Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
ZTE MF283U 4G Unlocked Router (Used)
ayanthamaxi
Updated:
Sunday at 8:26 PM
ලංකාවේ හොඳම උපකාරක පන්ති සහ ගුරුවරුන් එකම තැනකින් - TopTuition.lk
dulithapathum
Updated:
Jul 18, 2026
Colombo
RidhMathraa ’26 🎶✨
Tmadhusanka
Updated:
Jul 15, 2026
Ad icon
Colombo
PXN V10 Pro Direct Drive Racing Wheel (Under Warranty)
Abdur Rahman
Updated:
Jul 15, 2026
Ad icon
USDT ණය සේවාව - USDT Loan Service
පුරවැසියා
Updated:
Jul 15, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
Computers & Internet
Software Development
April 1 beware of this !!!!!! [warning] Conficker.C start woking 1st april [warning]
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Manojfdo" data-source="post: 4230393" data-attributes="member: 3576"><p>Pinch VIRUS DETAILS:Conficker.C</p><p></p><p>Win32/Conficker.C</p><p></p><p>Date Published:</p><p>11 Mar 2009</p><p></p><p>Last Updated:</p><p>11 Mar 2009</p><p>Threat Assessment</p><p>Overall Risk: Low</p><p>Wild: Low</p><p>Destructiveness: Medium</p><p>Pervasiveness: Medium</p><p></p><p>Characteristics</p><p></p><p>Type : Worm</p><p></p><p>Category : Win32</p><p></p><p>Also known as: Worm:Win32/Conficker.D (MS OneCare), W32/Confick-G (Sophos), Trojan.Win32.Pakes.ngs (Kaspersky)</p><p></p><p>Method of InfectionDevlish</p><p></p><p>When executed, Win32/Conficker.C drops a copy of itself using a random filename in the %System% directory. It may also drop copies of itself in the following directories:</p><p></p><p>%Program Files%\Windows NT</p><p>%Program Files%\Windows Media Player</p><p>%Program Files%\Internet Explorer</p><p>%Program Files%\Movie Maker</p><p></p><p>For these and other dropped files, Win32/Conficker.C:</p><p></p><p>* Sets Read Only, Hidden and System file attributes</p><p>* Generates a file creation/access time-stamp based on that of "kernel32.dll"</p><p>* Creates access control entries</p><p>* Exclusively locks the file, thus restricting access and privileges</p><p></p><p>Note: %System% and %Program Files% are variable locations. The malware determines the locations of these folders by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; for XP and Vista is C:\Windows\System32. A typical location for the Program Files folder would be C:\Program Files.</p><p></p><p>In order to automatically execute at each startup, it adds the registry entry below:</p><p></p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<random string> = "rundll32.exe <worm executable>, <random string>"</p><p></p><p>Conficker also registers a service with a random name created by combining a word from this list:</p><p></p><p>App</p><p>Audio</p><p>DM</p><p>ER</p><p>Event</p><p>help</p><p>Ias</p><p>Ir</p><p>Lanman</p><p>Net</p><p>Ntms</p><p>Ras</p><p>Remote</p><p>Sec</p><p>SR</p><p>Tapi</p><p>Trk</p><p>W32</p><p>win</p><p>Wmdm</p><p>Wmi</p><p>wsc</p><p>wuau</p><p>xml</p><p></p><p>with another word from this list:</p><p></p><p>access</p><p>agent</p><p>auto</p><p>logon</p><p>man</p><p>mgmt</p><p>mon</p><p>prov</p><p>serv</p><p>Server</p><p>Service</p><p>Srv</p><p>srv</p><p>svc</p><p>Svc</p><p>System</p><p>Time</p><p></p><p>The worm also derives a display name for the service by combining two words from the list below:</p><p></p><p>Audit</p><p>Backup</p><p>Boot</p><p>Browser</p><p>Center</p><p>Component</p><p>Config</p><p>Control</p><p>Discovery</p><p>Driver</p><p>Framework</p><p>Hardware</p><p>Helper</p><p>Image</p><p>Installer</p><p>Logon</p><p>Machine</p><p>Management</p><p>Manager</p><p>Microsoft</p><p>Monitor</p><p>Network</p><p>Notify</p><p>Policy</p><p>Power</p><p>Security</p><p>Shell</p><p>Storage</p><p>Support</p><p>System</p><p>Task</p><p>Time</p><p>Trusted</p><p>Universal</p><p>Update</p><p>Windows</p><p></p><p>For example, the worm may register a service with these registry entries:</p><p></p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\DisplayName = "Component Task"</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Type = 00000020</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Start = 00000002</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ErrorControl = 00000000</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ImagePath = "%Root%\system32\svchost.exe -k netsvcs"</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ObjectName = "LocalSystem"</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Description = "<randomly copied from an existing service with a Startup Type of 2 >"</p><p>HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Parameters\ServiceDll = "%System%\<worm executable >"</p><p><img src="http://www.ca.com/us/securityadvisor/virusinfo/showimage.aspx?caid=77976&name=confickerc_newservice.gif" alt="" class="fr-fic fr-dii fr-draggable " style="" /></p><p></p><p>Note: %Root% is a variable location. The malware determines the location of the current root drive by querying the operating system. A typical location for the root drive would be C:\.