How to Stop and Remove Conficker

Conficker How to Stop and Remove Conficker
What is Conficker?

Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in October 2008. The worm propagated through the Internet by exploiting a vulnerability in the network stack of Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, Windows 7 Beta, and Windows Server 2008 R2 Beta.

The worm has been unusually difficult for network operators and law enforcement to counter because of its combined use of advanced malware techniques.

How to Check if you are Infected by Conficker?

Conficker.B and Conficker.C infections can be detected simply by surfing a web-page.

Conficker.A infections cannot be detected this way. Click here to check your system (for Conficker.B or Conficker.C) infection.

How to Remove Conficker?

Below are removal instruction and tools on how to remove conficker.

Removal Instructions

Removal Tools

Conficker Remote Scanners

Conficker Memory Disinfector

It is hard to identify files containing Conficker, because the executables are packed and encrypted. When Conficker runs in memory, it is fully unpacked. Our memory disinfector scans the memory of every running process in the system and terminates Conficker threads without touching the process it runs in. This helps to keep the system services running.

The tool itself and the source code can be downloaded here:

conficker_mem_killer.exe – 594 K
memscan.zip – 8.4 K

Detecting Conficker Files and Registry

Despite other reports, the file names and registry keys Conficker.B and Conficker.C use are not random. They are calculated on the basis of the hostname. We have developed a tool that you can run on your system to check for Conficker’s Dlls. Unfortunately, Conficker.A really uses random names and can therefore not be found this way.

It is at a very early development stage, but usable. We would be grateful to benefit from your changes if you develop it further.

Tool and source code are here:

regnfile.exe – 599 K
conficker_names.zip

Nonficker Vaccination Tool

Conficker uses different global and local mutexes to ensure that only the most up-to-date version is run on the system. This fact can be exploited to scan for and to prevent infections.

We have developed our Nonficker Vaccination dll that can be installed as a system service and pretends to be a running Conficker by registering all mutexes from version .A, .B, and .C (and possibly .D depending which naming scheme you refer to). A setup tool to install the dll as system service is provided as well.

Removal instructions:

  • Open your favorite registry editor (e.g. Start->Run…->regedit.exe->ok)
  • Go to registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
  • Remove the “aaaaanonficker” from the “netsvcs” key
  • Remove registry key and all sibling keys: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aaaaanonficker

Besides vaccination, the mutexes can be used to scan for local infections. We have developed a small mutex scanner that tells you if you are infected.

Both tools and source code can be downloaded here:

nonficker.zip – 547 K
nonflicker_code.zip – 64 K

More information on using Network Scanner and Intrusion Detection Signatures. (via Universitat Bonn)

Stay informed. Follow us on Twitter, or subscribe to our Whatsthelatest RSS Feed.

Related Posts

Enjoy this Posts?

Your vote will help us grow this site. If you enjoyed this article, help us spread it to the world.

11 Comments

  1. April 7, 2009

    nice tips,thanks for sharing

  2. April 7, 2009

    Sure. My pleasure

  3. James
    April 7, 2009

    Hi,

    Good article. I found Sophos’ Conficker removal tool to be the best although i ran a few of them just to make sure.

    As long as people run these tools it should stop any serious outbreak.

    James

  4. April 7, 2009

    Hi, thanks for the compliment. Glad to know that it has helped you in anyway.

  5. April 12, 2009

    Your post is better than mine. This post contain every thing you should know about conficker. I’m going to put a link from my blog to this post.

  6. KENN
    April 14, 2009

    Hi Nice guide for the conficker virus on how to remove it, thanks and I will tell my colleagues about this site. :-)

  7. April 15, 2009

    Hi KENN,

    Glad to hear that you’re helping me promote my site to your colleagues. Thank you very much for that.
    Hope you find interesting stuffs here. :)

  8. December 24, 2009

    Hi,,
    its really good link. my server is full by conficker.

    i m trying all link by one by one. hopefully i know these are working>>>

    Thanks for this.

  9. December 25, 2009

    Hi, thanks for the visit. Yeah, you can try the steps here. Hope it helps. cheers!

  10. June 2, 2010

    meg nice2x bakod kagid ya more power!!!!!! thanks sa link lempyo na server ko… hehehe contact taka meg dason may mapahimo d website….

  11. June 6, 2010

    @godfrey,

    :) glad it helps…thanks for the compliment and more power man saimo ah :D

Add a comment

{ .. Get a Gravatar .. }

Subscribe without commenting

blog comments powered by Disqus