Jump to content

Recommended Posts

Posted

Yeah I've been sending it round teaching PCs the last few days - not sure but think it requires a reboot so want to try and get it done manually before people come back.

 

So far haven't found anything odd in the registry keys and all the services are still working on the PCs I've looked at so fingers crossed...

Posted
I've been checking the registry in HKLM\Software\Microsoft\Windows NT\Currentversion\svchost for odd-named entries from what I read in the Microsoft KB article - is that a reliable indicator of infection?

 

Things you can (perhaps) visually spot...

 

Extract from the "more information" tab on Mal/Conficker-A Malicious behavior (WORM_DOWNAD.AD, W32/Conficker.worm, Worm:Win32/Conficker.gen!A, Worm:W32/Downadup, Net-Worm.Win32.Kido) - Sophos security analysis

 

(1) \ (e.g. C:\windows\system32\zdtnx.g)

 

(2) The registry entries added by Mal/Confiker-A are under:

 

HKLM\SYSTEM\CurrentControlSet\Services\

 

(3) The random service name will also be added to the list of services referenced by:

 

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs

 

(4) When spreading to removable media Mal/Conficker-A attempts to create the following hidden files:

 

\autorun.inf

\RECYCLER\S-x-x-x-xxx-xxx-xxx-x\.dll (where x represents a random digit)

 

Please read the above page in full for more information and also Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker

 

Regards,

Sophos Technical Support

Posted

After reading this thread my number one priority at the moment is to talk my crazy network manager out of getting rid of WSUS altogether and basically 'winging' it.

 

Currently:

 

Mcafee not updated since Jan 9th

WSUS not active since way before christmas.

 

Im terrified.

Posted

I had the Conficker virus. No need to shut down your network. Set your anti virus (I use sophos) to on write access scanning, restart computer then do full scan. This should now pick up the virus and allow you to remove it. Push out the patch via GP if you don't have WSUS. If you use ISA, search for any host accessing the sites Conficker tries to access. This will give you a list of infected machines. Clean these up using the method above and then clear the virus alerts. Wait to see if you get any more alerts (may take a few hours). If you do, check ISA logs again. You may get machines warning you they have been infected then the file has been deleted. Conficker can spread using the ADMIN$ share, so this warning is basically telling you a machine on your domain has tried to infect it, not that it has the virus.

 

Hope this helps. Took me 3 days to clear, but not that much work. It certainly helps you find the workstations that aren't running anti-virus properly. As a side note, if you have sophos, upgrade to the enterprise console 3.1. Its much better at automatically installing sophos according to linked active directory OUs.

 

If you need any advice give us a shout

  • 2 weeks later...
Posted (edited)
ARRRRHHH

 

Sophos has been picking this up all morning, can't tell if Sophos has been cleaning it up or not?

 

Go to a machine. Unplug the network cable. Run a FULL scan (scan all files checked). When the scan has finished cleanup items in quarantine. Run another FULL scan. If it comes back clean we're cleaning it up.

 

If you put the computer back on the network and it gets "infected" then there is an unpatched or unprotected machine on the network - or someone plugged in a USB pen into the computer.

 

Regards,

Sophos

Edited by Sophos-Support-5
Posted
Cheers will give that ago tomorrow, just gonna be pretty difficult getting round all the machines it seems to have infected! I would say around nearly 100
Posted

@Sophos Support

 

I have been installing the patch, and running the Malicous Software remover from Microsoft and was as Sophos, this has picked up the virus and got rid of it.

 

Do you know if it still leaves the schedule tasks? And these can be deleted manually?

 

Also who would I need to contact I have got a few machines that won't let me install Sophos, various errors including Registry error etc.

Posted
Sophos have a nice removal script that will remove all traces of sophos from a client. Fixes most issues with installation.

 

@SYSMAN_MK have tried the script but doesn't help.

 

Very annonying.

Posted
Do you know if it still leaves the schedule tasks? And these can be deleted manually?

 

Removing the scheduled tasks created by Conficker can be tricky as it's not easy to tell if the task is legitimate or not. Microsoft's KB does suggest removing all AT jobs...

 

Virus alert about the Win32/Conficker.B worm

 

Remove all AT-created scheduled tasks. To do this, type AT /Delete /Yes at a command prompt.

 

Also who would I need to contact I have got a few machines that won't let me install Sophos, various errors including Registry error etc.

 

You can call us: Sophos - Contact technical support

 

Regards,

 

Sophos Technical Support

Posted (edited)

@ SYSMAN_MK : Am using version 1.01

 

@ Sophos Support : am just deleting any task called AT, I have found machines with anything from 3 to 21.

 

Am also having trouble removing it, when I do a full scan as requested by Sophos to perform the action to delete it still doesn't let delete the conficker virus file.

Edited by mullet_man
Posted (edited)

COMPUTER VIRUS

 

 

 

A computer virus has been detected on various school networks.

 

 

 

The NOD32 anti-virus software will quarantine this virus but the alert screen keeps appearing and needs to be closed over and over again.

 

 

 

We have consulted with Eset who supply our anti-virus software and they have provided two patches which need to be applied to all servers and computers.

 

 

 

Please see attached file ( Virus Removal Tool.Zip ) and perform the following on all Servers / Workstations ASAP :-

 

 

 

· On ALL Servers Run the WindowsServer2003-KB958644-x86-ENU.exe file

 

· On ALL DEVICES now run the EConfickerRemover.exe File

 

· In the NOD32 Tray Icon browse to System Tools / Quarantine Area & Highlight and delete any quarantined files – ( you may need to go to Advanced mode in newer versions of NOD )

 

· REBOOT

 

 

 

If necessary run :

 

 

 

· On a Windows Vista PC’s run the Windows6.0-KB958644-x86.exe File

 

· On a Windows XP PC’s run the WindowsServer2003.WindowsXP-KB958644-x64-ENU.exe File

 

 

 

 

 

NOTE :- You Can create a startup batch file for the client workstations containing these exe’s

 

"\\UNC-PATH-TO-EXE-FOLDER\WindowsXP-KB958644-x86-ENU.exe" /passive /forcerestart

 

"\\UNC-PATH-TO-EXE-FOLDER\EConfickerRemover.exe" -autoclean

 

 

 

If the virus is detected please run the Remove FixDownadup symantic tool which will perform an intensive scan however it will and take several hours to complete.

Edited by PEO
Posted
I thinks it's upto 1.9

 

And I got page not found aswell for the removal tool last week. Very helpful that was!

 

Any idea where to get the latest script?

Posted

This b*****d of a virus made a comeback today, think we found a few machines that Sophos hasn't been updating recently.

 

Hopefully we should be ok, been a crappy few day today.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...