Mar 26 2009No Joke: Conficker C Virus Coming April 1st

That's right folks, a beefed up version of the Conficker virus, Conficker C is scheduled to wreak havoc on April 1st. Your grandparents may think it's just a joke, but it's no joke -- this is real life, son!
What's known so far is that on April 1, all infected computers will come under the control of a master machine located somewhere across the web, at which point anything's possible. Will the zombie machines become denial of service attack pawns, steal personal information, wipe hard drives, or simply manifest more traditional malware pop-ups and extortion-like come-ons designed to sell you phony security software? No one knows.
Conficker is clever in the way it hides its tracks because it uses an enormous number of URLs to communicate with HQ. The first version of Conficker used just 250 addresses each day -- which security researchers and ICANN simply bought and/or disabled -- but Conficker C will up the ante to 50,000 addresses a day when it goes active, a number which simply can't be tracked and disabled by hand.
Well, just like I did in preparation for the Y2K bug, I'm building a rocketship and blasting off into outerspace before the damage is done. Now you may be asking yourself, "self, what the hell is he still doing here if he really blasted off into outerspace?" And the answer, my friends, is none of your business (read: I'm collecting earth women for the trip). Ladies? Freeze-dried ice cream!
Beware Conficker worm come April 1 [yahoonews]
Thanks to Ashely and Xeta, who aren't worried about the virus because they don't use computers. It's true, they sent their tips snail mail and only read Geekologie telepathically.

Reader Comments
1. crimson skies - March 26, 2009 9:11 AM
1st!
2. E of R - March 26, 2009 9:11 AM
God it itches!!!!
3. Atreids - March 26, 2009 9:11 AM
At last Geekologie's hold on me will be broken!
4. crimson skies - March 26, 2009 9:12 AM
But a bad situation :(
5. naas - March 26, 2009 9:20 AM
I just bought a bunch of cans of bacon to survive the post apocalyptic aftermath when scantily dressed cavewomen start attacking the cities on April 3rd
6. Gordon "Fücking" Shumway - March 26, 2009 9:21 AM
OH NO!
7. naas - March 26, 2009 9:23 AM
@6 http://static.stickam.com/media/video/converted/1700/7240/6/8fdc6ce7-76fa-11da-b964-0f09f07f632c.wmv.flv.jpg
8. catch22 - March 26, 2009 9:23 AM
so basically backup anything you wanna keep. and hope for the best... trust in your anti virus/maleware/spam, etc software. im sure changing the clock/calendar on your computer wont help. worse comses to worse if your parinoid... turn your computer off and dont connect to the net till you see what it does to everyone else.
9. naas - March 26, 2009 9:25 AM
@8 ...or just pull the plug on your internet connection for awhile
10. Alegeobla - March 26, 2009 9:26 AM
so since it says its coming as of April 1st, im calling april fools joke on this one
11. Gordon "Fücking" Shumway - March 26, 2009 9:28 AM
@naas
Blocked at work. Please tell me it's the mustashed gay dude from Family Guy.
12. naas - March 26, 2009 9:32 AM
It's the kool-aid guy jumping through the wall OHYEAH...
Wtf is geekologie becoming blocked more often with the regs? I thought the language spam filters would keep this website worksafe appropriate
13. Gordon "Fücking" Shumway - March 26, 2009 9:35 AM
Nope. Just the link you posted. If it's streaming media, I can't watch it until I get home. Kinda sucks. Kinda keeps me doing my job. Just a little.
14. Megan the Love Fairy - March 26, 2009 9:37 AM
Count me in Geekologie Writer! I wanna have sex in Mars with you...........
15. poop on my small shaft - March 26, 2009 9:38 AM
TINA TURNER
Well the men come in these places
And the men are all the same
You dont look at their faces
And you dont ask their names
You dont think of them as human
You dont think of them at all
You keep your mind on the money
Keeping your eyes on the wall
Chorus
I'm YOUR PRIVATE DANCER
A DANCER FOR MONEY
ILL DO WHAT YOU WANT ME TO DO
I'm YOUR PRIVATE DANCER
A DANCER FOR MONEY
ANY OLD MUSIC WILL DO
I wanna make a million dollars
I wanna live out by the sea
Have a husband and some children
Yeah I guess I want a family
All the men come in these places
And the men are all the same
You dont look at their faces
And you dont ask their names
Repeat chorus twice
Deutschmarks or dollars
American express will nicely thank you
Let me loosen up your collar
Tell me do you wanna see me do the shimmy again
Repeat chorus
16. naas - March 26, 2009 9:44 AM
Ahh good. It was just a pic - but I see the .wmv in the file which could trigger those media filters over there into thinking it was streamable.
