Last-minute Conficker survival guide

Tue Mar 31, 2009 1:42PM EDT

See Comments (3068)

Tomorrow -- April 1 -- is D-Day for Conficker, as whatever nasty payload it's packing is currently set to activate. What happens come midnight is a mystery: Will it turn the millions of infected computers into spam-sending zombie robots? Or will it start capturing everything you type -- passwords, credit card numbers, etc. -- and send that information back to its masters?

No one knows, but we'll probably find out soon.

Or not. As Slate notes, Conficker is scheduled to go "live" on April 1, but whoever's controlling it could choose not to wreak havoc but instead do absolutely nothing, waiting for a time when there's less heat. They can do this because the way Conficker is designed is extremely clever: Rather than containing a list of specific, static instructions, Conficker reaches out to the web to receive updated marching orders via a huge list of websites it creates. Conficker.C -- the latest bad boy -- will start checking 50,000 different semi-randomly-generated sites a day looking for instructions, so there's no way to shut down all of them. If just one of those sites goes live with legitimate instructions, Conficker keeps on trucking.

Conficker's a nasty little worm that takes serious efforts to bypass your security defenses, but you aren't without some tools in your arsenal to protect yourself.

Your first step should be the tools you already have: Windows Update, to make sure your computer is fully patched, and your current antivirus software, to make sure anything that slips through the cracks is caught.

But if Conficker's already on your machine, it may bypass certain subsystems and updating Windows and your antivirus at this point may not work. If you are worried about anything being amiss -- try booting into Safe Mode, which Conficker prevents, to check -- you should run a specialized tool to get rid of Conficker.

Microsoft offers a web-based scanner (note that some users have reported it crashed their machines; I had no trouble with it), so you might try one of these downloadable options instead: Symantec's Conficker (aka Downadup) tool, Trend Micro's Cleanup Engine, or Malwarebytes. Conficker may prevent your machine from accessing any of these websites, so you may have to download these tools from a known non-infected computer if you need them. Follow the instructions given on each site to run them successfully. (Also note: None of these tools should harm your computer if you don't have Conficker.)

As a final safety note, all users -- whether they're worried about an infection or know for sure they're clean -- are also wise to make a full data backup today.

What won't work? Turning your PC off tonight and back on on April 2 will not protect you from the worm (sorry to the dozens of people who wrote me asking if this would do the trick). Temporarily disconnecting your computer from the web won't help if the malware is already on your machine -- it will simply activate once you connect again. Changing the date on your PC will likely have no helpful effect, either. And yes, Macs are immune this time out. Follow the above instructions to detect and remove the worm.

Comments on Last-minute Conficker survival guide

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 26 Posted by waimyolin on Thu Sep 3, 2009 10:38PM EDT Report Abuse

    go to download.com and get AVG Anti-Virus.

  • 27 Posted by jorge3019 on Thu Sep 3, 2009 4:41PM EDT Report Abuse

    Hello I am a computer technician and I have always recommended Kaspersky is one of the best antivirus inthe market and it updates daily. Best thing you could get a free 30 day trial. The license is 80 bucks and its good for 1 year.

  • 28 Posted by jeremycain@ymail.com on Thu Sep 3, 2009 4:33PM EDT Report Abuse

    AVG is an amazing one to checkout. you can find that and many more at download.com

  • 30 Posted by zosia_q2 on Thu Sep 3, 2009 11:01PM EDT Report Abuse

    Do I have to worry if I have an iMac?

  • 33 Posted by screwzlews on Thu Sep 3, 2009 9:10PM EDT Report Abuse

    Chris Null you're useless. Folks, go to insecure.org and d/l the nmap 4.8 beta and run the command line utility provided in the write up. If you're a network admin this is a very useful tool as it will scan network ranges in seconds. You could also pipe an output to a text file and do a "find" for the word infected to see which machines are likely infected.

  • 35 Posted by kayandronte on Thu Sep 3, 2009 4:48PM EDT Report Abuse

    so is this sayin if u have confilcker than it will mess your computer up..??? i dont get it...

  • 36 Posted by mariparker2 on Thu Sep 3, 2009 7:07PM EDT Report Abuse

    Yes- I have been using AVG for some time now- they have a free download- i am completly satisfied with it.

  • 37 Posted by screwzlews on Thu Sep 3, 2009 9:10PM EDT Report Abuse

    Chris Null you're useless. Folks, go to insecure.org and d/l the nmap 4.8 beta and run the command line utility provided in the write up. If you're a network admin this is a very useful tool as it will scan network ranges in seconds. You could also pipe an output to a text file and do a "find" for the word infected to see which machines are likely infected.

  • 38 Posted by avenger50 on Thu Sep 3, 2009 2:59PM EDT Report Abuse

    So, if they know about it and when it is "set to begin", how come they made no effort to prevent it?

  • 40 Posted by kasamara_phoenix on Thu Sep 3, 2009 4:47PM EDT Report Abuse

    With a Webroot Antivirus and Spyware, completely updated might I add, plus my double firewalls and fully patched computer I think I'm gonna be just fine. But I still worry.

  • 41 Posted by nazaredl on Thu Sep 3, 2009 7:34PM EDT Report Abuse

    April Fool !!!!!!!!!!!!!!!!!!!!!!!!

  • 43 Posted by kjpzoom on Thu Sep 3, 2009 4:52PM EDT Report Abuse

    So are you saying this is only a PC problem? Not a MAC problem?

  • 44 Posted by primalfear6662006 on Thu Sep 3, 2009 8:18PM EDT Report Abuse

    Yes i agree, its all a ----- scam to sell more of there bull----- ...........

  • 45 Posted by rbounsy90 on Thu Sep 3, 2009 8:31PM EDT Report Abuse

    its a april fools joke you ----- retards

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.