Slashdot Mirror


Diagnose Conficker With Web-Based Eye Chart

thomsomc writes "Joe Stewart from the Conficker Working Group has created an eye chart that allows for online identification of Conficker B and C infections. Using basic knowledge of the blacklisting that Conficker employs to avoid attempting to infect IPs that belong to popular Anti-Virus and security firms (including Microsoft), the group whipped up this very simple test to see if you can load content from the various pages. If you can see all of the images, you're more than likely Conficker-free. According to Honeynet, 'This detection method should be more reliable than network scanning based tests. Happy scanning!'" Related: Tech Fragments notes in passing that nothing much seems to have come of conficker's dreaded April 1 deadline.

8 of 180 comments (clear)

  1. Jon Stewart? by ender1598 · · Score: 5, Funny

    Am I the only one that read it as Jon Stewart and then spent a few minutes trying to figure out the joke on the page?

    --
    There are 10 kinds of people in the world; those that understand binary and those that do not.
    1. Re:Jon Stewart? by RevRagnarok · · Score: 5, Funny

      Just another flaw in the system.

      Come and see the flaws inherent in the system! Help! Help! I'm being modded down!

      --
      I should put something clever here. Maybe someday.
  2. I see a dog. by memorycardfull · · Score: 5, Funny

    Dog with head split in half.

  3. Re:sweet by ShieldW0lf · · Score: 5, Funny

    a nice, easy, reliable way to detect a conficker infection.

    As long as it doesn't get slashdotted... that might cause a new panic :P

    --
    -1 Uncomfortable Truth
  4. Mirror by Anonymous Coward · · Score: 5, Funny

    Conficker Eye Chart

    Conficker Eye Chart




    How to interpret:

    If you see this above:It probably means this:

    = Normal/Not Infected by Conficker (or using proxy)
    = Possibly Infected by Conficker (C variant or greater)
    = Possibly Infected by Conficker A/B variant
    = Image loading turned off in browser?
    Any other combination= Poor Internet connection?

    Explanation:

    Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.

    If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (websites of alternative operating systems) then your Windows PC may be infected by Conficker (or some other malicious software).

    If you can see all six images in both rows of the top table, you are either not infected by Conficker, or you may be using a proxy server, in which case you will not be able to use this test to make an accurate determination, since Conficker will be unable to block you from viewing the AV/security sites.

    F-Secure and the F-Secure Logo are trademarks of F-Secure Corporation.

    SecureWorks and the SecureWorks Logo are registered trademarks of SecureWorks Inc.

    Trend Micro and the T-Ball logo are trademarks or registered trademarks of Trend Micro Inc.

  5. Re:Lynx support? by MBCook · · Score: 5, Funny

    Works here.

    You must be infected.

    --
    Comment forecast: Bits of genius surrounded by a sea of mediocrity.
  6. Re:sweet by Chabil+Ha' · · Score: 5, Funny

    The chart or the virus?

    --
    We're all hypocrites. We all have hidden parts, it's the contrast between them that make us more a hypocrite than others
  7. Another option for the eye chart by fava · · Score: 5, Funny

    And if you can see the top row and not the bottom one it means you work at Microsoft.