Computing and Networking Services American University of Beirut
CNS heading
* Author:
Rabih Itani
Computing & Networking Services,
American University of Beirut




Contact:
CNS.Helpdesk
West Wing,
Van Dyck Hall,
Ext. 2260



CNS HelpDesk Pages
Students
Faculty
Staff

CNS Self Service Support:
login to Heat

 

Conficker Worm: Special instructions

What to do to protect your computer from the worm?
How to detect the presence of the worm at your computer?
How to remove the worm?
How to disable AutoRun?


What to do to protect your computer from the worm?
  1. Make sure that you computer is patched with latest Microsoft OS updates. The patch required to protect your computer from Conficker worm has been identified by MS: MS08-067. (See http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx)

    Private Computer owners only: Windows XP computers can be patched from within campus network . However, Windows Vista computers currently cannot and will have to be patched form outside campus (a solution is currently in the works).
  2. Make sure that you have anti-virus software installed and updated with latest signature definition files. Read the help for Private computer owners.

  3. CNS recommends that you disable the “AutoRun” capability that would help protect your computer form this worm and other similar future security threats. Here is how to disable "AutoRun".

  4. Use a solid and strong password. Using a password that's easy to guess, located in a dictionary of any language, or less than eight characters is not recommended. See CNS password recommendations.

back to top   

How to detect the presence of the worm at your computer?

Users can apply a simple test for the presence of a Conficker/Downadup infection on their computers. The presence of a Conficker/Downadup infection may be detected if a user is unable to surf to their security solution website or if they are unable to connect to the websites, by downloading detection/removal tools available free from those sites (or similar):

  • http://www.symantec.com/norton/theme.jsp?themeid=conficker_worm&inid=us_ghp_link_conficker_worm
  •  http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx
  •  http://www.mcafee.com
If a user is unable to reach any of these websites, it may indicate a Conficker/Downadup infection. The most recent variant of Conficker/Downadup interferes with queries for these sites, preventing a user from visiting them. If a Conficker/Downadup infection is suspected, the system or computer should be removed from the network or unplugged from the Internet - in the case for home users.

back to top   

How to remove the worm?

There are many tools to use over the Internet, CNS recommends below:

There are more tools online. However, only those from known and trusted vendors should be used. Criminals are taking advantage of the Conficker fear and offering malicious tools that offer removal, but in reality do nothing of the sort.

back to top   

How to disable AutoRun?

Windows XP, 2000, 2003

  1. Click START then RUN
  2. Type GPEDIT.MSC into the OPEN box and click OK
  3. Under Computer Configuration, click Administrative Templates, and then System
  4. Right click on Turn off Autoplay (Disable Autoplay on Win 2000) and select Properties
  5. Click Enabled, and then in the dropdown select All Drives. Click OK and close the GP Editor
  6. Reboot
Windows Vista:
  1. Click START, type GPEDIT.MSC in the search box and hit enter
  2. Note: You might need to enter your administrator password at this point
  3. Under Computer Configuration, expand both Administrative Templates and Windows Components, and then click Autoplay Policies
  4. Double click Turn off Autoplay
  5. Reboot
If you are using Vista Home or Home Premium, you will not have access to GPEDIT. This is because only domain-based versions of Vista have the ability to use group policy tools.

IMPORTANT: Windows Vista-based and Windows Server 2008-based systems must have update 950582 (Security bulletin MS08-038) installed to take advantage of the registry key settings that disable Autorun

For operating systems that do not include Gpedit.msc, follow these steps:
  1. Click Start, click Run (search box for Vista), type regedit in the Open box, and then click OK.
  2. Locate and then click the following entry in the registry: HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorerNoDriveTypeAutorun
  3. Right-click NoDriveTypeAutoRun, and then click Modify.
  4. In the Value data box, type 0xFF to disable all types of drives.
  5. If you want to be selective the following codes will apply according to Microsoft.
    0x1 - Disables AutoPlay on drives of unknown type
    0x4 - Disables AutoPlay on removable drives
    0x8 - Disables AutoPlay on fixed drives
    0x10 - Disables AutoPlay on network drives
    0x20 - Disables AutoPlay on CD-ROM drives
    0x40 - Disables AutoPlay on RAM disks
    0x80 - Disables AutoPlay on drives of unknown type
    0xFF - Disables AutoPlay on all kinds of drives
  6. Click OK, and then exit Registry Editor.
  7. Restart the computer.

back to top   

Wednesday, 27-May-2009 11:31:50 EEST
Computing and Networking Services
American University of Beirut
Ext. 2260