How to identify and clean Conficker infections
As the world prepares for the complete destruction of the Internet tomorrow when the Conficker worm makes a small change in its communication protocol, a voice of reason has emerged from the wilderness. The Honeynet Project on Monday released a paper with a detailed analysis of the worm as well as some weaknesses in its design that allow for identification of infected machines.
As my colleague Ryan Naraine reported yesterday, the Honeynet researchers discovered that Conficker attempts to patch the Windows flaw that it uses to compromise machines. But it does so in a sloppy way that allows researchers to identify infected PCs. In their paper, the Honeynet researchers lay out exactly how to identify and disinfect compromised machines.
"All Conficker variants try to patch the infected systems to prevent re-exploitation. The handler, installed as a function hook, changes the behavior of RPC requests on infected machines. This information can be used to remotely scan for Conficker infections. In addition to actively scanning, machines infected with Conficker.A and .B can be identified using the presented IDS signatures," they write.
Editor's Pick
You can read the full Honeynet Project paper here. (.PDF)
Commenting on this Article is closed.
Today's Most Popular
- Yahoo Includes Private Key in Source File For Axis Chrome Extension
- Researchers Unveil New Way to Trust Certificates
- FBI Warns Top Firms Of Anonymous Protest Hacks on May 25
- DNSChanger Lingers: 330k Systems Still Infected, 77,000 In The U.S.
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (10)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (14)
-
FBI Warns Top Firms Of Anonymous Protest Hacks on May 25 (2)
-
Facebook Cancellation Malware Disguised As Adobe Update Making Rounds (3)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



