70470 Posts in 6879 Topics - by 687 Members - Latest Member: Laricwashere

Author Topic: Conficker scanner!  (Read 1399 times)

Offline decepticon

  • Staff
  • Godlike Gamer
  • *
  • Posts: 5763
  • Karma: 6
  • aka "Deception"
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: seanryan52
  • XBox Gamer Tag: Decpticon
  • XFire: decepticon420
Conficker scanner!
« on: March 30, 2009, 08:32:14 PM »
I am sure most if not all of you have heard of the Conficker virus that is supposed to unleash holy hell in the computing world on 4/1/2009.  It's the biggest internet/virus scare since Y2K.  Anywhoo, supposedly there is no way to scan for the virus....until now.

From the Hack-a-day article:
http://hackaday.com/2009/03/30/containing-conficker/

Quote
With all the noise about Conficker turning your computer into liquid hot magma on April 1st, there’s actually some positive news. Researchers from the HoneyNet Project have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely.


There is a tool available that will scan a remote system via it's IP or a range of IP's and will report whether or not the system shows signs of an infection.  If you even remotely think you may have an infection, it's worth it to run this scan!

For the file and some basic instructions:
http://www.doxpara.com/?p=1291

or for just the file:
http://www.doxpara.com/scs.zip


That's Mr. Deception to you.

Offline Czar

  • Event Administrator
  • Sponsorship Coordinator
  • Godlike Gamer
  • *
  • Posts: 4632
  • Karma: 11
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: therealdealmobile@hotmail.com
  • XBox Gamer Tag: IAmCzarAlex
  • XFire: czaralex
Re: Conficker scanner!
« Reply #1 on: March 30, 2009, 09:07:58 PM »
Thanks for the link. I appear to be clean!

Offline h4gg4rd

  • Vintage VIP
  • Supreme Gamer
  • *
  • Posts: 287
  • Karma: 0
  • GIRUGAMESH!
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: newdealskater420@juno.com
  • XBox Gamer Tag: h4gg4rd420
  • XFire: h4gg4rd
Re: Conficker scanner!
« Reply #2 on: March 30, 2009, 09:12:30 PM »
hmmm interesting.

thank you for the heads up sir.

"cover me I'm bout to get my bazooka"

- c-note

Offline sully!

  • Administrator
  • Godlike Gamer
  • *
  • Posts: 4997
  • Karma: 16
  • If the future is now, where's my jetpack?
  • OS:
  • Windows 7 Windows 7
  • Browser:
  • Minefield 3.6a1pre Minefield 3.6a1pre
  • Steam ID: sully213
  • XBox Gamer Tag: FITESully
Re: Conficker scanner!
« Reply #3 on: March 30, 2009, 09:30:37 PM »
Saw a similar thing on Slashdot earlier today...

http://it.slashdot.org/article.pl?sid=09/03/30/090224&from=rss

Wednesday has the potential to be a very bad day in the IT world, but we've been pretty thorough in our preparedness of our IT systems in preparation of ConFudgeer. I just hope our engineering department has been too.
Please just walk away. I don't want to have to stand here and say something so awesome that I'll have to remember it the rest of the day. Thank you!

Offline {ShadowWX}

  • Vintage VIP
  • Uber Gamer
  • *
  • Posts: 1177
  • Karma: 0
  • OS:
  • Windows Vista Windows Vista
  • Browser:
  • Firefox 3.0.3 Firefox 3.0.3
  • XBox Gamer Tag: Shadowwx1017
Re: Conficker scanner!
« Reply #4 on: March 31, 2009, 06:34:37 AM »
now my question is will my norton be able to find and eliminate this thing if I have it?
~ShadowWX~



Offline decepticon

  • Staff
  • Godlike Gamer
  • *
  • Posts: 5763
  • Karma: 6
  • aka "Deception"
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: seanryan52
  • XBox Gamer Tag: Decpticon
  • XFire: decepticon420
Re: Conficker scanner!
« Reply #5 on: March 31, 2009, 07:18:31 AM »
now my question is will my norton be able to find and eliminate this thing if I have it?

Not sure.  As of now, I heard that the av companies have no way to scan for the virus until maybe after it get's "activated" on 4/1. 
That's Mr. Deception to you.

Offline decepticon

  • Staff
  • Godlike Gamer
  • *
  • Posts: 5763
  • Karma: 6
  • aka "Deception"
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: seanryan52
  • XBox Gamer Tag: Decpticon
  • XFire: decepticon420
Re: Conficker scanner!
« Reply #6 on: March 31, 2009, 07:52:06 AM »
Oh, if anyone is interested: here is a whitepaper on the deconstruction and detection of Conficker.

http://www.honeynet.org/files/KYE-Conficker.pdf
That's Mr. Deception to you.

Offline h4gg4rd

  • Vintage VIP
  • Supreme Gamer
  • *
  • Posts: 287
  • Karma: 0
  • GIRUGAMESH!
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: newdealskater420@juno.com
  • XBox Gamer Tag: h4gg4rd420
  • XFire: h4gg4rd
Re: Conficker scanner!
« Reply #7 on: March 31, 2009, 10:24:21 AM »
I am clean! Also I am wondering if NOD32 can detect and eliminate it as well.. It should though NOD32 is leet.

"cover me I'm bout to get my bazooka"

- c-note

Offline decepticon

  • Staff
  • Godlike Gamer
  • *
  • Posts: 5763
  • Karma: 6
  • aka "Deception"
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: seanryan52
  • XBox Gamer Tag: Decpticon
  • XFire: decepticon420
Re: Conficker scanner!
« Reply #8 on: March 31, 2009, 01:09:40 PM »
I am clean! Also I am wondering if NOD32 can detect and eliminate it as well.. It should though NOD32 is leet.

You'll have to check NOD32's website to see if they have a definition update that can check for this.
That's Mr. Deception to you.

Offline The Shoctor

  • Administrator
  • Godlike Gamer
  • *
  • Posts: 5803
  • Karma: 17
  • OS:
  • Windows Vista Windows Vista
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: shadohawk@shadoworks.net
  • XBox Gamer Tag: TheShoctor
  • XFire: shadoworks
Re: Conficker scanner!
« Reply #9 on: March 31, 2009, 03:06:52 PM »
« Last Edit: March 31, 2009, 03:10:11 PM by ShadoHawk »

Support LAN Play!
ლ(ಠ益ಠლ) "I have more than 20 friends EA!" --FITES.NET
(╯°□°)╯︵ ┻━┻
"Close enough." --UGC League

Offline h4gg4rd

  • Vintage VIP
  • Supreme Gamer
  • *
  • Posts: 287
  • Karma: 0
  • GIRUGAMESH!
  • OS:
  • Windows XP Windows XP
  • Browser:
  • Firefox 3.0.8 Firefox 3.0.8
  • Steam ID: newdealskater420@juno.com
  • XBox Gamer Tag: h4gg4rd420
  • XFire: h4gg4rd
Re: Conficker scanner!
« Reply #10 on: March 31, 2009, 11:33:47 PM »
Half hour into April 1st...

all quiet on the eastern front. =]]

"cover me I'm bout to get my bazooka"

- c-note

Offline {ShadowWX}

  • Vintage VIP
  • Uber Gamer
  • *
  • Posts: 1177
  • Karma: 0
  • OS:
  • Windows Vista Windows Vista
  • Browser:
  • Firefox 3.0.3 Firefox 3.0.3
  • XBox Gamer Tag: Shadowwx1017
Re: Conficker scanner!
« Reply #11 on: April 01, 2009, 06:50:09 AM »
through the tool you posted shado I appear to be clean.
~ShadowWX~