodgy copy who can't update.
Old 21 January 2009, 09:16 AM
  #6  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by BlkKnight
probabily the only people getting hit by this are the ones running a dodgy copy who can't update.

Not strictly true. Corporates can have slow update policies and extensively test patches before releasing them into the infrastructure. Then there are those corporates who have no IT policy and get caught with their pants down like this....

This patch was released on October 23rd so there really is no excuse.

Sheffield City NHS management should be shot for turning off ALL updates because one pc had an issue with automatic reboots.
Old 21 January 2009, 09:49 AM
  #7  
jaytc2003
Scooby Regular
iTrader: (1)
 
jaytc2003's Avatar
 
Join Date: Aug 2005
Location: Manchester ish
Posts: 18,547
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Kieran_Burns
Not strictly true. Corporates can have slow update policies and extensively test patches before releasing them into the infrastructure. Then there are those corporates who have no IT policy and get caught with their pants down like this.....

So true, company I work for has only just (past few months) done a roll out to update xp pro to service pack 2 - this was after sp3 had been released, and its quite a big company I work for as well
Old 21 January 2009, 09:59 AM
  #8  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

The first tests we did with SP3 hosed XP, so I don't blame them for being slow.

Yesterday we've run into a XP SP3 compatability issue (or so one of the two software vendor is claiming...)
Old 21 January 2009, 10:09 AM
  #9  
MJW
Scooby Senior
 
MJW's Avatar
 
Join Date: Nov 2001
Location: West Yorks.
Posts: 4,130
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by hutton_d
I saw all the media hype about this worm/virus/patch - thought I'd check that I had it installed. (XP). Had to Google how to find out the patches I have installed. Found the easiest way was to look in the registry. So just to point anyone else in the same direction you can use 'regedit' [Start/run/regedit] and look at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\

This lists all the SW you have installed, including patches. You'd think they'd make it easier .......

Dave

PS: they probably do but I couldn't see how ....
If you go into Add/Remove Programs in the Control Panel, tick the box that says 'Show Updates' there's a list of Windows patches at the bottom - easier than dicking around in the registry.

Last edited by MJW; 21 January 2009 at 10:12 AM.
Old 21 January 2009, 10:09 AM
  #10  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

The antivirus companies will be rubbing their hands together as will the ISP's who are allowing this particular piece of code to register the hundreds of domains and hosting packages daily, who's paying and will the card owners be traced and for a refund. Why are the domains continuing to be registered? Would you take steps to stop this lucrative revenue stream?

The efforts of the antivirus companies and ISP's will be minimal I can assure you.
Old 21 January 2009, 11:00 AM
  #11  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

Patches for all OS's

http://www.microsoft.com/technet/sec.../MS08-067.mspx
Old 21 January 2009, 02:54 PM
  #13  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

F-Secures log of originating IP's supports my "dodgy install" theory:

How Big is Downadup? Very Big. - F-Secure Weblog : News from the Lab
Old 21 January 2009, 04:19 PM
  #14  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Default

had some trouble logging into the works CCTV pc from last friday, had a look at it just now and found this downadup thing while doing a safe mode virus scan

avg free 8.0 has found various things and put them in the virus vault, including 2 worms while i was logging into the router via my laptop (flashed on screen)

so i booted it into safe mode and started a full check, thing is the works machine, although only used for the CCTV program, also runs a http server so i can login from home. i found that leaving auto updates switched on was allowing the staff to click the title bar while the bubble thing was on screen and getting to the desktop quite easy, so switched it all off, do not want them to kill the pc and do sneaky valets for cash while i am not around so it needs to stay "locked"

so far the check has found the suspect ecbxse[1].gif file and is ploughing into the rest of the hard drives.

Last edited by StickyMicky; 21 January 2009 at 04:21 PM.
Old 21 January 2009, 04:36 PM
  #15  
STi wanna Subaru
Scooby Regular
iTrader: (1)
 
STi wanna Subaru's Avatar
 
Join Date: Apr 2001
Location: Yorkshire
Posts: 16,517
Likes: 0
Received 0 Likes on 0 Posts
Default

Isn't avg crap?
Old 21 January 2009, 10:49 PM
  #16  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Default

Some people say yes, some people say no, i can only compare it with norton, in that respect its vastly superior!

Cant say i have ever had a real problem with "AVG free" to be honest.