</p><p></p><p>Additionally, Win32/Conficker.C checks for and tries to inject code into any processes executed with the commandline parameters "svchost.exe -k NetworkService".</p><p>Payload</p><p>Modifies Registry / Lowers Security Settings</p><p></p><p>Win32/Conficker.C deletes the following registry entry to deactivate Windows Security Center notifications:</p><p></p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}</p><p></p><p>It deletes the registry entry below to prevent the operating system from starting in Safe Mode:</p><p></p><p>HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot</p><p></p><p>Additionally, Win32/Conficker.C deletes the below registry entry to prevent "Windows Defender" from executing on system start:</p><p></p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender</p><p></p><p>Deletes Restore Points</p><p></p><p>Conficker resets all system restore points and deletes any saved system restore points on the affected system.</p><p></p><p>Disables Services</p><p></p><p>Win32/Conficker.C looks for and disables the following services if running:</p><p></p><p>wscsvc - Security Center</p><p>WinDefend &#150; Windows Defender (available in Vista)</p><p>wuauserv - Automatic Updates</p><p>BITS - Background Intelligent Transfer Service</p><p>ERSvc - Error Reporting Service</p><p>WerSvc - Windows Error Reporting Service (available in Vista)</p><p></p><p>[Image: showimage.aspx?caid=77976&name=c...rvices.gif]</p><p><img src="http://www.ca.com/us/securityadvisor/virusinfo/showimage.aspx?caid=77976&name=confickerc_services.gif" alt="" class="fr-fic fr-dii fr-draggable " style="" /></p><p>Win32/Conficker.C terminates the following security-related processes in an attempt to prevent its removal from the system:</p><p></p><p>autoruns</p><p>avenger</p><p>confick</p><p>downad</p><p>filemon</p><p>gmer</p><p>hotfix</p><p>kb890</p><p>kb958</p><p>kido</p><p>klwk</p><p>mbsa.</p><p>mrt.</p><p>mrtstub</p><p>ms08-06</p><p>procexp</p><p>procmon</p><p>regmon</p><p>scct_</p><p>sysclean</p><p>tcpview</p><p>unlocker</p><p>wireshark</p><p></p><p>Blocks Websites</p><p></p><p>Win32/Conficker.C hooks the following APIs to monitor and restrict access to security websites:</p><p></p><p>Query_Main</p><p>DnsQuery_W</p><p>DnsQuery_UTF8</p><p>DnsQuery_A</p><p>sendto</p><p></p><p>In its attempt to prevent access to security-related sites for information, help or software updates, the worm attempts to block running applications from accessing URLs containing any of the following strings:</p><p></p><p>avg.</p><p>avp.</p><p>bit9.</p><p>ca.</p><p>cert.</p><p>gmer.</p><p>kav.</p><p>llnw.</p><p>llnwd.</p><p>msdn.</p><p>msft.</p><p>nai.</p><p>sans.</p><p>vet.</p><p>agnitum</p><p>ahnlab</p><p>anti-</p><p>antivir</p><p>arcabit</p><p>avast</p><p>avgate</p><p>avira</p><p>bothunter</p><p>castlecops</p><p>ccollomb</p><p>centralcommand</p><p>clamav</p><p>comodo</p><p>computerassociates</p><p>conficker</p><p>cpsecure</p><p>cyber-ta</p><p>db networkassociates</p><p>defender</p><p>drweb</p><p>dslreports</p><p>emsisoft</p><p>esafe</p><p>eset</p><p>etrust</p><p>ewido</p><p>f-prot</p><p>f-secure</p><p>fortinet</p><p>free-av</p><p>freeav</p><p>gdata</p><p>grisoft</p><p>hackerwatch</p><p>hacksoft</p><p>hauri</p><p>ikarus</p><p>jotti</p><p>k7computing</p><p>kaspersky</p><p>malware</p><p>mcafee</p><p>microsoft</p><p>mirage</p><p>msftncsi</p><p>msmvps</p><p>mtc.sri</p><p>nod32</p><p>norman</p><p>norton</p><p>onecare</p><p>panda</p><p>pctools</p><p>prevx</p><p>ptsecurity</p><p>quickheal</p><p>removal</p><p>rising</p><p>rootkit</p><p>safety.live</p><p>securecomputing</p><p>secureworks</p><p>sophos</p><p>spamhaus</p><p>spyware</p><p>sunbelt</p><p>symantec</p><p>technet</p><p>threat</p><p>threatexpert</p><p>trendmicro</p><p>trojan</p><p>virscan</p><p>virus</p><p>wilderssecurity</p><p>windowsupdate</p><p></p><p>Downloads