![]() |
|
|||||||
|
|
Thread Tools | Search this Thread |
|
#1
|
||||
|
||||
|
This is an advanced Capsa capture filter to capture only the traffic of the notorious and aged Mydoom virus. By using this filter, all packets matching the filter's conditions will be displayed and you know there is Mydoom virus movements in your network.
Now download the filter and follow the instructions below to load and apply the filter. Download Mydoom worm virus filter: mydoom-filter.zip How to use this filter?
What is Mydoom worm? Defination from Wikipedia: Mydoom, also known as W32.MyDoom@mm, Novarg, Mimail.R and Shimgapi, is a computer worm affecting Microsoft Windows. It was first sighted on 26 January 2004. It became the fastest-spreading e-mail worm ever (as of January 2004), exceeding previous records set by the Sobig worm.
__________________
Colasoft LLC Official Website: http://www.colasoft.com Contact Support: http://www.colasoft.com/support/contact/index.php Follow us on twitter: colasoft |
|
#2
|
||||
|
||||
|
Quote:
__________________
I've discovered that people on IRC don't get offended or riled up by racism, nor politically incorrect jokes, nor feminism, nazism, nor goatse, or even tubgirl, not even jokes about 9/11 get a rise out of anybody but as soon as I tell somebody that macs are better than PCs, things get ugly. |
|
#3
|
||||
|
||||
|
Hi Spooony,
On the web, we know Conficker worm is rampant and it has the following features: Domain controllers respond slowly to client requests. System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager. Port 445/TCP scanning (A/B) Multicast UPnP requests High-port TCP and UDP P2P Activity Abnormal DNS lookup activity --ConfickerWorkingGroup.org The simplest way to find conficker is to start from DNS queries. Because the DNS queries are random, it's hard to offer a universal filter. We can find clues from the Log tab in Capsa, when you see lots of DNS error items, you should pay attention to them always. They may not be conficker, but definitely something is wrong. This picture shows the DNS activities of a typical Conficker worm. You may notice that the host sent DNS packets quickly and lots of error returned.
__________________
Colasoft LLC Official Website: http://www.colasoft.com Contact Support: http://www.colasoft.com/support/contact/index.php Follow us on twitter: colasoft |
|
#4
|
||||
|
||||
|
Resource: Protecting Against the Rampant Conficker Worm:
http://www.pcworld.com/article/15787...cker_worm.html
__________________
Colasoft LLC Official Website: http://www.colasoft.com Contact Support: http://www.colasoft.com/support/contact/index.php Follow us on twitter: colasoft |
|
#5
|
||||
|
||||
|
Quote:
Thanks man for the wonderfull reply. Even my wife understood it (and she only knows how to go on facebook and start Itunes). Scary thing about conflicker is it can sit and wait for years awaiting new instructions and a lot of users run their own private network these days. And unfortunately or fortunately depends what way you look at it systems are so good and quick these days so users who finds malware on a pc go by approach format that will remove a worm from my pc which is connected in a network. Then some time later they ask how they got infected again.
__________________
I've discovered that people on IRC don't get offended or riled up by racism, nor politically incorrect jokes, nor feminism, nazism, nor goatse, or even tubgirl, not even jokes about 9/11 get a rise out of anybody but as soon as I tell somebody that macs are better than PCs, things get ugly. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|