Conficker P2P Service Detection

critical Nessus Plugin ID 36217

Synopsis

The remote host seems to be infected by a variant of the Conficker worm.

Description

The remote host seems to be infected by the Conficker worm. This worm has several capabilities that allow an attacker to execute arbitrary code on the remote operating system.

The remote host might also be attempting to propagate the worm to third-party hosts.

Solution

Update the host's antivirus and perform a full scan of the remote operating system.

See Also

http://net.cs.uni-bonn.de/wg/cs/applications/containing-conficker/

http://www.skullsecurity.org/blog/?p=230

https://support.microsoft.com/en-us/help/962007/virus-alert-about-the-win32-conficker-worm

http://www.nessus.org/u?1f3900d3

Plugin Details

Severity: Critical

ID: 36217

File Name: conficker_p2p_detect.nbin

Version: 1.88

Type: remote

Family: Backdoors

Published: 4/22/2009

Updated: 3/19/2024

Configuration: Enable thorough checks

Asset Inventory: true

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C