<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx</link><description>So for the past 2 weeks now we are absolutely getting hammered with calls in CSS Security here at MS with organizations contracting this piece of malware. You can find write-ups from various AV companies at the following URL’s http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=76852</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3178213</link><pubDate>Thu, 08 Jan 2009 18:03:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178213</guid><dc:creator>nimdadotenc</dc:creator><description>&lt;p&gt;Great article!&lt;/p&gt;
&lt;p&gt;Lots of problem trying to ID the file that's causing the behavior (if your AV isnt picking it up), since this is being repacked and redistributed to avoid detection.&lt;/p&gt;
&lt;p&gt;In most case it creates a scheduled task pointing right to the offending file. So check C:\windows\task and see what file its pointing, and get that file into your AV vendor for new dat files.&lt;/p&gt;
&lt;p&gt;Thank again&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3178706</link><pubDate>Fri, 09 Jan 2009 13:48:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178706</guid><dc:creator>Phoenix Mudrij</dc:creator><description>&lt;p&gt;We have this virus in our web. Do you know any specific removal tool for this virus? Because our AV provider doesn't have any treat for this virus.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3178888</link><pubDate>Fri, 09 Jan 2009 19:19:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178888</guid><dc:creator>kfalde</dc:creator><description>&lt;p&gt;No specific removal tools. &amp;nbsp;Trend Micro does have a sysclean utility which is like a command line scanner you can use with their definitions which seems to be working ok in some sites.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3179544</link><pubDate>Sat, 10 Jan 2009 02:13:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3179544</guid><dc:creator>Jim Baine</dc:creator><description>&lt;p&gt;It's a pity that MSFCS like other major end point security vendors doesn't protect against behavoural targeting threats such as the B worm.... maybe folks using MSFCS would then not be making the many calls to MS?&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3179548</link><pubDate>Sat, 10 Jan 2009 02:14:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3179548</guid><dc:creator>Jim Baine</dc:creator><description>&lt;p&gt;Great article though! I like your &amp;quot;context&amp;quot; and frankness....&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3180814</link><pubDate>Sun, 11 Jan 2009 23:19:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3180814</guid><dc:creator>Jim Baine</dc:creator><description>&lt;p&gt;The virus is actually a rootkit, therefore use GME as part of your tool kit to detect and then use uptodate virus defs to remove or follow the manual instructions on your AV/malware product vendors website....&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/GMER.shtml"&gt;http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/GMER.shtml&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3180870</link><pubDate>Mon, 12 Jan 2009 02:45:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3180870</guid><dc:creator>kfalde</dc:creator><description>&lt;p&gt;Well as for FCS we were actually one of if not the first AV company to have any detection whatsoever for the .B variant of this. &amp;nbsp;In some senses our product is very 1.0ish at times :) especially in regards to areas like working hand in hand with a firewall etc. &amp;nbsp;During the last two weeks though I have worked multiple cases that included at least 4+ other major AV companies and in every case the ACL's on the files combined with the rootkit capabilities of this piece of malware were evading detection/removal. &amp;nbsp;During the end of this past week however the AV companies appear to be finally catching up.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3181231</link><pubDate>Mon, 12 Jan 2009 20:10:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3181231</guid><dc:creator>raymundo</dc:creator><description>&lt;p&gt;Anyone know how to contain the bloody virus??, I do update my PC on my network and also update the antiviral scanner, but alway show me theres someone with the virus, dos anyone hava a clue to contain or avoid more copies of ??&lt;/p&gt;
&lt;p&gt;Thanks &lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3182548</link><pubDate>Wed, 14 Jan 2009 23:31:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182548</guid><dc:creator>Jim Baine</dc:creator><description>&lt;p&gt;Symantec has released a cleanup utility that will remove the virus from infected computers.&lt;/p&gt;
&lt;p&gt;The Removal Tool does the following: &lt;/p&gt;
&lt;p&gt;&amp;#183; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Terminates the associated processes &lt;/p&gt;
&lt;p&gt;&amp;#183; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Deletes the associated files &lt;/p&gt;
&lt;p&gt;&amp;#183; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Deletes the registry values added by the threat &lt;/p&gt;
&lt;p&gt;&amp;#183; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Removes the scheduled jobs created by the worm &lt;/p&gt;
&lt;p&gt;&amp;#183; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Re-enable Windows Update&lt;/p&gt;
&lt;p&gt;This fix will work on any computer, you don’t need to have SAV installed for it to work.&lt;/p&gt;
&lt;p&gt;Also, the fix has been released with command line switches… we can run silently with no reboot. &amp;nbsp; So we should be able to setup altiris jobs to run the fix automatically.&lt;/p&gt;
&lt;p&gt;Please see this link for more information and a download link:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99"&gt;http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3190653</link><pubDate>Fri, 23 Jan 2009 09:55:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3190653</guid><dc:creator>RBailey</dc:creator><description>&lt;p&gt;Have found perhaps a variant today that nothing seems to be able to clean up. &amp;nbsp;Some AV software is cleaning up the service that gets created, but is not repairing service.exe&lt;/p&gt;
&lt;p&gt;nastly little bug.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3190742</link><pubDate>Fri, 23 Jan 2009 14:33:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3190742</guid><dc:creator>Extremesecurity</dc:creator><description>&lt;p&gt;Did Downadup/conficker attack your network? I've created a batch file for system administrators to clean/patch/cure infected systems in their networks.&lt;/p&gt;
&lt;p&gt;check it out here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html"&gt;http://extremesecurity.blogspot.com/2009/01/beat-downadupconficker-like-pro-my.html&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3204578</link><pubDate>Thu, 19 Feb 2009 19:40:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3204578</guid><dc:creator>Igoy</dc:creator><description>&lt;p&gt;I found that the B Variant keeps coming back even after cleanup using Symantec FixTool. I had to to erase all of the service it registered on the Registry manually.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3210919</link><pubDate>Mon, 09 Mar 2009 21:29:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3210919</guid><dc:creator>tesseeb</dc:creator><description>&lt;p&gt;You MUST disable System Restore on your PCs. &amp;nbsp;Until we did that with a group policy, it just kept coming back. &amp;nbsp;We would run the clean up tools and frequent full system scans that came back clean and it would reappear hours later. &amp;nbsp;And set your AV scan defaults to delete as first attempt/quarantine second.&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3226103</link><pubDate>Tue, 14 Apr 2009 09:31:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226103</guid><dc:creator>tower defense</dc:creator><description>&lt;p&gt;I do update my PC on my network and also update the antiviral scanner, but alway show me theres someone with the virus, dos anyone hava a clue to contain or avoid more copies of ?&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3233760</link><pubDate>Fri, 01 May 2009 01:19:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3233760</guid><dc:creator>Manic</dc:creator><description>&lt;p&gt;What passwords does it attempt? Is there a pre-defined list?&lt;/p&gt;
</description></item><item><title>re: Malware Win32/Conficker.B W32.Downadup.B</title><link>http://blogs.technet.com/kfalde/archive/2009/01/08/malware-win32-conficker-b-w32-downadup-b.aspx#3233761</link><pubDate>Fri, 01 May 2009 01:19:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3233761</guid><dc:creator>Manic</dc:creator><description>&lt;p&gt;What passwords does it attempt? Is there a pre-defined list?&lt;/p&gt;
</description></item></channel></rss>