Publication of Conficker tools (Updated)
Par Sylvain SARMEJEANNE, vendredi 3 avril 2009 à 17:02 :: General :: #296 :: rss
In previous posts, methodologies and tools related to the detection and eradication of Conficker were discussed:
- generic VBS script to remove Conficker A/B/C
- using mutexes to build a digital vaccine against Conficker C
- TCP and UDP ports generation used by Conficker C's P2P mechanism
The proof of concepts that were developed are now available for download (password: lexsi). Be careful, technical users only 
Updated, 04/03/2009: The P2P ports generation tool has been updated to fix a bug causing a one day lag in the generation (one day per week, the generated ports are those of the day before), because of an incorrect structure initialization before using it in mktime.