<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Giedrius Majauskas blog &#187; conficker</title>
	<atom:link href="http://www.majauskas.com/tag/conficker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.majauskas.com</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 15:37:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New development in virus market &#8211; Conficker family</title>
		<link>http://www.majauskas.com/new-development-in-virus-market-conficker-family</link>
		<comments>http://www.majauskas.com/new-development-in-virus-market-conficker-family#comments</comments>
		<pubDate>Fri, 27 Mar 2009 12:17:39 +0000</pubDate>
		<dc:creator>Giedrius Majauskas</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>

		<guid isPermaLink="false">http://www.majauskas.com/?p=115</guid>
		<description><![CDATA[Conficker (latest one is Conficker.C) is one of the few malwares nowdays that bring something new in the market that relies on new names and new skins only. The thing distinguishing it from crowd is unique registry modification scheme that makes its removal difficult for comon spyware removers. The trick used by Conficker.C is seting up [...]]]></description>
			<content:encoded><![CDATA[<p>Conficker (latest one is Conficker.C) is one of the few malwares nowdays that bring something new in the market that relies on new names and new skins only. The thing distinguishing it from crowd is unique registry modification scheme that makes its removal difficult for comon spyware removers.</p>
<p>The trick used by Conficker.C is seting up registry permissions instead of inserting registry keys only. And you can not modify registry permission from the lowest leaf of affected tree &#8211; you need to traverse whole tree and start modifying it from top node. Thus removal instructions, just stating that you need removing single node  like</p>
<p>HKCUSoftwareMicrosoftWindowsCurrentVersionRun[Random String] = “rundll32.exe [Worm Executable], [Random String]”</p>
<p>are not fully correct. You need to check and fix the whole tree!.</p>
<p>There are couple dedicated tools that help you with removing Conficker and similar parasites. One of them is produced by <a  href="http://www.enigmasoftware.com/a1/download/cfremover.exe">enigma software group &#8211; conficker remover</a>. Though I would suggest using complete spyware remover like <a  href="http://www.majauskas.com/spdoc.exe">Spyware Doctor</a> or Malwarebytes Anti-Malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.majauskas.com/new-development-in-virus-market-conficker-family/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

