• Steam recently changed the default privacy settings for all users. This may impact tracking. Ensure your profile has the correct settings by following the guide on our forums.

Conficker worm: D-day April 1st

xploren

Contributor
My laptop's clean, not sure about my desktop though. If it DOES go by EST time, it's about 2AM, so nothing's happened.

The author must be sitting in his chair amused at how big the situation's gotten. He or she is just epic.
 

Whisper

Logic :(

LocutusEstBorg

Active Member
IMPORTANT NOTICE: No media files are hosted on these forums. By clicking the link below you agree to view content from an external website. We can't be held responsible for the suitability or legality of this material. Rezzy's Triple Lindy @ 0:28

It worked fine in preview post, why not in the submitted post.
 

Colm

New Member
Chances are that as they managed to hype up april 1st, the virus has been told to delay activity until a later date, when less people expect it.
 

Slasher

Suck It
Nothing was ever set to actually really go down April 1st. It was just updating itself to receive a new set of instructions on this date. The instructions could have been anything, even nothing.

Even in class this morning I heard people moaning about it with so much misinformation it was making me want to turn around and slap them in the faces. Things like "Yeah it works on macs too", "When you guys turning your computers back on?", and "I heard google.ca doesn't work if you have it", "It's crashing computers that have it now"...

There's so much bullshit flying around it's just ridiculous
 

Mister Chief

New Member
I suggest everyone read the wiki page for it. Like Slasher said, April 1st was just a scheduled update for the worm.

There has already been several updates to the worm where a previous version has contacted a domain to receive a new payload. April 1st just marks the first time version D will begin visiting domains for payloads.
 

Pokemanz master

Lowering your IQ
Im so lost now....
So it can be launch at anytime now?
 

Dan

Contributor
wait, if this virus infects thorugh the vulnerable windows -068 update, can't we just manually delete that patch?

- just some info

1[YT]http://www.youtube.com/watch?v=eoAYsGV5MkY[/YT]
2[YT]http://www.youtube.com/watch?v=9Zr-nE74VQc&feature=related[/YT]
 

Colm

New Member
OK, the best thing to do is wiki it. Summing up what I've learned from the wiki:
Conficker itself is just a backdoor for a payload to enter it. This was the plan from the start. Variants A, B and C were placed to propagate itself and infect computers. Variant D has changed this completely. Variant D does not propagate itself. Instead, it spreads by "updating" the other three variants, by means of a payload placed on a sequence of random domain names.
April 1st marks the first time that Conficker.D will start searching for payloads through a P2P network created by the virus. The payloads will enter the network from a sequence of domains that will infect about 1% of people carrying the virus. Variants A-C had a similar system, but with fewer domains, and therefore a higher chance to spread payloads (although the only payload that they've spread is the "update" to D) But, once they're in, they'll distribute quickly throughout the system. This is only a change in the way the virus listens for payloads. The virus could easily have spread payloads through the domain name system. The change today is very minor.
The virus will act as soon as a payload enters the system, but this could be at ANY time. Not specifically today. Or tomorrow. Or this week.

Keep updated. If you have Variant D, it kills anti-malware applications every second and variants B-D disable autoupdate. Get the patches, and if autoupdate is disabled without you disabling it, you may have the virus. Get your AV up-to-date and have a scheduled scan. Which you should be doing already.
 
Top