Conficker worm

Post Reply
cdd
Posts: 2607
Joined: Fri 15 Aug, 2003 14.05

Presumably you've all heard about the conficker worm that the media are hyping about. However I have a question.

Namely, if this worm connects to a list of predictable domain names to download updates for itself, why can't the security companies set up a future domain name that contains software that removes the worm?

What am I missing here?
User avatar
marksi
Posts: 1892
Joined: Wed 07 Jan, 2004 05.38
Location: Donaghadee

The fact that the malware is unlikely to be programmed to visit a site that would remove it?
:?
cdd
Posts: 2607
Joined: Fri 15 Aug, 2003 14.05

Well I agree the creators wouldn't go out of their way to make it possible but the way I understand it is that the virus goes to randomly generated websites so the creators can avoid getting one fixed site shut down. So the security companies have been able to predict future websites to monitor how many people have the virus.

So my guess is there's something wrong with my understanding somewhere. If they are able to create servers which the virus contacts to download software, why can't they put software up that removes it?
User avatar
Sput
Posts: 7543
Joined: Wed 20 Aug, 2003 19.57

I thought it was instructed to do everything, so you'd probably have flexibility as the guy in charge to make it update from anywhere you wanted.
Knight knight
User avatar
Netizen
Posts: 197
Joined: Wed 17 Oct, 2007 19.16
Location: Wakefield

Wish I had a botnet, seems like a more effective way of making many PCs do what they're told than fathoming out why I can't get group policies to stick on the company LAN :(
Martin
Posts: 386
Joined: Sat 09 Aug, 2003 20.01
Location: U.K.

The company I work for has been crippled by the virus over the past 4 weeks. Everyone in I.T. seems to be running around after the virus so if you want anything else done your up a gum tree. There is now a 'usb stick' amnesty where no one is to use them outwith the company network. :roll:
rts
Posts: 1637
Joined: Fri 15 Aug, 2003 14.09

How do you know if your PC has been infected, how do you remove it, and how do you stop it coming back?
Image
User avatar
Sput
Posts: 7543
Joined: Wed 20 Aug, 2003 19.57

Stop looking at porn, rod! :)
Knight knight
rts
Posts: 1637
Joined: Fri 15 Aug, 2003 14.09

You've rumbled me!
Image
Jovis
Posts: 1454
Joined: Fri 25 Aug, 2006 20.08

rts wrote:You've rumbled me!
Is that a line from the film?
rts
Posts: 1637
Joined: Fri 15 Aug, 2003 14.09

10 points Jovis. Very good ;)
Image
Post Reply