In association with heise online

03 April 2009, 16:38

The H Security Conficker information site

On this page you will find all of the important information about the Conficker worm, including how to detect it and to guard against it. Note that some manufacturers call Conficker either Kido or Downadup.

Test pages

There are several test sites that can help you check for Conficker infection. These links open a page that performs the test and shows the result.

Info pages and removal tools from AV vendors

Many anti-virus manufacturers are offering specific tools for detecting and removing Conficker. These applications do not require installation of a complete AV package. The easiest way to proceed is to download the tool on an uninfected computer, copy it onto a USB drive and then run it on the infected system. NOTE - all of these links start a file download process.

* Conficker may block access to indicated sites

Network Scanner

Various companies offer scanners that can detect Conficker over a network. They are based on techniques developed by security researchers Felix Leder and Tillmann Werner. These techniques do require access to TCP port 445 to reach the target systems, so they will normally only work within local networks since this port should be blocked from the internet side of any firewalls.

  • Nmap version 4.85Beta5
    To do a basic conficker scan with Nmap, run:
    nmap -sC -PN -d -p445 --script=smb-check-vulns \
    --script-args=safe=1 ip-address-to-scan
  • Nessus plugin 36036
  • Confickertest from McAfee
  • ConfickerScanner by eEye
  • SCS from the University of Bonn (Leder, Werner)

Reports from The H Security about Conficker

Tips and Tricks

Lock bypass: Conficker blocks access to certain websites. You can bypass this lock by clicking on the Start menu and clicking run with the following command:

NET STOP DNSCACHE

The Conficker page from the University of Bonn also has several interesting Conficker tools.

Other

We will try to keep this page updated and expand it over time. If you have any suggestions for improvements or problems with any of the links, please email us.

Print Version | Permalink: http://h-online.com/-746181
  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit