Third party information on conficker, (Fri, Feb 13th)
(This will be updated as more information becomes public)
UPDATES ARE HIGHLIGHTED IN GREEN
In an effort to provde YOU the enduser the ability to educate your self on this threat I will be posting as much information as possible, from as many sources as possible. This may lead to redundancies in the data that is avalible but I am hoping that this will allow you to pick and choose the information, removal tool, and more importantly your own path when mitigating Conficker. Please do note that ISC nor SANS is verifying the validity of any of the information or tools present here (you can check our own posts on this topic, or compare against multiple sources). ALWAYS TEST IN A DEV OR TEST ENVIRONMENT BEFORE ROLLING OUT TO PRODUCTION!
Removal Instructions
Microsoft
support.microsoft.com/kb/962007
/> Kaspersky
support.kaspersky.com/faq/
/> BitDefender
www.bitdefender.com/VIRUS-1000462-en–Win32.Worm.Downadup.Gen.html
/> TrendMicro
www.trendmicro.com/vinfo/virusencyclo/default5.asp
/> Sophos
www.sophos.com/support/knowledgebase/article/51416.html
/>
Removal Tools
Microsoft MSRT
www.microsoft.com/security/malwareremove/default.mspx
/> F-Secure
ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip
AhnLab
www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99
/> McAfee
vil.nai.com/vil/stinger/
/> ESET
download.eset.com/special/EConfickerRemover.exe
/> BitDefender
data2.kaspersky-labs.com:8080/special/KidoKiller_v3.3.3.zip
/> TrendMicro
www.trendmicro.com/ftp/products/pattern/spyware/fixtool/SysClean-WORM_DOWNAD.zip
/> Sophos
asert.arbornetworks.com/2009/02/the-conficker-cabal-announced/
/> ICANN
www.icann.org/en/announcements/announcement-2-12feb09-en.htm
/> Symantec
End user/Consumer page
www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
/>
IT Security/Professional Page
technet.microsoft.com/en-us/security/dd452420.aspx
/>
Centralized information about Conficker
blogs.technet.com/mmpc/archive/2009/01/22/centralized-information-about-the-conficker-worm.aspx
/>
SecureWorks
www.secureworks.com/research/threats/downadup-removal/
/>
Research (technical)
SRI
mtc.sri.com/Conficker
/> MNIN Security Blog
blog.threatexpert.com/2009/01/confickerdownadup-memory-injection.html
/> CERT.at
www.cert.at/static/conficker/TR_Conficker_Detection.pdf
(great paper that covers setting up your local DNS server to mitigate/alert on infections)
Sample zonefiles can be downloaded here
www.cert.at/english/downloads/downloads.html
And last but not least, the previous ISC articles on Conficker!
Internet Storm Center (SANS)
isc.sans.org/diary.html?storyid=5695
/>
isc.sans.org/diary.html?storyid=5671
/>
isc.sans.org/diary.html?storyid=5830
/>