and Executes Arbitrary Files</p><p></p><p>If the current system date is on or after 1 April 2009, the worm attempts to access pre-computed domain names to either download an updated copy of itself or download other malware. Below is a list of URL extensions used for pre-computed/generated URLs:</p><p></p><p>vn</p><p>vc</p><p>us</p><p>tw</p><p>to</p><p>tn</p><p>tl</p><p>tj</p><p>tc</p><p>su</p><p>sk</p><p>sh</p><p>sg</p><p>sc</p><p>ru</p><p>ro</p><p>ps</p><p>pl</p><p>pk</p><p>pe</p><p>no</p><p>nl</p><p>nf</p><p>my</p><p>mw</p><p>mu</p><p>ms</p><p>mn</p><p>me</p><p>md</p><p>ly</p><p>lv</p><p>lu</p><p>li</p><p>lc</p><p>la</p><p>kz</p><p>kn</p><p>is</p><p>ir</p><p>in</p><p>im</p><p>ie</p><p>hu</p><p>ht</p><p>hn</p><p>hk</p><p>gy</p><p>gs</p><p>gr</p><p>gd</p><p>fr</p><p>fm</p><p>es</p><p>ec</p><p>dm</p><p>dk</p><p>dj</p><p>cz</p><p>cx</p><p>com.ve</p><p>com.uy</p><p>com.ua</p><p>com.tw</p><p>com.tt</p><p>com.tr</p><p>com.sv</p><p>com.py</p><p>com.pt</p><p>com.pr</p><p>com.pe</p><p>com.pa</p><p>com.ni</p><p>com.ng</p><p>com.mx</p><p>com.mt</p><p>com.lc</p><p>com.ki</p><p>com.jm</p><p>com.hn</p><p>com.gt</p><p>com.gl</p><p>com.gh</p><p>com.fj</p><p>com.do</p><p>com.co</p><p>com.bs</p><p>com.br</p><p>com.bo</p><p>com.ar</p><p>com.ai</p><p>com.ag</p><p>co.za</p><p>co.vi</p><p>co.uk</p><p>co.ug</p><p>co.nz</p><p>co.kr</p><p>co.ke</p><p>co.il</p><p>co.id</p><p>co.cr</p><p>cn</p><p>cl</p><p>ch</p><p>cd</p><p>ca</p><p>bz</p><p>bo</p><p>be</p><p>at</p><p>as</p><p>am</p><p>ag</p><p>ae</p><p>ac</p><p><img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /> <img src="/styles/default/xenforo/smilies/default/no.gif" class="smilie" loading="lazy" alt=":no:" title="No :no:" data-shortname=":no:" /></p></blockquote><p></p>
[QUOTE="Manojfdo, post: 4230393, member: 3576"] Pinch VIRUS DETAILS:Conficker.C Win32/Conficker.C Date Published: 11 Mar 2009 Last Updated: 11 Mar 2009 Threat Assessment Overall Risk: Low Wild: Low Destructiveness: Medium Pervasiveness: Medium Characteristics Type : Worm Category : Win32 Also known as: Worm:Win32/Conficker.D (MS OneCare), W32/Confick-G (Sophos), Trojan.Win32.Pakes.ngs (Kaspersky) Method of InfectionDevlish When executed, Win32/Conficker.C drops a copy of itself using a random filename in the %System% directory. It may also drop copies of itself in the following directories: %Program Files%\Windows NT %Program Files%\Windows Media Player %Program Files%\Internet Explorer %Program Files%\Movie Maker For these and other dropped files, Win32/Conficker.C: * Sets Read Only, Hidden and System file attributes * Generates a file creation/access time-stamp based on that of "kernel32.dll" * Creates access control entries * Exclusively locks the file, thus restricting access and privileges Note: %System% and %Program Files% are variable locations. The malware determines the locations of these folders by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; for XP and Vista is C:\Windows\System32. A typical location for the Program Files folder would be C:\Program Files. In order to automatically execute at each startup, it adds the registry entry below: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<random string> = "rundll32.exe <worm executable>, <random string>" Conficker also registers a service with a random name created by combining a word from this list: App Audio DM ER Event help Ias Ir Lanman Net Ntms Ras Remote Sec SR Tapi Trk W32 win Wmdm Wmi wsc wuau xml with another word from this list: access agent auto logon man mgmt mon prov serv Server Service Srv srv svc Svc System Time The worm also derives a display name for the service by combining two words from the list below: Audit Backup Boot Browser Center Component Config Control Discovery Driver Framework Hardware Helper Image Installer Logon Machine Management Manager Microsoft Monitor Network Notify Policy Power Security Shell Storage Support System Task Time Trusted Universal Update Windows For example, the worm may register a service with these registry entries: HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\DisplayName = "Component Task" HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Type = 00000020 HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Start = 00000002 HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ErrorControl = 00000000 HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ImagePath = "%Root%\system32\svchost.exe -k netsvcs" HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\ObjectName = "LocalSystem" HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Description = "<randomly copied from an existing service with a Startup Type of 2 >" HKLM\SYSTEM\CurrentControlSet\Services\IrSvc\Parameters\ServiceDll = "%System%\<worm executable >" [IMG]http://www.ca.com/us/securityadvisor/virusinfo/showimage.aspx?caid=77976&name=confickerc_newservice.gif[/IMG] Note: %Root% is a variable location. The malware determines the location of the current root drive by querying the operating system. A typical location for the root drive would be C:\. Additionally, Win32/Conficker.C checks for and tries to inject code into any processes executed with the commandline parameters "svchost.exe -k NetworkService". Payload Modifies Registry / Lowers Security Settings Win32/Conficker.C deletes the following registry entry to deactivate Windows Security Center notifications: HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC} It deletes the registry entry below to prevent the operating system from starting in Safe Mode: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot Additionally, Win32/Conficker.C deletes the below registry entry to prevent "Windows Defender" from executing on system start: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Windows Defender Deletes Restore Points Conficker resets all system restore points and deletes any saved system restore points on the affected system. Disables Services Win32/Conficker.C looks for and disables the following services if running: wscsvc - Security Center WinDefend – Windows Defender (available in Vista) wuauserv - Automatic Updates BITS - Background Intelligent Transfer Service ERSvc - Error Reporting Service WerSvc - Windows Error Reporting Service (available in Vista) [Image: showimage.aspx?caid=77976&name=c...rvices.gif] [IMG]http://www.ca.com/us/securityadvisor/virusinfo/showimage.aspx?caid=77976&name=confickerc_services.gif[/IMG] Win32/Conficker.C terminates the following security-related processes in an attempt to prevent its removal from the system: autoruns avenger confick downad filemon gmer hotfix kb890 kb958 kido klwk mbsa. mrt. mrtstub ms08-06 procexp procmon regmon scct_ sysclean tcpview unlocker wireshark Blocks Websites Win32/Conficker.C hooks the following APIs to monitor and restrict access to security websites: Query_Main DnsQuery_W DnsQuery_UTF8 DnsQuery_A sendto In its attempt to prevent access to security-related sites for information, help or software updates, the worm attempts to block running applications from accessing URLs containing any of the following strings: avg. avp. bit9. ca. cert. gmer. kav. llnw. llnwd. msdn. msft. nai. sans. vet. agnitum ahnlab anti- antivir arcabit avast avgate avira bothunter castlecops ccollomb centralcommand clamav comodo computerassociates conficker cpsecure cyber-ta db networkassociates defender drweb dslreports emsisoft esafe eset etrust ewido f-prot f-secure fortinet free-av freeav gdata grisoft hackerwatch hacksoft hauri ikarus jotti k7computing kaspersky malware mcafee microsoft mirage msftncsi msmvps mtc.sri nod32 norman norton onecare panda pctools prevx ptsecurity quickheal removal rising rootkit safety.live securecomputing secureworks sophos spamhaus spyware sunbelt symantec technet threat threatexpert trendmicro trojan virscan virus wilderssecurity windowsupdate Downloads and Executes Arbitrary Files If the current system date is on or after 1 April 2009, the worm attempts to access pre-computed domain names to either download an updated copy of itself or download other malware. Below is a list of URL extensions used for pre-computed/generated URLs: vn vc us tw to tn tl tj tc su sk sh sg sc ru ro ps pl pk pe no nl nf my mw mu ms mn me md ly lv lu li lc la kz kn is ir in im ie hu ht hn hk gy gs gr gd fr fm es ec dm dk dj cz cx com.ve com.uy com.ua com.tw com.tt com.tr com.sv com.py com.pt com.pr com.pe com.pa com.ni com.ng com.mx com.mt com.lc com.ki com.jm com.hn com.gt com.gl com.gh com.fj com.do com.co com.bs com.br com.bo com.ar com.ai com.ag co.za co.vi co.uk co.ug co.nz co.kr co.ke co.il co.id co.cr cn cl ch cd ca bz bo be at as am ag ae ac :no: :no: :no: :no: :no: :no: :no: :no: [/QUOTE]
Insert quotes…
Verification
Haya warak paha keeyada? (haya wadi kireema paha)
Post reply
Top
Bottom