Jump to content

Recommended Posts

Posted

Our main file server, as reported one file as infected with this virus, and when I check the Mcafee EPO server, it has two reports of the virus.

One on the main file server, and one on the workstation that had the USB disk with the virus on.... not sure how it managed to move to the file server... as it was deleted on both.

 

 

I like this.. Virus found, Virus deleted... it's like the Advert. :cool:

Posted

Harsh but seemingly required, especially as was mentioned earlier with the spate of them being given out free.

I'd be tempted to disable USB ports altogether (unless required on specific machines) either through BIOS or via software/AD permissions. If infections like this can spread throughout a network which is heavily protected already continue to gain in popularity I'd be fairly paranoid about security about now :/

Posted

If you are using Sophos - (there is nothing wrong with it, if it's not working for you, then look in the mirror and blame the first person you see!)

 

You could use that logic for almost all computer related issues.

Posted
You could use that logic for almost all computer related issues.

 

Definitely worth noting that NO single AV package available is capable of 100% disinfection of 100% of nasties. There are free packages out there with better detection rates than the most expensive packages, and some paid packages that barely do anything.

Posted

I have just mailed staff, put up a notice in the staff room, and in the staff bulletin to get all teachers and staff to bring their usb pens/hdd to us for scanning. Lets hope they take note!

 

We've just been advised by county that their head offices have been affected.

Posted

If you need a simple action plan for conficker...

 

(1) Patch - this is your first and main priority. Patch patch patch.

(2) Make sure your AV is installed, up to date and has working on-access/ real-time scanning - don't assume. Do check that all computers are running some protection.

(3) Strengthen passwords for network shares. Conficker tries a large number of passwords and may guess weaker ones. Make the password long and complex - perhaps a phrase with UPPER and lowercase characters, d1g1t5 and symbols.

(3) Disable file and printer sharing. OR divide your network up. If it's a small network you can pull the network cable and clean the machine. If you do: do NOT put it back on to the network unless you know every other computer connected is clean and will not potentially reinfect the machine.

 

If you are running Sophos Anti-Virus see our "What to do" section for Conficker: Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker

 

Regards,

 

Sophos Technical Support

  • Thanks 2
Posted

We had this on our network - the lads I work with and Sophos were absolutley brilliant!! Couldnt have done this without them :)

 

In the end I patched and updated all the servers in the school, deleted the 'random name' service using the cmd line and ran sophos.

 

In the Sophos menu I selected 'delete' (or something similiar) when a virus was found and then started to deploy WSUS to do the remainder.

 

All the lads kept an eye on it over the few days and the weekend, it killed the network but it was worth it.

 

Now I only have an handful of PC's playing up but nothing a rebuild wouldnt fix.

 

The problem is when staff bring in their laptops after long term illness/holidays and the Sophos updates their laptops and scans for any threat. It does grind the laptop right down but I think its worth having that for 10-20 mins rather than the confick appearing again.

 

Hope this has helped someone

 

STariq

Posted

Worth noting that if you have the option of using a DNS server other than local authority. OpenDNS have added a "catcher" for conficker - meaning if you have an infected machine which tries to call one of it's many homes, OpenDNS will let you know about it.

Nice little article here: OpenDNS rolls out Conficker tracking, blocking ? The Register

 

I use openDNS at home as it's quicker/more reliable than Be/O2's orrible servers so bonus here :) Not sure how that translates to school networks but if you register with openDNS you can use it to block all sorts of traffic, it's very handy and very free.

  • Thanks 1
Posted

This thread is filling me with dread!

 

Sophos caught Conficker on a USB that one of the kids plugged in a couple of weeks ago.

 

We panic'd when I got the e-mail from the console appear in my mailbox and swiftly downed the machine and run an off-line scan on it. (Came up clean).

 

I disabled the pupils account and he had to come and see me about it, but just seemed completely oblivious to it. :wall:

 

Pete

Posted
Does anyone know if eset nod32 can do the same thing... email me if a virus is found. we find alot of people in the school close the warning and not tell us.
Posted
This thread is filling me with dread!

 

You shouldn't let it. :)

 

Conficker isn't that bad if you're protected. This virus is causing a certain amount of panic because, in all honesty, it's exposing how poorly protected some networks are. Microsoft released the patch back in October and loads of networks still don't have it installed.

 

If you're patched on ALL machines and you have up-to-date AV on ALL machines then you won't suffer.

 

Asked "are you 100% patched?" the usual answer is "yes, certainly, yes, yes, yes. Ah, well probably." If you have no central management of either (1) patch control or (2) minimum AV requirement on every machine allowed to communicate on the network then how can you be sure you're protected?

 

Answer: Sophos Endpoint Security 8 (which includes SophosNAC) or Sophos NAC Advanced (that doesn't require SAV to be installed):

 

Endpoint control - How much control do you want?

 

Our vulnerabilities list shows three vulnerabilities in February, one in January and nine back in December. Hands up who is 100% patched on 100% of their machines and can prove it.

 

Latest vulnerabilities analysis

 

Regards,

 

Sophos Technical Support

  • Thanks 1
Posted

Some of the difficulties lie in existing AV products not being able to detect it. Update definitions but more important program updates for all the big ones, Sophos included, haven't been rolled out until the last couple of weeks. However the removal tools (I think I've got just about everyones!) are invaluable - I've got a pair of CDRs with them all on due to the amount of infections I've had to deal with.

Another difficulty is the sub-infections - conficker itself as we know isn't a major problem to detect and remove, but some of the infections that have started to come down with and variants of Conficker itself are appearing all over the place. One that springs to mind in this area is "zlob" - one of many fake AV program providers.

Posted

We've had this infection for a couple of week and now that it is half term I see it as an opportunity to eradicate it properly.

 

Up to now; we have deployed the patch to all servers, pcs and laptops; disabled autorun in portable devices.

 

To actually remove the worm from infected systems we have setup a shutdown script which runs f-secure's f-downadup.exe to scan for the worm; it returns an error level of 1 it has detected the worm and in this case runs f-downadup.exe again but with --disinfect. All infections are logged centrally.

 

We are going to keep this going and if it doesn't work we may shutdown the network for the afternoon.

 

One potential niggle is I suspect that if a PC is infected and an admin user logs on the worm inherits admin right; thus giving it full rights to infect all PCs and servers, irrespective of the patch.

 

I agree that this episode exposes just how insecure some networks can be. The real problem is that all networks are inherently insecure. A centralised thin client network may help and the TCM module (with associated software) may also (future).

 

Bruce.

Posted

Reading about this fills me with paranoia as well as teaching machines are much harder to patch as they're being used all the time so update time windows are few and far between. Looking into WOL in early morning maybe but for the moment I'm forcing the patch out room by room.

 

I've been checking the registry in HKLM\Software\Microsoft\Windows NT\Currentversion\svchost for odd-named entries from what I read in the Microsoft KB article - is that a reliable indicator of infection?

Posted

I have my updates for teachers computers set to download them automatically, and notify them of the updates. If they dont choose to apply the updates, the option once they shutdown defaults to "apply updates and shutdown" which they know to choose.

 

I keep an eye on WSUS to keep on top of any machines that arenet up at 99-100%.

Posted
As pointed out WSUS should provide the update automatically; if you don't have WSUS setup than you can deploy the patch automatically (.exe downloadable from MS) in the startup script (may require a command line option to do it silently). However, the update will only apply to WinXP SP2 (and above) PCs. Thanks Bruce.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...