Page 1 of 2 1 2 LastLast
Results 1 to 15 of 25

Thread: Conficker Search and Removal

  1. #1
    Member
    Join Date
    Mar 2007
    Posts
    253

    Conficker Search and Removal

    I read an interesting article in yesterday's USA Today (3/25/2009) about the Conficker Worm. They claim a major action/attack is due on 1 April, in just a few days.

    They suggest using WinPatrol (have that), Bufferzone Pro (Trustware.com) ($40). and Enigma SpyHunter (EnigmaSoftware.com)

    Enigma has put out a free tool designed exclusively to hunt and destroy Conficker. This posting concerns that tool.

    Has anybody here used this program from Enigma? Does anybody feel they can recommend it? Is it going to be any better than the protection programs already listed here on this site? Is there a highly recommended program for this job?

    I feel just a bit uneasy using a totally unknown program. The last time I did that I totally and completely trashed my system and had to reinstall everything. I'd like a bit of reassurance that that won't happen again.

    Opinions, suggestions, experiences?

  2. #2
    Administrator Steve R Jones's Avatar
    Join Date
    May 1999
    Location
    Largo, FL.
    Posts
    5,275
    Enigma has put out a free tool designed exclusively to hunt and destroy Conficker.
    "Hunt and destory" would be different then I don't want to be infected in the first place...Does it mention preventative protection?
    "Vegetarians live up to nine years longer than the rest of us...Nine horrible, worthless, baconless years."

  3. #3
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    The only good preventative protection is to unplug the system from the Internet and never download again.

    I would check Trend Micros' website for removal tools. They are one of the few websites that I trust.

  4. #4
    Stark Raving MOD Midknyte's Avatar
    Join Date
    May 2002
    Location
    Arkham Asylum
    Posts
    22,270
    If Enigma was that good, we would have heard about it a lot by now.

    Do your windows updates, keep you AV (Avira, perhaps?) updated, run antispyware (Malwarebytes or SuperAntispyware)

  5. #5
    Member
    Join Date
    Mar 2007
    Posts
    253
    Quote Originally Posted by Steve R Jones View Post
    "Hunt and destory" would be different then I don't want to be infected in the first place...Does it mention preventative protection?
    Preventive protection is in the sidebar, two of the three programs I mentioned. They suggest WinPatrol and BufferZone Pro, and Enigma SprHunter in the event you're already infected.

    I don't know that my system is infected. I believe it is not. I'm looking for a way to check on the possibility before the April 1st event.

    Here's a link to the article.

    USAToday Article

    I'll look also at the Trend site. You're right, they probably have a removal tool. A 'known-good' site is better than a 'sounds-good' site.

  6. #6
    Administrator Steve R Jones's Avatar
    Join Date
    May 1999
    Location
    Largo, FL.
    Posts
    5,275
    The Microsoft Windows Malicious Software Removal Tool has been updated to scan for it.
    http://support.microsoft.com/?kbid=890830
    "Vegetarians live up to nine years longer than the rest of us...Nine horrible, worthless, baconless years."

  7. #7
    Member t34b4g5's Avatar
    Join Date
    Sep 2008
    Location
    Australia.
    Posts
    219
    Combofix also seems to be able to detect and remove this sneaky lil worm..

  8. #8
    Member
    Join Date
    Mar 2007
    Posts
    253
    I ran Trend Micro HouseCalls last night, overnight. I set it in motion and went to bed. It ran for 5 hours and 10 minutes, scanned resources = 176802. This morning I was greeted with "Trend Micro HouseCall Error Page. HouseCall client cannot be executed due to internal errors..." It went on to tell me to contact my system admin people.

    TM HouseCalls seems to be Trend's solution for Conficker search and removal. I couldn't find that they had a removal tool specifically for Conficker.

    Anyone care to guess what happened? I've run HouseCalls before, successfully. I'll try it again tonight.

    Does the MS Malicious Removal Tool work as well as we might hope? I'll take a look at that one too.

    Thanks for the help and replies.

  9. #9
    Member
    Join Date
    Mar 2007
    Posts
    253
    Quote Originally Posted by Steve R Jones View Post
    The Microsoft Windows Malicious Software Removal Tool has been updated to scan for it.
    http://support.microsoft.com/?kbid=890830
    I just ran this, and got a clean report. I would guess at this point that my system is clean.

    The question now is concerning TM HouseCalls, and it's error message.

  10. #10
    Mod w/ an attitude Sterling_Aug's Avatar
    Join Date
    Jun 1999
    Location
    Schuylkill Haven, PA 1797
    Posts
    12,786
    Did you run the Trend scan using Firefox or IE?

    It only runs correctly on IE.

  11. #11
    Member
    Join Date
    Mar 2007
    Posts
    253
    I tried numerous times to run HouseCalls under IE, and it would not work on my system. It would not complete the "install" portion. Perhaps I have a too old version of IE, since I never run it, much prefer FireFox. My IE is v6.0.

    HouseCalls seems to have run okay under FireFox, though it's always hard to tell, as long as it runs to completion.

    I ran the MS Malicious Software Removal Tool first, so I think that between the two of them I should be safe.

    Many thanks for your help and guidance in this.

  12. #12
    Member
    Join Date
    Mar 2007
    Posts
    253
    60 Minutes, the CBS Sunday night news show, just ran their lead story about Conficker. That's an indication of it's seriousness. They brought out the point that you're at risk every time you turn your computer on, every time you go online.

    Their own computer system, there at CBS, was infected by Conficker. They've worked long and hard to clean it up, and think they have. But they're not absolutely sure that they really got it all. Their people admit that it may still be lurking, buried deep within their system. They're just not sure.

  13. #13
    Administrator Steve R Jones's Avatar
    Join Date
    May 1999
    Location
    Largo, FL.
    Posts
    5,275
    I saw 60 minutes too....Pretty Interesting. Think I'll do a little more scanning on the office computers..
    "Vegetarians live up to nine years longer than the rest of us...Nine horrible, worthless, baconless years."

  14. #14
    Member
    Join Date
    Mar 2007
    Posts
    253
    Microsoft help with Conficker:

    Microsoft Help

    MS has some suggestions, help, background, links...

  15. #15
    Ultimate Member Rocketmech's Avatar
    Join Date
    May 2001
    Location
    Corpus Christi, Texas
    Posts
    5,739
    All the major security program companies offer a removal tool, ex. Symantec, Kapersky, McAfee, TrendMicro, Avira, Sunbelt and so on . So keep that in mind if you really believe you are infected with Conficker. If your AV is updated and Windows is patched / updated , your fine. Its the folks with network pc's that are not patched and protected that have to worry.

    http://sunbeltblog.blogspot.com/2009...n-april-1.html

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •