gshaw Posted February 19, 2009 Posted February 19, 2009 Yeah I've been sending it round teaching PCs the last few days - not sure but think it requires a reboot so want to try and get it done manually before people come back. So far haven't found anything odd in the registry keys and all the services are still working on the PCs I've looked at so fingers crossed...
Sophos-Support-5 Posted February 19, 2009 Posted February 19, 2009 I've been checking the registry in HKLM\Software\Microsoft\Windows NT\Currentversion\svchost for odd-named entries from what I read in the Microsoft KB article - is that a reliable indicator of infection? Things you can (perhaps) visually spot... Extract from the "more information" tab on Mal/Conficker-A Malicious behavior (WORM_DOWNAD.AD, W32/Conficker.worm, Worm:Win32/Conficker.gen!A, Worm:W32/Downadup, Net-Worm.Win32.Kido) - Sophos security analysis (1) \ (e.g. C:\windows\system32\zdtnx.g) (2) The registry entries added by Mal/Confiker-A are under: HKLM\SYSTEM\CurrentControlSet\Services\ (3) The random service name will also be added to the list of services referenced by: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs (4) When spreading to removable media Mal/Conficker-A attempts to create the following hidden files: \autorun.inf \RECYCLER\S-x-x-x-xxx-xxx-xxx-x\.dll (where x represents a random digit) Please read the above page in full for more information and also Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker Regards, Sophos Technical Support
Crispin Posted February 19, 2009 Posted February 19, 2009 After reading this thread my number one priority at the moment is to talk my crazy network manager out of getting rid of WSUS altogether and basically 'winging' it. Currently: Mcafee not updated since Jan 9th WSUS not active since way before christmas. Im terrified.
theaksy Posted February 19, 2009 Posted February 19, 2009 I had the Conficker virus. No need to shut down your network. Set your anti virus (I use sophos) to on write access scanning, restart computer then do full scan. This should now pick up the virus and allow you to remove it. Push out the patch via GP if you don't have WSUS. If you use ISA, search for any host accessing the sites Conficker tries to access. This will give you a list of infected machines. Clean these up using the method above and then clear the virus alerts. Wait to see if you get any more alerts (may take a few hours). If you do, check ISA logs again. You may get machines warning you they have been infected then the file has been deleted. Conficker can spread using the ADMIN$ share, so this warning is basically telling you a machine on your domain has tried to infect it, not that it has the virus. Hope this helps. Took me 3 days to clear, but not that much work. It certainly helps you find the workstations that aren't running anti-virus properly. As a side note, if you have sophos, upgrade to the enterprise console 3.1. Its much better at automatically installing sophos according to linked active directory OUs. If you need any advice give us a shout
mullet_man Posted March 3, 2009 Posted March 3, 2009 ARRRRHHH Sophos has been picking this up all morning, can't tell if Sophos has been cleaning it up or not?
Sophos-Support-5 Posted March 3, 2009 Posted March 3, 2009 (edited) ARRRRHHH Sophos has been picking this up all morning, can't tell if Sophos has been cleaning it up or not? Go to a machine. Unplug the network cable. Run a FULL scan (scan all files checked). When the scan has finished cleanup items in quarantine. Run another FULL scan. If it comes back clean we're cleaning it up. If you put the computer back on the network and it gets "infected" then there is an unpatched or unprotected machine on the network - or someone plugged in a USB pen into the computer. Regards, Sophos Edited March 3, 2009 by Sophos-Support-5
mullet_man Posted March 3, 2009 Posted March 3, 2009 Cheers will give that ago tomorrow, just gonna be pretty difficult getting round all the machines it seems to have infected! I would say around nearly 100
mullet_man Posted March 4, 2009 Posted March 4, 2009 ARRH again!! Got in this morning to most admin accounts locked out
mullet_man Posted March 4, 2009 Posted March 4, 2009 @Sophos Support I have been installing the patch, and running the Malicous Software remover from Microsoft and was as Sophos, this has picked up the virus and got rid of it. Do you know if it still leaves the schedule tasks? And these can be deleted manually? Also who would I need to contact I have got a few machines that won't let me install Sophos, various errors including Registry error etc.
mullet_man Posted March 4, 2009 Posted March 4, 2009 Sophos have a nice removal script that will remove all traces of sophos from a client. Fixes most issues with installation. @SYSMAN_MK have tried the script but doesn't help. Very annonying.
