DCSIMG
Conficker - Avi Samocha's Blog

Avi Samocha's Blog

Microsoft Products and Technologies

Browse by Tags

All Tags » Conficker (RSS)
The W32.Downadup/W32.Conficker Worm
Hi All, As you probably heard, there is a new worm spreading lately that affects Windows based computers. The worm spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability described in Microsoft Security Bulletin MS08-067 . The worm, once infecting a computer, does the following: Extract all its files to the %System% directory with random DLL file names. Delete the user’s Restore Points. Create a services called Netsvcs and adds a registry key for...