/nass' image retort, fail
17. V - March 26, 2009 9:50 AM
I doubt anything is even going to happen. It's probably just someone pulling a prank to try to put everyone in a panic.
18. Turd Ferguson - March 26, 2009 9:53 AM
Step 1) Back up everything important now ...especially your good pron. Mmmmm...pron.
Step 2) Turn off computer on April 1st
Problem solved.
If your smart(or paranoid like me), you'll reformat your drive at least once a year anyway. Now is a good time.
Your friend,
Turd
19. 24bit-whore - March 26, 2009 10:07 AM
@18 you don't need to store pron on your computer anymore, it's free online all over the place.
20. Nero - March 26, 2009 10:10 AM
If it's that serious than the quarter million bounty is an April Fool's joke!
21. Darth - March 26, 2009 10:13 AM
Quarter million Darth Vader dollars=no joke!=exchange starts now!
22. Graf Zeppelin - March 26, 2009 10:17 AM
@2 Ha. That's what happens when you try to copulate with the USB port without proper protection. In fact, how do we know that wasn't how you transmitted the Conficker to the net in the first place?!
@15 We don't need anotheer hero
@19 But.. if the internet dies so will the pron!
23. Watch - March 26, 2009 10:24 AM
Maybe this virus will erase daisy and all the other dumbass spammers on this site
24. I Hate Fakers - March 26, 2009 10:27 AM
what is the fackin shet about Tina Turner anyways?
25. dennis - March 26, 2009 10:32 AM
lets hope so
26. MacMaster - March 26, 2009 10:34 AM
Get a life, get a Mac!!!
I work at Symantec and they are taking this very seriously...
27. $.02 and a pocket full of FAH-Q - March 26, 2009 10:41 AM
GW - Make it Dippin Dots or no way I'm going.
28. VIc - March 26, 2009 10:46 AM
This burns my insides.
29. ClaMs - March 26, 2009 12:49 PM
WOO HOOO!!!
This is going to be such a fun ride.
Tip: Steve Jobs is behind this, honest.
30. Somebody - March 26, 2009 1:59 PM
On April 1st, my TYPEWRITER is gonna PWN all you B**ches!! PEW PEW PEW
31. Bryce - March 26, 2009 2:01 PM
Let's just hope that this is a pre-emptive APRIL FOOLS joke. D:
32. Native - March 26, 2009 2:36 PM
Dear Widoze users,
It hides itself from your spyware, adware malware, whatever programs by disabling the software update. So, check your last update, and then update it now. If you can't, congratulations your CPU is a zombie, hey those road signs were right!
I have a mac.
33. RideNsmile - March 26, 2009 2:46 PM
Wait @26
You work at a anti virus place and u own a Mac? haha thats like saying i Like chevy when i work for Jaguar....
So what your saying is you must not have to much faith in the company you work for? but yet your boss lets you come to the website and trash your name...funny.
And thanks for the 1 minute of b*tching and the 2 minutes of you trying to figure out what i said.
34. RideNsmile - March 26, 2009 2:59 PM
Ok Everyone heres the steps
Click Run
type CMD (it will take you into a black screen)
Then Type Format C:
It will say this drive is in use. You cannot format a drive that is in use However would you like to schedule this task When the Computer restarts? Y/N
Type Y
Your scheduled task will resume at restart
Then Type Shutdown.exe -i
Your computer will restart and grab your windows CD and get ready to call microSoft.
haha
35. catch22 - March 26, 2009 5:00 PM
@34 ... its pronounced "micro$oft"
36. Alex - March 26, 2009 5:59 PM
For all you desesperate people, you can know if you have the virus with this http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDwndp.exe
Yes its an .exe... and I tryed it, not a virus.
It takes about 15-25 minutes to do the check up
37. vferg - March 26, 2009 7:48 PM
Our company just got hit with type B last Sunday and it quickly spread through almost the entire company within a day... Still cant get rid of it after 4 days now and its messing up a lot of stuff. I really hope that this article is a joke cause if not im prob going to quit if it hits us! Trust me its no fun and even after patching and running the tools and turning off autoplay and following every little tip it tells you to it still comes back.
38. HunnyBear - March 26, 2009 8:28 PM
i think im gonna puke...
39. rofl - March 26, 2009 8:46 PM
hmmm april 1st ayye?
40. Gerinych - March 27, 2009 12:20 AM
This can be a very elaborate April Fool's joke. All the infected computers will flash "HAHA GOTCHA" the whole day.
41. HunnyBear - March 27, 2009 1:34 AM
joke or not im not taking any chances!
