Monday, July 4, 2011

Conficker Worm , Downad Malware

So today after several days of working on it, I finally managed to root out the Conficker Worm from my client's network. The Conficker worm is an easily spreading Malware which on subsequent generations become more and more deadly and dangerous, in fact even leading other Malware and Virus to gain easy entry into the networks.



The biggest evidence of your machine being affected by the Conficker worm is if your Anti Virus client does not get updated even if the the update dialog happens without event. If you monitor the Network Usage Statistics on your Task Manager while you are updating you will see that no network traffic is taking place when the Anti Virus is apparently updating. You can confirm your fears if you are able to visit all websites except websites of Microsoft, AVG, McAfee, Trend Micro, Symantec etc. The Conficker worm prevents web access to these web sites.

While several tools claim to remove this, the best method is to simply do this:

Run > CMD > net stop dnscache

By this flushing of DNS Cache you get a temporary window of opportunity during when you can successfully update your Anti Virus. If your network has a central Web Server, the preliminary updating should happen here as after updating its Anti Virus Client and scanning its directories for the Malware it can trigger updates to all the Computers under its network management.

Then you need to just update the Windows and problem solved.

No comments:

Post a Comment