The works cctv machine does nothing except run the CCTV program, dyndns to upload the current IP and a small hhtp server to allow me to login from home, no internet browsing or anything like that, so i am doubtful that paying for some "proper" antivirus program is worth it?


checked the laptop i use at work for browsing, it was clean, also switched auto updates on and found i had 80mb of patches to install

came home and checked the home desktop (took 4 hours to scan in safe mode) and that was clean, need to check the missus`s laptop tomorrow but would assume its going to be fine, suspect i got infected via the cctv machine and that is as far as it got.

Last edited by StickyMicky; 21 January 2009 at 10:52 PM.
Old 22 January 2009, 05:12 AM
  #17  
jono300
Scooby Regular
iTrader: (8)
 
jono300's Avatar
 
Join Date: Sep 2002
Location: Fife - Scotland
Posts: 4,455
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by BlkKnight
probabily the only people getting hit by this are the ones running a dodgy copy who can't update.
Always wondered this ?? so even thou there are many folK using dodgy copies off xp etc they cant actually carry out the updates as the software would be instantly recognised as not being genuine - correct ??

pity !! was going to " borrow " a copy for use with the little acer aspire I have here, getting kinda fed up trying to work with linux !!!
Old 22 January 2009, 08:04 AM
  #18  
jaytc2003
Scooby Regular
iTrader: (1)
 
jaytc2003's Avatar
 
Join Date: Aug 2005
Location: Manchester ish
Posts: 18,547
Likes: 0
Received 0 Likes on 0 Posts
Default

i always thought windows would let you update major security things even with a dodgy copy?

(not actually speaking from experience as mine are all legit)
Old 22 January 2009, 09:51 AM
  #20  
StickyMicky
Scooby Regular
 
StickyMicky's Avatar
 
Join Date: Feb 2003
Location: Zed Ess Won Hay Tee
Posts: 21,611
Likes: 0
Received 0 Likes on 0 Posts
Default

you can usually buy a broken laptop from fleabay with a genuine key it on for pennies, done this a few times in the past
Old 22 January 2009, 10:39 AM
  #21  
GC8
Scooby Regular
 
GC8's Avatar
 
Join Date: Aug 2003
Location: Sheffield; Rome of the North
Posts: 17,582
Likes: 0
Received 0 Likes on 0 Posts
Default

WGA was defeated almost immediately. The only success MS has had has been in acting against any websites who dared to host it. Google: "RemoveWGA".
Old 22 January 2009, 04:42 PM
  #23  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

If you go here:

W32/Conficker.worm.gen.a

Read the details about the worm, specifically this bit:
Attempts to download a malware file from the remote website

hxxp://trafficconverter.biz/[Removed]antispyware/[Removed].exe

New variants are connecting to various other hosts.

Then go do a WHOIS on that domain:

Trafficconverter.biz - Traffic Converter

The status is 'suspended' but do you think that maybe:
Daniel Adams

of
13 Baterman Street
London
W1D 3AF
UNITED KINGDOM
GB

is in a spot of bother?

and he owns 50 odd other domains.....
Old 22 January 2009, 04:55 PM
  #24  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

What gets my goat is the Antivirus companies and ISP's saying they're doing all they can to stop this.. bla, bla, bla. Well why don't the antivirus companies install their product on the ISP's servers, end of problem.
Old 22 January 2009, 05:26 PM
  #25  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

They will be on the ISPs Servers, but as our traffic doesn't hit the Servers, it's academic.

All the web traffic is just passing through. If you would like the ISP to provide IDS on all web facing devices, be prepared to pay £1000 per month for your 'net connection and take a HUGE hit on the latency of all connections.
Old 22 January 2009, 06:06 PM
  #26  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

You've lost me a little there Keiran

"Attempts to download a malware file from the remote website"

Surely this malware file is being uploaded in order to be downloaded, what's the problem with scanning uploaded files. You can't even put a pair of **** on some servers without it being picked.

Ah, perhaps my use of ISP was a little vague, would 'hosting company' work?

Last edited by JackClark; 22 January 2009 at 06:08 PM.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
alcazar
Non Scooby Related
13
15 September 2015 02:39 PM
Steve Perriam
Non Scooby Related
13
18 September 2001 04:53 PM
a2jcy
ScoobyNet General
3
30 May 2001 12:38 PM
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: Conficker Virus - MS patch



All times are GMT +1. The time now is 04:17 PM.