42. milk - March 27, 2009 5:06 AM
thank you GW! If it were not for that mention of ice cream, I would have forgotten about my Green Tea-flavored tub in my back pack until morrow. When it would have been all over the carpet. And my knitting.
43. conka - March 27, 2009 7:40 AM
hmmm virus will reak havok... well ill just unplug my ethernet and do some l337 diggin
44. conka - March 27, 2009 9:20 AM
^
|| screw my old post, april first is april fools, so im assuming its just a hoax
45. KILLA K - March 27, 2009 8:41 PM
Yeah I was skeptical about this two, until I did some searching on my work's computer. Ran that file and it came back positive on 5/5 machines, haven't been able to remove it. I've tried all tools and even have completely rewritten every sector of the harddrve and reinstalled windows. Still there, I don't know how but it is. I scanned the xp pro install cd and it was infected. Thats right, the virus was installed by the cd. And don't think your safe if you have a mac, I've scanned my linux box at home, I have it. Its a process called confc that I cannot kill, and runs 100% cpu every 5 min for about 3 seconds. I've searched it and its an unknown process. Mac is unix so its very likely there is a mac version too. This is much bigger than anyone can imagination. When this thing hits... its going to be big
46. sO oH RiginaL - March 28, 2009 10:52 PM
I know who created the worm (not in person) and I'm going to turn him in.
47. Vicky - March 29, 2009 3:41 PM
@46 WHO DID IT?!
Please tell me because when I find out I'm gonna find that person and kick them in the balls so hard his whole family won't be able to have kids
48. Emperor - March 30, 2009 8:10 AM
on april 1st i will test my antivirus If its dosen't on AVG i will test Spyware Doctor 6 and Avira
49. Sugga - March 30, 2009 6:06 PM
Hey everyone, I am not really good with computers.... I want to know if I dont go on the internet April1 and go the following day then I cant get hit with the virus???
50. O_O - March 30, 2009 6:17 PM
actually, to the seventeenth person, it's not fake. Schools are even prohibiting kids from using the computers, and no one's allowed to even really, well, go near them, in case. I think one of the best ways is to keep your computer off after using a virus ...uh....cleaner. something like that.
51. lol bich please - March 30, 2009 6:24 PM
Oh I see April First huh?
Well I heard the world will end on April First anyways so what's the point.
Oh also I heard that April First was April Fools day but who does those jokes these days anyways?
52. omg - March 30, 2009 9:39 PM
So, after this virus hits on April 1st, when will it be safe to turn on your computer and connect to the Internet?
53. Babon - March 31, 2009 5:14 AM
don't warry just update ur anti virus it will safe ur pc. Visit Microsoft.com we will found every answer of ur question.....
54. Vincent Alvarez - March 31, 2009 5:44 AM
omg. lol. Lets hope for the best. People at work or school tomorow (april 1st) won't be risking their own computers which is good xD lol. Just hope that your computer at work or school doesnt crash or anything.
anyone scared?. lol i got about 3 hours or so before april first, since i live in australia. lol good luck too all . Hope my computers at school dnt malfunction or anything.
report back if anything happens. i know i will! xD
55. romeo - March 31, 2009 7:51 AM
well what i read on cnn it will be activated on april 1, so the way i see it and the way i think it as a computer science student. a program follows the CPU clock, or whatever they call it. and in the code it is clear that it will activate on april 1. so my theory is that if you delay your date on your pc like a day before april 1 it will not be activated. or if the program follows the servers's time well one way to do is to cut of the internet connection. and yeah also change the date on the pc. well since i have that idea i might use it, and we might be the one of the that will have the date april 1 which will be in like 5 hours from now.....well good luck to all!!! if you tried it guys just email me owi_bong@yahoo.com
56. KUPAL - March 31, 2009 8:32 AM
MGA KUPAL KAYO!!!! MiCHAEL TO!!! PAK YU KAYO LAHAT!!! LAHAT KAYO GAGO!!!
57. KUPAL - March 31, 2009 8:36 AM
MGA FUSHIANG HiNA!!!! MGA HAYUP!!! KALOKOHAN YAN!!! CNO MTPANG JAN!!! MGA FUSHiANG iNA MGA EHGLESERO KAYO!!,`=-
58. KUPAL - March 31, 2009 8:48 AM
PKER FACE
59. lolwtflol! - March 31, 2009 10:45 AM
If you actually believe this, turn your computer off or just don't open or download stupid shit. For you gamers out there, it's better to play over LAN or by yourself. DotA fans out there, Garena is the way to go.
JUST DON'T DOWNLOAD RANDOM MAPS or RANDOM SHIT PERIOD OR PORN.
