• Conficker Eye Chart

    5
    scissors
    April 4th, 2009EthelInternet, Technology
    Listen with webreader

    Wondering if you’re infected with the much-hyped Conficker worm?

    Conficker interferes with the Domain Name System (DNS) that resolves a domain like “www.ethelthefrog.com” into an IP address.  In particular, if Conficker is present, your browser won’t be able to resolve domains containing almost a hundred specific text strings. These include the names of just about every major security vendor, as well as strings like “anti-”, “malware”, “removal”, “rootkit”, “spyware”, “threat”, and “virus”.  (It also blocks the Windows Update web site. So a system infected with Conficker won’t actually be able to download removal tools, update security software, or run Windows Update).

    Joe Stewart

    Joe Stewart

    Armed with this knowledge, a smart fellow named Joe Stewart, who is the Director of Malware Research with SecureWorks, and who maintains a blog called ACATTAG, devised the Conficker Eye Chart.  This clever web page includes links to images from several security companies. If they all show up, you’re clean.  If not, you can even determine which Conficker variant is present based on which ones don’t appear.

    Due to it’s brilliant simplicity, I have been able to reproduce the Eye Chart below.  (I hope you don’t mind, Joe).

    Conficker Eye Chart

    How to interpret:

    chart

    Explanation:

    Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.

    If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (websites of alternative operating systems) then your Windows PC may be infected by Conficker (or some other malicious software).

    If you can see all six images in both rows of the top table, you are either not infected by Conficker, or you may be using a proxy server, in which case you will not be able to use this test to make an accurate determination, since Conficker will be unable to block you from viewing the AV/security sites.

    F-Secure and the F-Secure Logo are trademarks of F-Secure Corporation.

    SecureWorks and the SecureWorks Logo are registered trademarks of SecureWorks Inc.

    Trend Micro and the T-Ball logo are trademarks or registered trademarks of Trend Micro Inc.

    The Conficker Eye Chart is a concept by Joe Stewart.

    Reblog this post [with Zemanta]
    Did you know this: Budweiser is the best-selling beer in the world. . . .Now you do!

    Related posts:

    1. Are You Ready for April 1?
    2. Top Ten Ways to Know If You Have the Conficker Virus
    3. Is Microsoft Crazy?
    4. Eye-Catching Ads!
    5. Follow My Blog On Facebook
    Tags: ,

5 Trackbacks / Pingbacks

  • [...] Conficker Eye Chart 04.04.2009 | Posted in Computer World Wondering if you’re infected with the much-hyped Conficker worm? Conficker interferes with the Domain Name System (DNS) that resolves a domain like “www.ethelthefrog.com” into an IP address.  In particular, if Conficker is present, your browser won’t be able to resolve domains containing almost a hundred specific text strings. These include the names of just about every major security vendor, as well as strings like “anti-”, “malware”, “removal”, “rootkit”, “spyware”, “threat”, and “virus”.  ( More here: Conficker Eye Chart [...]

  • [...] Ethel The Frog added an interesting post on Conficker Eye ChartHere’s a small excerptWondering if you’re infected with the much-hyped Conficker worm? Conficker interferes with the Domain Name System (DNS) that resolves a domain like “www.ethelthefrog.com” into an IP address.  In particular, if Conficker is present, your browser won’t be able to resolve domains containing almost a hundred specific text strings. These include the names of just about every major security vendor, as well as strings like “anti-”, “malware”, “removal”, “rootkit”, “spyware”, “threat”, and “virus”.  ( [...]

  • [...] Conficker Eye Chart (ethelthefrog.com) [...]

  • [...] Conficker Eye Chart (ethelthefrog.com) [...]

Leave a reply