Mal/Conficker-B is a worm for the Windows platform.
Mal/Conficker-B can be removed with either Sophos Anti-Virus or the standalone
Conficker removal tool.
Mal/Conficker-B spreads via an HTTP download initiated by other variants of the Conficker family.
When running Mal/Conficker-B patches the computer against further exploitation via the MS08-067 vulnerability.
Mal/Conficker-B attempts to terminate anti-virus and security related programs and blocks access to related domains:
Mal/Conficker-B terminates processes associated with files containing the following substrings:
autoruns
avenger
confick
downad
filemon
gmer
hotfix
kb890
kb958
kido
klwk
mbsa.
mrt.
mrtstub
ms08-06
procexp
procmon
regmon
scct_
sysclean
tcpview
unlocker
wireshark
Mal/Conficker-B blocks access to domains containing the following substrings:
agnitum
ahnlab
anti-
antivir
arcabit
avast
avgate
avira
bothunter
castlecops
ccollomb
centralcommand
clamav
comodo
computerassociates
conficker
cpsecure
cyber-ta
defender
downad
drweb
dslreports
emsisoft
esafe
eset
etrust
ewido
f-prot
f-secure
fortinet
free-av
freeav
gdata
grisoft
hackerwatch
hacksoft
hauri
ikarus
jotti
k7computing
kaspersky
kido
malware
mcafee
microsoft
mirage
msftncsi
msmvps
mtc.sri
networkassociates
nod32
norman
norton
onecare
panda
pctools
prevx
ptsecurity
quickheal
removal
rising
rootkit
safety.live
securecomputing
secureworks
sophos
spamhaus
spyware
sunbelt
symantec
technet
threat
threatexpert
trendmicro
trojan
virscan
virus
wilderssecurity
windowsupdate
avg.
avp.
bit9.
ca.
cert.
gmer.
kav.
llnw.
llnwd.
msdn.
msft.
nai.
sans.
vet.