But only applies if you actually believe this.
60. Ashanda - March 31, 2009 9:32 PM
So if you have a Mac, then this Conficker C virus won't affect you since it only targets Windows users???
AKA - Are all Mac owners safe?
61. wtfbbq - March 31, 2009 11:10 PM
If it did launch on April 1st, it would start at different times...hense this stupid virus would be like extemely hard to make, since precisely 12:00am? it will activated...so hmmm the creator could time it just right everywhere around the world?
62. Bill - March 31, 2009 11:51 PM
You guys are funny. Turning your computers off durning that time will solve nothing. For this virus to work your computer must already contain a virus, witch in turn lets the Conficker in (or if your haven't installed the updates from microsoft). So when you think its safe to turn your computer on lol the Conficker will "play" in your computer. Now the funny thing is Norton has a fix for this.... so why is everyone worried?? The virus i had two weeks ago was a much bigger headache. It was the win32/Virut reader_l.exe. After three days of reading the only fix on the net was a format. Bottom line is if you have the MS08-067 fix installed then you have nothing to worry about, oh yea and if your system is clean :) cheers
63. madammecahs - April 1, 2009 12:25 AM
i dont understand how do people know this virus is coming and nothing comes out of it and who da hell made it and like told people to plan like wth?!
64. bill - April 1, 2009 12:32 AM
well its April first and my computer is fine. My buddy on the other hand... well he got it lol After he ran the exe i sent him everything is all good.... so please dont worry about it... anyways there are worst virus out there that dont make the news :p cheerrs
65. PhuxPro - April 1, 2009 12:41 AM
@64 Bill, why would they already bomb everything when everybody's looking and examining? That would be too obvious. All they did was put the clip in the gun. Now, they're waiting for the time when we don't expect it, THEN they would shoot. Wouldn't you duck if you saw the gun? Now what if the person didn't show the gun yet and you don't know when?
66. Bill - April 1, 2009 12:48 AM
Good point but it seems that the gun has been fired already... as i said my buddy just got the virus
67. Bill - April 1, 2009 12:57 AM
My buddy and I are talking about the msblast virus... lol anyone remember that one??? Now that was a PAIN
68. Bill - April 1, 2009 1:28 AM
@65 I was thinking about what you said. I think the programer that wrote this mess is depending on people like my dad who haven't the slightest clue about computers. Even if there are just one million people like my dad (I'm sure there is more) then its mission success for the writter. Now the fun starts when those computers become drome computers and start infecting other computers or start attacking servers. Bottom line is there are so many people out there that will get blind-sided by this and will not have the know how to fix it.
69. Vincent Alvarez - April 1, 2009 3:04 AM
lol nothing happened to me YAY!! xD
70. janet barrera - April 1, 2009 5:08 AM
I think the culprit is a professional attention getter...he's getting off on everyone freaking out.
71. Vincent Alvarez - April 1, 2009 6:45 AM
Soo this is just some stupid hoax ? But the virus exist though lol.
72. Bystander - April 1, 2009 10:30 AM
If you did any research on this at all you would know that if your OS and Antivirus software have been kept up to date (even mildly up to date) the hole this worm exploits was plugged a long time ago. Only those who don't apply updates are at risk. Also, the "10 million infected computers" was only a number someone extrapolated from a much smaller test group, and was the largest number possible with the test's percentage of error. In other words, this is the media making it look as bad as they can so more people watch and they can sell more advertising. Sure something might happen, but it won't be anywhere near as bad as chicken little on the news is telling you. Think Y2K.
73. Freshmen - April 1, 2009 11:09 AM
@50
Im in school right now wrighting this soo your wrong and if its puting the schools cpus at risk haha.....
74. Bill - April 1, 2009 1:51 PM
@72 Finally someone with a brian.
75. Ulala369 - April 1, 2009 4:28 PM
Nothing Happened To My Copm
I bet it was all a joke
LOLS
76. Lol - April 2, 2009 12:27 AM
Ok guys,
I knew it wasn't as big as everyone thought.. People going on about it at school so I left the computer on to prove those idiots wrong -.-
77. Vincent Alvarez - April 2, 2009 12:44 AM
lol Hoax.
78. Computer Support - October 1, 2009 7:51 AM
the virus exist though lol.
79. Computer Help Desk - October 21, 2009 7:18 AM
be aware that manual removal of Conficker C is a cumbersome process and does not always ensure complete deletion of the malware, due to the fact that some files might be hidden or may get reanimated automatically afterwards
80. Computer repair toronto - November 5, 2009 10:50 PM
Why you still talking about this Virus? Most of the anti viruses can easily remove it.