| View previous topic :: View next topic |
| Author |
Message |
PaNdAmAn Grandmaster Cheater
Reputation: 0
Joined: 22 Jun 2008 Posts: 521
|
Posted: Tue Mar 31, 2009 11:35 pm Post subject: What does the conficker worm do |
|
|
Don't be a dumb as and say it fkd up ur cmp what does it do to u
Make porn pop up
Restart comp every min
Keylog
What does it do
_________________

Remember Rep is always Appreciated<3 |
|
| Back to top |
|
 |
Prince charming How do I cheat?
Reputation: 0
Joined: 08 Aug 2008 Posts: 0
|
Posted: Tue Mar 31, 2009 11:37 pm Post subject: |
|
|
Nothing.
_________________
I have the power to take everything from you. Including your life. |
|
| Back to top |
|
 |
Cheetah I post too much
Reputation: 0
Joined: 11 Nov 2007 Posts: 2758
|
Posted: Wed Apr 01, 2009 12:22 am Post subject: |
|
|
Other than create mass hysteria over nothing, this:
| Prince charming wrote: | | Nothing. |
|
|
| Back to top |
|
 |
Aids Expert Cheater
Reputation: 16
Joined: 13 Jun 2008 Posts: 197
|
Posted: Wed Apr 01, 2009 12:45 am Post subject: |
|
|
| It does not exist.
|
|
| Back to top |
|
 |
Fap2Admin Master Cheater
Reputation: -1
Joined: 10 Feb 2008 Posts: 483 Location: Somewhere down the Road
|
Posted: Wed Apr 01, 2009 12:54 am Post subject: |
|
|
It does exist, but the threat about the 20m+ infected pc that will attk diff. Sites are plain* baloney. Overblown threat again, reminds me of Y2K
_________________
Best AR-TITS on CEF |
|
| Back to top |
|
 |
EBODude Expert Cheater
Reputation: 0
Joined: 18 Oct 2007 Posts: 136
|
Posted: Wed Apr 01, 2009 12:56 am Post subject: |
|
|
| Quote: |
Stops and Disables Services
Win32/Conficker.B disables the following services:
wscsvc - Security Center
wuauserv - Automatic updates
BITS - Background Intelligent Transfer Service
WinDefend - Windows Defender
ERSvc - Error Reporting Service
WerSvc - Windows Error Reporting Service
It does this by setting the following registry entries:
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\Start = "4"
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Start = "4"
HKLM\SYSTEM\CurrentControlSet\Services\BITS\Start = "4"
HKLM\SYSTEM\CurrentControlSet\Services\WinDefend\Start = "4"
HKLM\SYSTEM\CurrentControlSet\Services\ERSvc\Start = "4"
HKLM\SYSTEM\CurrentControlSet\Services\WerSvc\Start = "4"
Disables Security Notifications
The worm deletes the following registry entry which deactivates Windows Security Center notifications:
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellServiceObjects\{FD6905CE-952F-41F1-9A6F-135D9C6622CC}
Blocks Access to Websites
Win32/Conficker.B attempts to block running applications from accessing websites that contain any of the following strings in the URL:
Ccert.
sans.
bit9.
windowsupdate
wilderssecurity
threatexpert
castlecops
spamhaus
cpsecure
arcabit
emsisoft
sunbelt
securecomputing
rising
prevx
pctools
norman
k7computing
ikarus
hauri
hacksoft
gdata
fortinet
ewido
clamav
comodo
quickheal
avira
avast
esafe
ahnlab
centralcommand
drweb
grisoft
nod32
f'prot
jotti
kaspersky
f'secure
computerassociates
networkassociates
etrust
panda
sophos
trendmicro
mcafee
norton
symantec
microsoft
defender
rootkit
malware
spyware
virus
This prevents anti-malware programs from downloading vital signature updates, and the user from accessing security websites.
Modifies System Settings
Win32/Conficker.B executes the following command on the affected system if the operating system is Windows Vista or Windows Server 2008:
netsh interface tcp set global autotuning=disabled
This disables Windows auto-tuning.
