Conficker Worm Detection (uncredentialed check)

Critical Nessus Plugin ID 36036

Synopsis

The remote host seems to be infected by a variant of the Conficker worm.

Description

The remote host seems to be infected by the Conficker worm. This worm has several capabilities which allow an attacker to execute arbitrary code on the remote operating system. The remote host might also be attempting to propagate the worm to third party hosts.

Solution

Update your Antivirus and perform a full scan of the remote operating system.

See Also

http://net.cs.uni-bonn.de/wg/cs/applications/containing-conficker/

http://support.microsoft.com/kb/962007

http://www.nessus.org/u?1f3900d3

Plugin Details

Severity: Critical

ID: 36036

File Name: conficker_detect.nasl

Version: Revision: 3.12

Type: local

Family: Backdoors

Published: 2009/03/29

Modified: 2017/05/16

Dependencies: 10394, 10150, 11011

Risk Information

Risk Factor: Critical

CVSSv2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C