Wednesday, April 01, 2009

Don't Panic! Conficker/Downadup/Kido worm

Don't Panic! You probably don't have the Conficker/Downadup/Kido worm

One fast way to check is to try to visit any major security software publisher's Web site.
If you've cleared your browser cache beforehand, and you can load the sites below then you're clean because Conficker blocks access to them.

Symantec
http://www.symantec.com/index.jsp

Eset
http://www.eset.com/

Avira
http://www.avira.com/en/pages/index.php

AVG
http://www.avg.com/


There are some tools specific to this worm that you can download to clean up

McAfee's Stinger
http://download.cnet.com/3001-2239_4-10911653.html?spi=f091b4ab47a30abe6a9872f8065a0cc8

Eset: Win32/Conficker Worm Removal Tool
http://download.cnet.com/Win32-Conficker-Worm-Removal-Tool/3000-2239_4-10911654.html

Symantec's W32.Downadup Removal Tool
http://download.cnet.com/Symantec-W32-Downadup-Removal-Tool/3000-2239_4-10911656.html

Sophos' Conficker Cleanup Tool
http://download.cnet.com/Sophos-Conficker-Cleanup-Tool/3000-2239_4-10911655.html


Don't Do This Unless you understand it!!!

To prevent infection form memory sticks, or USB drives, disable the Autorun feature
copy the text below into Notepad. It should be one line from the left bracket to the final quotation mark. save it as "StopAutoRun.reg"

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\IniFileMapping\Autorun.inf]@="@SYS:DoesNotExist"

right click the new file and choose merge

PS I dashed this off quickly

end.>

No comments: