@SYSMAN_MK have tried the script but doesn't help.
Very annonying.
Printable View
Removing the scheduled tasks created by Conficker can be tricky as it's not easy to tell if the task is legitimate or not. Microsoft's KB does suggest removing all AT jobs...
Virus alert about the Win32/Conficker.B worm
You can call us: Sophos - Contact technical supportQuote:
Remove all AT-created scheduled tasks. To do this, type AT /Delete /Yes at a command prompt.
Regards,
Sophos Technical Support
Which script have you used? There is one for version 7 that makes us of the Windows Installer CleanUp Utility + SubInACL
@ SYSMAN_MK : Am using version 1.01
@ Sophos Support : am just deleting any task called AT, I have found machines with anything from 3 to 21.
Am also having trouble removing it, when I do a full scan as requested by Sophos to perform the action to delete it still doesn't let delete the conficker virus file.
Yep same here, tried to get it yesterday!!
COMPUTER VIRUS
A computer virus has been detected on various school networks.
The NOD32 anti-virus software will quarantine this virus but the alert screen keeps appearing and needs to be closed over and over again.
We have consulted with Eset who supply our anti-virus software and they have provided two patches which need to be applied to all servers and computers.
Please see attached file ( Virus Removal Tool.Zip ) and perform the following on all Servers / Workstations ASAP :-
· On ALL Servers Run the WindowsServer2003-KB958644-x86-ENU.exe file
· On ALL DEVICES now run the EConfickerRemover.exe File
· In the NOD32 Tray Icon browse to System Tools / Quarantine Area & Highlight and delete any quarantined files – ( you may need to go to Advanced mode in newer versions of NOD )
· REBOOT
If necessary run :
· On a Windows Vista PC’s run the Windows6.0-KB958644-x86.exe File
· On a Windows XP PC’s run the WindowsServer2003.WindowsXP-KB958644-x64-ENU.exe File
NOTE :- You Can create a startup batch file for the client workstations containing these exe’s
"\\UNC-PATH-TO-EXE-FOLDER\WindowsXP-KB958644-x86-ENU.exe" /passive /forcerestart
"\\UNC-PATH-TO-EXE-FOLDER\EConfickerRemover.exe" -autoclean
If the virus is detected please run the Remove FixDownadup symantic tool which will perform an intensive scan however it will and take several hours to complete.
if any one wants the virus removal tool pm me... I cant seem to upload it here :(
ok here is a link to the remove tool
http://www.bishopsgarth.stockton.sch...=article&id=99
Cheers for that PEO
gonna give it a test later.
Worked for me just now. We've not had any reported problems with downloading the file.
If you want another link (that doesn't require registration) then try (754kB):
http://www.sophos.com/support/cleaners/scct_10_sfx.exe
Regards,
Sophos Technical Support
We had a lot of fun with this very interesting worm.
I blogged about our experiences here http://spchappell.blogspot.com.
Simon