Heard from the grapevine that the Conficker (Worm_DownAD) worm is still in the wild (
http://msforums.ph/forums/t/50980.aspx). This worm generates randomly named services which makes it a tad difficult to detect and contain. Here's a short script I created to detect for possible rogue services triggered by this worm. The usual disclaimer applies:

The code should be self-explanatory. =)
No comments:
Post a Comment