Automated PC Solutions
VACM - Virus Alerts for the Common Man
As April 1, 2009 came and went, Conficker appeared to be a dud. But, Conficker is now
morphing into a real threat that you need to be aware of. New, virulent strains of Conficker
are now being detected in the wild.
F-Secure has made available a Conficker Removal Tool (W32.Downadup.GEN).
CONFICKER AWAKENS:
The Conficker worm started “waking up” recently (April 10, 2009) and there are now
some new Conficker variants showing up on computers worldwide. This Conficker variant,
one of the first, actually uses the “scareware” tactic
of popping up
phony “virus infection detected … click to get antivirus solution…”
messages which will then attempt to charge you $49.95 to buy the PHONY antivirus software
to remove a non-existent virus from your computer when
what you really have is a
Conficker virus infection that will NOT be removed by the phony antivirus software.
The phony software you would be presented with is called “Spyware Protect 2009” or
“Spyware Guard 2008”. If this happens to you, read the next section entitled "What You Should Do".
SCAREWARE TACTICS:
If you get any popups warning you that a virus was detected on your PC and offering to
let you get a removal tool by clicking a button or link, do NOT do it. This is a scareware
tactic. Scareware tactics are designed
only to scare you into entering your credit card
information for a phony product to get rid of a phony virus. The scareware scam seems
to be coming from a server in the Ukraine, according to the Washington
Post.
NOTE: within just the past couple of months, we also reported on the "Antivirus XP" scareware tactic.
This particular Conficker/Downadup payload uses a very similar
tactic to steal your money.
***************************************************
* What You Should Do
***************************************************
How to protect against the Conficker / Downadup virus
STAY SAFE:
To stay protected from Conficker and its variants, you must make sure that you
have ALL the latest Windows Updates and all the latest updates for your antivirus software.
How Conficker/Downadup Spreads:
Conficker spreads itself to other computers in many different ways. This virus can be carried
by MP3 players, Digital Cameras, USB thumb drives, your local network, infected websites
and any USB or FireWire device that looks like a disk drive to Windows, etc.
Conficker is VERY adept at spreading and has been the fastest spreading virus we have
seen in many years.
IF YOU GET INFECTED - Conficker Removal Tools and Instructions:
If you get infected with Conficker, seek help from a qualified computer tech. If you
are confident in your computer skills, you can also read how to manually get rid of
Conficker with our detection
and removal instructions for Conficker/Downadup here.
Easier still, download the Conficker/Downadup Removal Tool and follow the
instructions on how to use these tools. If you are not comfortable using command line
tools, seek
help from an experienced computer person.
Please pass this info on to your employees, friends, etc.
********************************************************
* W32/Downadup.gen Removal Tool
********************************************************
To find out if your system(s) are infected and to remove the Conficker/Downadup infection,
F-Secure provides these W32/Downadup.gen Removal Tools.
Please note that F-Secure says the following about the Downadup/Conficker removal tool:
Best Regards,
Marc Deschenes, VACM Editor
The VACM Project at
Automated PC Solutions
|
*** Be sure to check out the appendix at the end of this alert
******** APPENDIX - Handy How-To Tips ********** * How To Boot into Safe Mode Shut the computer down so that the power is off.
|