Win32/Conficker.B sets the following registry entry to allow multiple simultaneuos connections on the affected system:
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpNumConnections = 0x00FFFFFE
Downloads and Executes Arbitrary Files
Win32/Conficker.B checks the system date before attempting to download and execute any files.
If it is on or after 1 January 2009, the worm attempts to access pre-computed domain names like the following:
cbchyttgqay.biz
cqazvyszh.com
dicgdsp.org
dzxecapiw.info
epwqbyya.com
fogzchqe.org
gkenjj.biz
iwtrubh.biz
jvikldgo.net
kcgxgnny.net
lyhivgkd.org
mefenydz.com
mfqal.net
nprzq.biz
ojzarbw.net
rheni.org
syqxvsid.com
tyoxnaqjrlu.org
ukdikl.org
uqruninkqca.net
uzapl.com
vyuiwltf.com
xskeqrcl.net
xxhdy.net
xxztb.org
yeofa.org
yeynxe.net
yjodeikka.org
yprpg.biz
ytcqft.com
Deletes System Restore Points
Win32/Conficker.B resets all system restore points and deletes all saved system restore points on the compromised system.
Backdoor Functionality
Win32/Conficker.B starts an HTTP server on the affected system by opening a random port, shown below. This allows a copy of the worm to be downloaded by systems vulnerable to MS08-067.
The downloaded files usually have the following file extensions:
.BMP
.GIF
.PNG
.JPG
The worm also searches for an Internet Gateway device in the network and configures it to allow the malware-opened port to be accessed outside the network.
Win32/Conficker.B checks for Internet connectivity by accessing the URLs below:
www.aol.com
www.cnn.com
www.ebay.com
www.msn.com
www.myspace.com
The worm also tries to obtain the IP address of the affected system by accessing the following legitimate websites:
checkip.dyndns.org
www.getmyip.org
www.whatismyip.org
www.whatsmyipaddress.com |
|
|
| Back to top |
|
 |
Aids Expert Cheater
Reputation: 16
Joined: 13 Jun 2008 Posts: 197
|
Posted: Wed Apr 01, 2009 12:56 am Post subject: |
|
|
| Freak X wrote: | | It does not exist, but the threat about the 20m+ infected pc that will attk diff. Sites are plain* baloney. Overblown threat again, reminds me of Y2K |
|
|
| Back to top |
|
 |
EBODude Expert Cheater
Reputation: 0
Joined: 18 Oct 2007 Posts: 136
|
Posted: Wed Apr 01, 2009 1:02 am Post subject: |
|
|
oh and i lol'd
| Quote: | | Although the origin of the name "conficker" is not known with certainty, Internet specialists and others have speculated that it is a German portmanteau fusing the term "configure" with "ficken", the German word for "fuck." |
|
|
| Back to top |
|
 |
Fap2Admin Master Cheater
Reputation: -1
Joined: 10 Feb 2008 Posts: 483 Location: Somewhere down the Road
|
Posted: Wed Apr 01, 2009 1:10 am Post subject: |
|
|
Although the conficker won't end the internet, the kornfucker(or lloydkornfucker) will.
Search "cornfucker" here in cef to know more
_________________
Best AR-TITS on CEF |
|
| Back to top |
|
 |
Prince charming How do I cheat?
Reputation: 0
Joined: 08 Aug 2008 Posts: 0
|
Posted: Wed Apr 01, 2009 1:16 am Post subject: |
|
|
| Freak X wrote: | Although the conficker won't end the internet, the kornfucker(or lloydkornfucker) will.
Search "cornfucker" here in cef to know more |
It wans't really funny.
_________________
I have the power to take everything from you. Including your life. |
|
| Back to top |
|
 |
{-}Sketch{-} Advanced Cheater
Reputation: 0
Joined: 22 Sep 2007 Posts: 53 Location: In Your Webz Eating Your Cookies!
|
Posted: Wed Apr 01, 2009 3:00 am Post subject: |
|
|
it dose all of the above!
_________________
ಠ_ಠ |
|
| Back to top |
|
 |
|