Sophos-Support-5 Posted March 4, 2009 Posted March 4, 2009 Do you know if it still leaves the schedule tasks? And these can be deleted manually? Removing the scheduled tasks created by Conficker can be tricky as it's not easy to tell if the task is legitimate or not. Microsoft's KB does suggest removing all AT jobs... Virus alert about the Win32/Conficker.B worm Remove all AT-created scheduled tasks. To do this, type AT /Delete /Yes at a command prompt. Also who would I need to contact I have got a few machines that won't let me install Sophos, various errors including Registry error etc. You can call us: Sophos - Contact technical support Regards, Sophos Technical Support
mullet_man Posted March 4, 2009 Posted March 4, 2009 (edited) @ SYSMAN_MK : Am using version 1.01 @ Sophos Support : am just deleting any task called AT, I have found machines with anything from 3 to 21. Am also having trouble removing it, when I do a full scan as requested by Sophos to perform the action to delete it still doesn't let delete the conficker virus file. Edited March 4, 2009 by mullet_man
RabbieBurns Posted March 4, 2009 Posted March 4, 2009 Anyone else getting a page not found when trying to download the Sophos Conficker Cleanup Tool? direct link: https://secure.sophos.com/support/updates/dp/full/scct_10_sfx.exe
PEO Posted March 5, 2009 Posted March 5, 2009 (edited) COMPUTER VIRUS A computer virus has been detected on various school networks. The NOD32 anti-virus software will quarantine this virus but the alert screen keeps appearing and needs to be closed over and over again. We have consulted with Eset who supply our anti-virus software and they have provided two patches which need to be applied to all servers and computers. Please see attached file ( Virus Removal Tool.Zip ) and perform the following on all Servers / Workstations ASAP :- · On ALL Servers Run the WindowsServer2003-KB958644-x86-ENU.exe file · On ALL DEVICES now run the EConfickerRemover.exe File · In the NOD32 Tray Icon browse to System Tools / Quarantine Area & Highlight and delete any quarantined files – ( you may need to go to Advanced mode in newer versions of NOD ) · REBOOT If necessary run : · On a Windows Vista PC’s run the Windows6.0-KB958644-x86.exe File · On a Windows XP PC’s run the WindowsServer2003.WindowsXP-KB958644-x64-ENU.exe File NOTE :- You Can create a startup batch file for the client workstations containing these exe’s "\\UNC-PATH-TO-EXE-FOLDER\WindowsXP-KB958644-x86-ENU.exe" /passive /forcerestart "\\UNC-PATH-TO-EXE-FOLDER\EConfickerRemover.exe" -autoclean If the virus is detected please run the Remove FixDownadup symantic tool which will perform an intensive scan however it will and take several hours to complete. Edited March 5, 2009 by PEO
mullet_man Posted March 5, 2009 Posted March 5, 2009 I thinks it's upto 1.9 And I got page not found aswell for the removal tool last week. Very helpful that was! Any idea where to get the latest script?
PEO Posted March 5, 2009 Posted March 5, 2009 (edited) if any one wants the virus removal tool pm me... I cant seem to upload it here ok here is a link to the remove tool http://www.bishopsgarth.stockton.sch.uk/index.php?option=com_content&view=article&id=99 Edited March 5, 2009 by PEO hope this helps you all 1
Sophos-Support-5 Posted March 6, 2009 Posted March 6, 2009 After i login i get a page not found Worked for me just now. We've not had any reported problems with downloading the file. If you want another link (that doesn't require registration) then try (754kB): http://www.sophos.com/support/cleaners/scct_10_sfx.exe Regards, Sophos Technical Support
spchappell Posted March 8, 2009 Posted March 8, 2009 We had a lot of fun with this very interesting worm. I blogged about our experiences here http://spchappell.blogspot.com. Simon
mullet_man Posted March 10, 2009 Posted March 10, 2009 This b*****d of a virus made a comeback today, think we found a few machines that Sophos hasn't been updating recently. Hopefully we should be ok, been a crappy few day today.
tmcd35 Posted March 10, 2009 Posted March 10, 2009 This virus has made the local news here on Norfolk! EDP24 - Norfolk schools hit by computer virus Five secondary schools and the PDC hit! The main secondary school mentioned in the article, Thorpe St Andrew, was my old place. I've been back over the past week to help them eradicate it. It's quite a vicious virus. Once it's in, it's there to stay.
mullet_man Posted March 10, 2009 Posted March 10, 2009 It's quite a vicious virus. Once it's in, it's there to stay. Tell me about it, thought I got rid of it last week. How you been hitting it??
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now