How do you know if your computer has the Conficker worm?

Hi,I did the following:
Question: How do you know if your computer has the Conficker worm?

I’ve heard about this nasty worm that’s supposed to come out April 1st.
Is this an April fools joke or what? I’m not computer savvy and the stuff I’ve read still does not help me. Could someone explain to me in layman’s terms just exactly what this is and how to deal with it? Should I even use my computer on April 1st??

Q&A:

Answer by Madman6510
Conficker is a virus that started spreading in 2008. It will search for “new instructions” on april 1st. The exploit it used is patched now, you cannot get it anymore unless your computer is not patched (update.microsoft.com to download patches). Simply run an UP TO DATE antivirus scanner, and the virus will be found and removed.

If you have a Mac you are immune.
If you run Linux you are immune.
Phones, PDAs, iPods, etc. are immune.

Some more information can be found here:
http://support.microsoft.com/kb/962007 (info)
http://en.wikipedia.org/wiki/Conficker (info)

A good free antivirus:
http://www.avast.com/eng/download-avast-home.html

Answer by Morgan Freeman
Shutting down everything won’t help it will only deley it. It is still there after April 1st, the Anti-Virus programs im using are AVG Free Edition, and Avast (free as well). I also have Microsoft Moniclious tool remover. Thats about the best you can do for free and not using up all the memory on your computer.

Answer by BillM
yes, you can use your computer, the windows update came out in oct of 2008, you probably have it, read on. What Happens on April 1, 2009?

Computers previously infected with the Conficker worm will begin to use specially crafted instructions to contact web domains owned by the attackers with the intent to find ways to spread (worm) Conficker to other computers to infect.

What does the Conficker worm do?

We don’t know the purpose of the Conficker worm. We have evidence that the creators of the worm can connect to an infected computer to remotely install software and possibly steal information. What will that software do? Most likely the worm will be used to create a botnet that will be “rented” out to criminals who want to send SPAM, steal IDs and direct users to online scams and phishing sites.

The Conficker worm mostly spreads across networks. If it finds a vulnerable computer, it turns off the automatic backup service, deletes previous restore points, disables many security services, blocks access to a number of security web sites and opens infected machines to receive additional programs from the malware’s creator. The worm then tries to spread itself to other computers on the same network.

How does the worm infect a computer?

Conficker, also known as the Downadup worm, tries to take advantage of a problem with Windows (a vulnerability) called MS08-067 to quietly install itself. Users who automatically receive updates from Microsoft are already protected from this. The worm also tries to spread by copying itself into shared folders on networks and by infecting USB devices such as memory sticks.

Who is at risk?

Users whose computers are not fully patched and receiving updates from GDIT’s System Management agent (SCCM) or directly from Microsoft and who are not running an up to date antivirus product are most at risk.

Ensure your Symantec Antivirus is up-to-date and actively running.

1. Your Symantec Antivirus program should be configured to receive updated signatures that have the latest information to identify and prevent th <> e variant of the worm from running on your computer. Please follow these instructions to help determine if your Symantec AV program is up-to-date (you must be connected to the Internet):

1. From your computer, open the Symantec AV console (from the system tray double-click the yellow, PC mouse-looking icon). The icon looks like this: cid:image001.jpg@01C9B1EC.32543F30

2. Check the Program Versions section, the Scan Engine should be 81.3.0.13

3. If the Scan Version is not at this level then call the GDIT IT Service Desk and Support for assistance

4. Next, check your Virus Definitions File section, the version should be at a minimum of 3/29/2009 rev. 3

5. If the version is not current then click the LIveUpdate button à Click the Next button –> It will go out to Symantec’s website and automatically download the latest version

6. If your system is prevented (confirm that you have Internet access) from accessing the Symantec website call IT Service Desk and Support immediately for assistance.

7. From the pull-down menu, choose Scan and select Full Scan. Click the Scan button and allow Symantec to perform a complete scan.

8. If Symantec finds a virus please contact the IT Service Desk and Support for assistance.

To reiterate, if your computer does not have the latest Program Version or Virus Definitions or it is prevented from accessing the Symantec website to receive the latest signatures please contact the IT Service Desk and Support and immediately.

