Thanks for the canned answer. Please read my question now.
Main Topics
Browse All TopicsOr is Windows Update getting slammed by downloaders scrambling to get the patch? Is conficker causing users to slam the Windows Update site?
I can't get these links to show anything:
http://www.microsoft.com/t
http://update.microsoft.co
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Both links work just fine here , could be a temporary down time as you say because of the 1st of April alert
can you get to the Microsoft Malicious software removal tool ?
http://www.microsoft.com/
also in order for windows update to function properly the BITS service which is affected by Conficker infection needs to be repaired
start>run>services.m
look for the service named "Background Intelligent Transfer Service", make sure it is running , running under Local system Account & that the path to executable is set to "C:\WINDOWS\system32\svcho
also you may want to confirm that there is no DNS / Hosts file hijack , please take a look at HOSTS file on the impacted machine to confirm it does not contain any rogue entries related to windows update
start>run>notepad
notep
the last line there should be 127.0.0.1 localhost
hope this helps.
If the problem persists, please psot a hijack this log, this may assist in revealing any remaining infectiosn that could be denying you access to windows update website
Yes there is a variant of the worm that blocks AV programs and Windows Update website but please see the following below for direct and complete info regarding the 4 actual types of the worm and a descritption of their effects.
Centralized Information About The Conficker Worm
http://blogs.technet.com/m
MSRT Released Today Addressing Conficker and Banload
http://blogs.technet.com/m
More MS08-067 Exploits
http://blogs.technet.com/m
Just in time for New Year's....
http://blogs.technet.com/m
Worm:Win32/Conficker.D
http://www.microsoft.com/s
Worm:Win32/Conficker.C
http://www.microsoft.com/s
Michael, thanks for the feedback.
More details:
Site actually tries to load and takes aproximately 1-2 minutes to load. Symantec and Spybot found nothing. I actually went to Symantec and Spybot's website and downloaded "trial" packages just to test the ability to connect. The problem is only with MS website.
Run this scan tool"Trend Micro HijackThis 2.0.2" and Copy/paste the list here.
Trend Micro HijackThis 2.0.2 Download:
http://www.softpedia.com/p
Trend Micro HijackThis 2.0.2
Will scan the registry and will produce a detailed list of your system for me to analyze.
A logfile is not so easy to analyze. Even for an advanced computer user. With the help of this automatic analyzer you are able to get some additional support. Just paste your complete logfile into the textbox at the bottom of this page.
But
MrMintanet said:
"most would be happy for you not to solve their questions"
FREE COMPUTER REPAIR
http://onecare.live.com/si
And run the: "FULL SERVICE SCAN" it will cleanup & speedup your computer, if it won't run then:
You may have been infected with Worm:Win32/Conficker.B
To protect from Conficker apply an emergency patch that Microsoft issued in October - ahead of Conficker's arrival - for a recently discovered flaw in the Windows operating system that Conficker was designed to exploit.
The patch was originally intended to protect Microsoft's customers against a different piece of malicious code, a data-stealing worm called Gimmev.
Conficker could still activate itself, and it's not the most dangerous piece of malicious code out there
Ways to detect and clean a system that has the Win32/Conficker.B worm
http://support.microsoft.c
If on a network, I recommend disabling "Password Lockout" policy for the time being, till you are sure the infection has been contained and cleaned in your network.
(http://technet.microsoft.
Also see:
Bit Defender:
http://anti-virus-software
This is free:
http://www.pctools.com/fre
(Regards from Michael Best: I troubleshoot: both, English OS & Japanese OS)
Business Accounts
Answer for Membership
by: xmachinePosted on 2009-04-01 at 06:24:08ID: 24038807
Hi,
com/downlo ad/4/a/3/4 a36c1ea-75 55- 4a88-98 ac-b0909cc 83c18/Wind ows2000-KB 958644-x86 -ENU.EXE
com/downlo ad/e/e/3/e e322649-7f 38- 4553-a2 6b-a2ac40a 0b205/Wind owsServer2 003-KB9586 44-x86- ENU .exe
com/downlo ad/4/f/a/4 fabe08e-53 58- 418b-81 dd-d503873 0b324/Wind owsXP-KB95 8644-x86-E NU.exe
com/downlo ad/d/c/0/d c047ab9-53 f8- 481c-8c 46-528b7f4 93fc1/Wind ows6.0-KB9 58644-x86. msu
ntent/en/u s/global/r emoval_too l/ threat_w riteups/Fi xDwndp.exe
com/en-us/ sysinterna ls/ bb89755 3.aspx) to import a text file that contains the infected machines and run it using a privileged account like a Windows domain admin.
m/products /networksc anner/)
om/en-us/l ibrary/cc7 36605.aspx com/securi ty/passwor dsec.htm
nload/), and scan all machines using this plugin ID (34476) to check if they have MS08-067 patch installed or not. (BTW, you can use a different tool to check for the installed patch, but this just an example)
This is my working cure for Conficker infections.
1) To start working, first you need to download the required patches + fix tool:
Windows 2000: http://download.microsoft.
Windows 2003: http://download.microsoft.
Windows XP: http://download.microsoft.
Windows Vista SP0 + SP1: http://download.microsoft.
Symantec FixDownadupTool: http://www.symantec.com/co
2) Create a shared folder on some server to contain the downloaded files (Apply Read-only permission for all users).
3) And you can use Psexec (http://technet.microsoft.
4) In the batch file, you should replace the server name and shared folder name.
so, for example (run this as domain administrator):
c:\psexec @infected.txt -d -c Clean-Downadup.bat
infected.txt should contains one name/ip per line, like:
...
192.168.1.2
192.168.1.3
192.168.1.4
...
Use netscan to ping a range of IP's and save the results as a text file (http://www.softperfect.co
Another important points:
1) Review the current Passwords policy, you can configure a Windows GPO that will require a complex password, with a minimum number of characters.
http://technet.microsoft.c
http://labmice.techtarget.
2) Use Nessus (http://www.nessus.org/dow
A Symantec Certified Specialist @ your service
Select allOpen in new window