
I would like to inform you that the 1st of April 2009 will be the time at which a sluggish worm called Conficker C will be activated causing the infected machines to conduct an obscure actions, By going after the following instructions provided by Microsoft you are expected to be reasonably safe from this worm
Apply the security update associated with MS08-067. View the security bulletin for more information about the vulnerability, affected software, detection and deployment tools and guidance, and security update deployment information.
Make sure you are running up-to-date antivirus software from a trusted vendor. Antivirus software may also be obtained from trusted third parties such as the members of the Virus Information Alliance.
Check for updated protections for security software or devices, such as antivirus, network-based intrusion detection systems, or host-based intrusion prevention systems.
Isolate legacy systems using the methods outlined in the Microsoft Windows NT 4.0 and Windows 98 Threat Mitigation Guide.
Implement strong passwords as outlined in the Creating a Strong Password Policy whitepaper.
Disable the AutoPlay feature through the registry or using Group Policies as discussed in Microsoft Knowledge Base Article 967715. Microsoft released Security Advisory 967940 to notify users that the updates to allow users to disable AutoPlay/AutoRun capabilities have been deployed via automatic updating channels.
NOTE: Windows 2000, Windows XP, and Windows Server 2003 customers must deploy the update associated with Microsoft Knowledge Base Article 967715 to be able to successfully disable the AutoRun feature. Windows Vista and Windows Server 2008 customers must deploy the security update associated with Microsoft Security Bulletin MS08-038 to be able to successfully disable the AutoRun feature.
PS: Microsoft also offers a free online safety scan here, which should be able to detect all Conficker versions.
Please consider admonishing all of your peers (IT administrators – Security administrators) regarding this malicious worm.
References:
http://www.f-secure.com/weblog/archives/00001636.html
http://mtc.sri.com/Conficker/addendumC/
http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
http://technet.microsoft.com/en-us/security/dd452420.aspx
http://tech.yahoo.com/blogs/null/128643/beware-conficker-worm-come-april-1/
http://www.zdnetasia.com/news/security/0,39044215,62052554,00.htm
http://www.eweek.com/c/a/Security/Conficker-The-Windows-Worm-That-Wont-Go-Away-529249/
http://www.theregister.co.uk/2009/03/26/conficker_activation_analysis/
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9130228&intsrc=hm_list
You need to be a member of telecentre.org to add comments!
Join telecentre.org