Advice to Stay Safe from the Downadup Worm:

* Periodically check the Symantec AV console to ensure you are receiving Program and Virus Definitions and they are not out of date.

* Keep your computer updated with the latest patches. This includes Microsoft Operating and Office updates (every 2nd Tuesday of every Month), and Adobe Flash Player, Acrobat and Reader programs, If you don’t know how to do this contact IT Service Desk and Support to assist you.

* Don’t use “free” security scans that pop up on many web sites. All too often these are fake, using scare tactics to try to get you to purchase their “full” service. In many cases these are actually infecting you while they run. There is reason to believe that the creators of the Conficker worm are associated with some of these fake security products.

* Be smart with your passwords. This includes

o Change your passwords periodically as per GDIT Policy

o Use complex passwords – no simple names or words, use special characters and numbers

Contact Information:

IT Service Desk: http://servicedesk.gdit.com/

IT Expanded Support Line: local to Massachusetts.: 781-455-5020,

Long Distance: 800-663-8315

* G

Answer by computerwiz1247
Go to symantec.com…. if you can go to that site, your computer is not infected.

Answer by Lalaland P
http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99 Run the scanner it tells you if you have it.

Give your answer to this question below!

10 Comments

  1. tempo1 says:

    Yep, its an April Fools Joke on the computer illiterate that shouldn’t be placing a computer on the public internet in the first place.

    Anybody with even a little bit of computer “savvy” took the upgrade from Microsoft that totally makes one immune to Conficker way back in October 2008!!

    There is NO excuse for anyone with a legal copy of Windows to get infected with Conficker.

    Except ignorance.

    If the shoe fits……

  2. I'm the LT of Yahoo! Answers says:

    To find out about it what you have to do is Shut your computer down. Then when it is booting back up; right when the screen turns on tap F8 repeadedly until a Black Screen shows up. Click the safe mode option(use the arrow keys to navigate and the enter key to select) and if it doesn’t work then you are infected, as the Conficker.C shuts down Safe Mode. If it works then it runs fine.

    NOTE: Make sure you have a good anti-virus software.

  3. starrjewell #3 is here!! says:

    Just type conficker scanner in to yahoo search. if you have it remove it. if you dont make sure all security patches are up to date on your computer and download an antivirus. it has been said on the news time and time again staying off the computer wont necessarily help.

  4. lyonsinc1 says:

    Conflicker is a worm and as many variants it as been around a few years.Microsoft as a small app’ that looks for about 15 different versions of the worm,down load it and let it run.And the next time you do updates on second tuesday it will update also,for new versions of pesty worm.Now you do not know about worm until it gets its command to do the damages,this is why you should download the malicious software removal tool from microsoft,your anti-virus may not pick up the worm hiding around in system 32 files.

  5. Joe says:

    pcmag.com,extreme tech, & others have imfo. and downloads on their sites. kwch.com our local tv has downloads to confirm your ok as do most of the software mfg.s on their sites.Its all free stuff which does not mean they won’t try to sell you something else but you don’t have to buy. XP is most in danger as I understand it ( vista is not immune). If you have been getting your security updates & microsoft updates your likely ok as it stops these from happening (again as I understand).I suggest you go to one of the sites mentioned & run their special program just to be safe. GOOD LUCK

  6. "Paladin" says:

    The worm is very real.

    If you do find your computer infected, and you can’t get to any site that has to do with security, type in “Kidokiller” in Google and download the program.

    It’s a simple program that will eliminate your problem.

  7. joejohnjuice says:

    You’re going to have to take your computer to the computer doctor. Remember that disease is spread through unprotected computer sex, so the next time your computer tries to play with others, remind it to wrap it up.

  8. Lady Rainbow says:

    I heard if you type in “mcafee’ or “microsoft” and your computer does not direct you their websites, but instead get some kind of “error” prompt / screen / whatever, that could be a good sign that you got the worm.

    Supposedly the worm does not allow you to access or at worst download computer protection programs.

    Try it and see what happens. You might want to google it as well, Ii posted some links for you to check out and get better informed. Don’t worry I have McAfee and these sites checked out clean.

    Good Luck!!!

  9. Lex says:

    oh gosh im so nervous about that!
    im scared i might get itttt

  10. dvdclarke says:

    please install norton anti virus software

Leave a Reply