How the conficker virus works


The conficker virus spreads via computers which are un patched and have weak passwords. If your computer is infected with this worm, you may not experience any symptoms, or you may experience any of the following symptoms: Conficker virus has several mechanisms which are built in for pushing or pulling payloads over the network. The payloads are used by the Virus to update its self and install additional packages such as malware.
This worm exploits the MS08-067 Microsoft Windows Server Service vulnerability in order to propagate. Machines should be patched and rebooted to protect against this worm re-infecting the system after cleaning. Upon detection of this worm the system should be rebooted to clean memory correctly. May require more that one reboot. Scheduled tasks have been seen to be created on the system to re-activate the worm. Autorun.inf files have been seen to be used to re-activate the worm.