Stopping Conficker

October 7, 2009

Conficker is a notorious computer worm that has been infecting Windows computers since early November 2008. Simply put, it uses flaws in Windows to co-opt your computer and link it to a giant collection of other computers (called a "botnet") that can be remotely commanded by the worm's authors.

FYI: Conficker only affects Windows computers, so if you're running a Mac or Linux-based operating system, you can stop panicking now.

Symptoms

Signs that you have Conficker include:

  • Some services have been turned off (updates, Windows Defender, etc.)
  • User account lockout policies are being reset automatically
  • Websites related to antivirus software are inaccessible

The easiest way to diagnose your computer is to use the Conficker Eye Chart. Open the link and wait for the page to finish loading. If you see all six images at the top, you're squeaky clean. If some or all of the images on the top row are missing, you may have Conficker.

Removal

Many antivirus software companies have written tools to fight Conficker, so the removal procedure is surprisingly easy. We'll be using Microsoft's free Malicious Software Removal Tool, which you can download from here.

  1. Download the .exe file and then run it to install MSRT.
  2. Hold down the Windows key, then hit R to bring up the Run dialog.
  3. Type "mrt.exe" in the box and hit Enter. MSRT will open.
  4. Click Next and then select the Quick Scan option.
  5. Click Next again to start the scan.

After 5 minutes or so, the scan will finish. Conficker should be gone for good, but you may want to check the Eye Chart again just in case.

Leave a Comment

Previous post:

Next post: