On CHOW: 10 good cheap liquors
BNET Business Network:
BNET
TechRepublic
ZDNet

April 2nd, 2009

Eyeballing Conficker with eye-charts and maps

Posted by Ryan Naraine @ 11:29 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Locally Running Web Servers, Malware, Microsoft, Patch Watch, Responsible disclosure, Symantec, Viruses and Worms

Tags: Web, SecureWorks Inc., Malware, Web Site, Conficker, Cyberthreats, Spyware, Adware & Malware, Web Site Development, Viruses And Worms, Security

As expected, the April 1st activation date for the Conficker worm passed without much noise but, as Microsoft and others are explaining, the botnet associated with the worm is very much alive — and still potentially dangerous.

“[This threat] should remain a manageable cause for concern and it doesn’t go away after April 1,” says Microsoft’s Christopher Budd.  The malware still lives on millions of Windows machines and could start calling home for instructions at any time.

Now that the crazy hype has died down (hopefully!), it’s important for end users to get reliable information on eyeballing the presence of Conficker on a machine and, if it’s found, disinfection instructions from a Web site that isn’t blocked by the malware.

Because Conficker blocks victims from visiting Web sites for anti-malware vendors,  Joe Stewart from SecureWorks has come up with a clever eye-chart (if that gets blocked, try this one) that provides visual confirmation on infections.

If you can see all three images in the top grid below, your computer is NOT infected with Conficker. However, if one of the F-Secure, SecureWorks or Trend Micro logos appears broken, chances are your computer is part of the Conficker botnet. Here’s the explanation on how to interpret the chart.

It’s also very tricky to point users to disinfection tools because they are all hosted on Web sites that are blocked.  The only one I’ve seen on an unblocked site is BitDefender’s bdtools.net, which offers disinfection tools for single PCs or networks.

If Conficker is not present on your machine, it’s important that you apply all Microsoft security updates immediately.

The Conficker Working Group has also provided some excellent maps with a view of the botnet around the world:

WORLD MAP:

USA INFECTIONS:

EUROPE INFECTIONS:

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 22 Talkback(s)
Be careful with the eyeball
There does exist some infections that redirects
all your DNS queries for a domain name within a
rogue root domain that resolves to other sites.
So you may effectively see the images from e... (Read the rest)
Posted by: PhilippeV Posted on: 04/10/09 You are currently: a Guest | | Terms of Use
MS is responsible for this  Christian_<>< | 04/02/09
Bull.  CobraA1 | 04/02/09
Exactly!  Wolfie2K3 | 04/03/09
The definition of bug free.  Dr. John | 04/03/09
You took the words right out of my mouth!  jrbirdman | 04/09/09
Two other words for "bug free"  David A. Pimentel | 04/09/09
...  Badgered | 04/03/09
HA HA HA HA.....  Nsaf | 04/07/09
Re: MS is responsible for this  The Rifleman | 04/02/09
rifleman sniping at the wrong target  djk_marbles | 04/03/09
HA HA HA HA....  Nsaf | 04/07/09
Excellent article and charts ...  johnfenjackson@... | 04/03/09
Can I get a closeup of Florida -- specifically Tallahassee?  Grayson Peddie | 04/03/09
skitch.com exceeded bandwidth  cwallen19803@... | 04/03/09
Exceeded Bandwidth?  RushTX | 04/03/09
RE: Eyeballing Conficker with eye-charts and maps  mixxitman03@... | 04/03/09
Had to reboot my dual boot system and check twice.  pfyearwood | 04/03/09
RE: Eyeballing Conficker with eye-charts and maps  tecsmedia | 04/03/09
RE: Eyeballing Conficker with eye-charts and maps  kmashraf | 04/06/09
Conficker don't bother me!  jonbaker_08_live.com | 04/07/09
Good Screening Tool  readyben | 04/09/09
Be careful with the eyeball  PhilippeV | 04/10/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads