Conficker Worm is Still Circulating in TM Datacenter
Posted By Raymond In Category: Computer
19
2010
Probably many of you have heard of the Conficker worm that has infected probably millions of computers in the whole world. As long as the computer is running an unpatched Windows XP or Vista, or without an Internet Security or Antivirus that can detect Conficker, chances are the worm could have found their way in. Conficker worm is quite an old news but only until recently I have encountered with this Conficker worm. I rented a dedicated server in Malaysia located in TM datacenter and the webhost installed Windows Server 2008 R2. I don’t really need a server operating system so I requested them to change it to the good old Windows XP.
Once they have finished installing XP, they gave me the user account information so that I can login using Remote Desktop Connection. The first thing that I always do when I get my hands on a newly installed Windows operating system is to go to Windows Update to download the hotfixes and service pack. I opened Internet Explorer and the default Microsoft page couldn’t load. Then I tried accessing the Windows Update and the page wasn’t accessible too! There was no problems in loading Google.com. The first thing that came to my mind was a bad HOSTS file. I checked the HOSTS file and it was clean. Next thing in line that could be the problem is the DNS server which translates domain name to IP address. Changed to Google DNS servers but still no go.
Finally I figured that it could be a virus or worm so I searched in Symantec’s website and the symptoms points to a Conficker worm. The Conficker worm is so shockingly smart that it was able to instantly infect a non patched Windows XP automatically by hacking in without any user interaction.
Fortunately the fix was pretty easy. All I need to do was stop dnscache service so that I can access the security websites again and download the Conficker Removal Tool. Once Conficker has been removed with the tool, I can visit Windows Update to update Windows and prevent any known worm from infecting the computer.
1. To stop dnscache service
1. Press WIN+R
2. Type cmd and hit enter
3. Type net stop dnscache and hit enter
2. Download Conficker Removal Tool
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/D.exe
3. Update Windows
The conficker worm was discovered about 4 months ago and it is still circulating in TM datacenter. I guess the server administrators are to be blamed for the continuous spreading of the Conficker worm because they did not bother to perform regular maintenance. Did you had any experience with the Conficker worm? If yes please do share your experience with us.
Related posts:
-
Firas
-
David Macdonald
-
David
-
iOnda
-
Starboykb
-
sharadh
-
GAGANDEEP
-
cristi
-
Ahmad Saleem
-
roy raay
-
GottaBigOne
-
abdullah
-
Dan
-
wantp
-
Zeljko
-
DeathSeed
-
Decent60
-
kingpin
-
Mike
-
Dan Austin
-
p14c
-
Bairac Mihai
-
mahmoud
-
http://the-electronic-cigarette-store.co.cc fr33mumia
-
http://megablue.blogspot.com megablue
-
Ang
-
venkat
-
norman
-
providensia
-
grillermo
-
Norman
Recent Posts
- Download from Multiple File Hosting with One Multi-Host Downloader Account
- Enable Cancel Sent Email Feature in Gmail
- How to Shut Down in Windows 8
- FTP Droplet Allows Uploading Files Without Knowing FTP Login Details
- Disable UAC for Specific Software in Windows 7 with UAC Trust Shortcut
- A Sad Day…
- Google Books Downloader Saves eBooks in PDF or Images