Conficker worm: More on how it works and how to protect against it 0
The worm:
* exploits the MS08-67 Windows Server service vulnerability (Services.exe)
* saves an executable autorun.inf file to any removable media attached
* saves an executable autorun.inf file to any mounted network shares
* attempts to brute-force credentials on other accessible machines
The last 3 methods allow the worm to quickly spread through internal
networks and to patched machines that lack sufficient anti-virus
coverage. Once installed, the worm attempts to block further Microsoft
or updates from being installed.
Preventative measure you can take additionally to those i mentioned in my post yesterday include:
* File servers should either be covered by antivirus protection, prevent the creation of autorun.inf files (see Workaround 1), or be checked periodically/automatically for the presence of such files.
* Disable autorun on workstations and servers see KB953252 on the MS site.
* Sites who maintain their own DNS servers or webcaches may want to monitor logs for the appearance of domains that appear on the F-Secure list of potential domains that the worm may use. See F-secures Pre-emptive block list
Removing the virus:
Most AV tools will clean the threat from your computer but if another computer on your network has it you could get it again. Like i mentioned yesterday keep your anti-virus up to date and be alert check your AV logs for any of the sigs of the virus.
