PcDude Posted February 2, 2009 Posted February 2, 2009 Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker ...very informative! 1
User3204 Posted February 2, 2009 Posted February 2, 2009 Our main file server, as reported one file as infected with this virus, and when I check the Mcafee EPO server, it has two reports of the virus. One on the main file server, and one on the workstation that had the USB disk with the virus on.... not sure how it managed to move to the file server... as it was deleted on both. I like this.. Virus found, Virus deleted... it's like the Advert.
WithoutMotive Posted February 3, 2009 Posted February 3, 2009 We got pounded by this this today. Spent all day with eveything off cleaning everything. Continuing tomorrow and banning the use of USB pen drives unless they're scanned by us first.
synaesthesia Posted February 3, 2009 Posted February 3, 2009 Harsh but seemingly required, especially as was mentioned earlier with the spate of them being given out free. I'd be tempted to disable USB ports altogether (unless required on specific machines) either through BIOS or via software/AD permissions. If infections like this can spread throughout a network which is heavily protected already continue to gain in popularity I'd be fairly paranoid about security about now :/
AyatollahPies Posted February 4, 2009 Posted February 4, 2009 If you are using Sophos - (there is nothing wrong with it, if it's not working for you, then look in the mirror and blame the first person you see!) You could use that logic for almost all computer related issues.
sippo Posted February 4, 2009 Posted February 4, 2009 Reading this thread as made me quite scared....
synaesthesia Posted February 4, 2009 Posted February 4, 2009 You could use that logic for almost all computer related issues. Definitely worth noting that NO single AV package available is capable of 100% disinfection of 100% of nasties. There are free packages out there with better detection rates than the most expensive packages, and some paid packages that barely do anything.
sippo Posted February 4, 2009 Posted February 4, 2009 I have just mailed staff, put up a notice in the staff room, and in the staff bulletin to get all teachers and staff to bring their usb pens/hdd to us for scanning. Lets hope they take note! We've just been advised by county that their head offices have been affected.
Sophos-Support-5 Posted February 5, 2009 Posted February 5, 2009 If you need a simple action plan for conficker... (1) Patch - this is your first and main priority. Patch patch patch. (2) Make sure your AV is installed, up to date and has working on-access/ real-time scanning - don't assume. Do check that all computers are running some protection. (3) Strengthen passwords for network shares. Conficker tries a large number of passwords and may guess weaker ones. Make the password long and complex - perhaps a phrase with UPPER and lowercase characters, d1g1t5 and symbols. (3) Disable file and printer sharing. OR divide your network up. If it's a small network you can pull the network cable and clean the machine. If you do: do NOT put it back on to the network unless you know every other computer connected is clean and will not potentially reinfect the machine. If you are running Sophos Anti-Virus see our "What to do" section for Conficker: Sophos Anti-Virus for Windows 2000+: removing W32/Confick and Mal/Conficker Regards, Sophos Technical Support 2
Sophos-Support-5 Posted February 6, 2009 Posted February 6, 2009 (edited) For those that do not have SAV installed or are finding cleanup difficult please check out: Sophos Conficker Cleanup Tool Edited February 6, 2009 by Sophos-Support-5 1
FN-GM Posted February 7, 2009 Posted February 7, 2009 Been chasing this about for most of today. Can't wait until monday
INeedAUsername Posted February 7, 2009 Posted February 7, 2009 We had this on our network - the lads I work with and Sophos were absolutley brilliant!! Couldnt have done this without them In the end I patched and updated all the servers in the school, deleted the 'random name' service using the cmd line and ran sophos. In the Sophos menu I selected 'delete' (or something similiar) when a virus was found and then started to deploy WSUS to do the remainder. All the lads kept an eye on it over the few days and the weekend, it killed the network but it was worth it. Now I only have an handful of PC's playing up but nothing a rebuild wouldnt fix. The problem is when staff bring in their laptops after long term illness/holidays and the Sophos updates their laptops and scans for any threat. It does grind the laptop right down but I think its worth having that for 10-20 mins rather than the confick appearing again. Hope this has helped someone STariq
PEO Posted February 7, 2009 Posted February 7, 2009 got the virus here, Just shut the servers down till I get in opn monday morning
WithoutMotive Posted February 8, 2009 Posted February 8, 2009 We're almost clean. Just a few more to do on Monday. Also showed me just how much staff DON'T listen to us.
synaesthesia Posted February 8, 2009 Posted February 8, 2009 Worth noting that if you have the option of using a DNS server other than local authority. OpenDNS have added a "catcher" for conficker - meaning if you have an infected machine which tries to call one of it's many homes, OpenDNS will let you know about it. Nice little article here: OpenDNS rolls out Conficker tracking, blocking ? The Register I use openDNS at home as it's quicker/more reliable than Be/O2's orrible servers so bonus here Not sure how that translates to school networks but if you register with openDNS you can use it to block all sorts of traffic, it's very handy and very free. 1
sippo Posted February 13, 2009 Posted February 13, 2009 Microsoft giving reward of $250k. BBC NEWS | Technology | Microsoft bounty for worm creator
AyatollahPies Posted February 13, 2009 Posted February 13, 2009 I went to the Sophos Open day yesterday. Was rather impressed, and not just with the free Umbrella! Graham Clueley is rather Dan Ackroyd esq in the flesh, unlike in his pictures.
FragglePete Posted February 13, 2009 Posted February 13, 2009 This thread is filling me with dread! Sophos caught Conficker on a USB that one of the kids plugged in a couple of weeks ago. We panic'd when I got the e-mail from the console appear in my mailbox and swiftly downed the machine and run an off-line scan on it. (Came up clean). I disabled the pupils account and he had to come and see me about it, but just seemed completely oblivious to it. :wall: Pete
PEO Posted February 13, 2009 Posted February 13, 2009 Does anyone know if eset nod32 can do the same thing... email me if a virus is found. we find alot of people in the school close the warning and not tell us.
Sophos-Support-5 Posted February 13, 2009 Posted February 13, 2009 This thread is filling me with dread! You shouldn't let it. Conficker isn't that bad if you're protected. This virus is causing a certain amount of panic because, in all honesty, it's exposing how poorly protected some networks are. Microsoft released the patch back in October and loads of networks still don't have it installed. If you're patched on ALL machines and you have up-to-date AV on ALL machines then you won't suffer. Asked "are you 100% patched?" the usual answer is "yes, certainly, yes, yes, yes. Ah, well probably." If you have no central management of either (1) patch control or (2) minimum AV requirement on every machine allowed to communicate on the network then how can you be sure you're protected? Answer: Sophos Endpoint Security 8 (which includes SophosNAC) or Sophos NAC Advanced (that doesn't require SAV to be installed): Endpoint control - How much control do you want? Our vulnerabilities list shows three vulnerabilities in February, one in January and nine back in December. Hands up who is 100% patched on 100% of their machines and can prove it. Latest vulnerabilities analysis Regards, Sophos Technical Support 1
synaesthesia Posted February 14, 2009 Posted February 14, 2009 Some of the difficulties lie in existing AV products not being able to detect it. Update definitions but more important program updates for all the big ones, Sophos included, haven't been rolled out until the last couple of weeks. However the removal tools (I think I've got just about everyones!) are invaluable - I've got a pair of CDRs with them all on due to the amount of infections I've had to deal with. Another difficulty is the sub-infections - conficker itself as we know isn't a major problem to detect and remove, but some of the infections that have started to come down with and variants of Conficker itself are appearing all over the place. One that springs to mind in this area is "zlob" - one of many fake AV program providers.
Bruce123 Posted February 16, 2009 Posted February 16, 2009 We've had this infection for a couple of week and now that it is half term I see it as an opportunity to eradicate it properly. Up to now; we have deployed the patch to all servers, pcs and laptops; disabled autorun in portable devices. To actually remove the worm from infected systems we have setup a shutdown script which runs f-secure's f-downadup.exe to scan for the worm; it returns an error level of 1 it has detected the worm and in this case runs f-downadup.exe again but with --disinfect. All infections are logged centrally. We are going to keep this going and if it doesn't work we may shutdown the network for the afternoon. One potential niggle is I suspect that if a PC is infected and an admin user logs on the worm inherits admin right; thus giving it full rights to infect all PCs and servers, irrespective of the patch. I agree that this episode exposes just how insecure some networks can be. The real problem is that all networks are inherently insecure. A centralised thin client network may help and the TCM module (with associated software) may also (future). Bruce.
gshaw Posted February 18, 2009 Posted February 18, 2009 Reading about this fills me with paranoia as well as teaching machines are much harder to patch as they're being used all the time so update time windows are few and far between. Looking into WOL in early morning maybe but for the moment I'm forcing the patch out room by room. I've been checking the registry in HKLM\Software\Microsoft\Windows NT\Currentversion\svchost for odd-named entries from what I read in the Microsoft KB article - is that a reliable indicator of infection?
RabbieBurns Posted February 18, 2009 Posted February 18, 2009 I have my updates for teachers computers set to download them automatically, and notify them of the updates. If they dont choose to apply the updates, the option once they shutdown defaults to "apply updates and shutdown" which they know to choose. I keep an eye on WSUS to keep on top of any machines that arenet up at 99-100%.
Bruce123 Posted February 18, 2009 Posted February 18, 2009 As pointed out WSUS should provide the update automatically; if you don't have WSUS setup than you can deploy the patch automatically (.exe downloadable from MS) in the startup script (may require a command line option to do it silently). However, the update will only apply to WinXP SP2 (and above) PCs. Thanks Bruce.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now