reggiep Posted October 9, 2009 Posted October 9, 2009 I am struggling to remove kido/conficker from my network at the moment. I have a tool from mcaffee which scans your network to let you know which machines are infected. Bizarrly it only showed three machines whereas Kaspersky is telling me that every machine has an infection (perhaps it isn't a full infection?) Anyway when i ran the scanner I found two of the three machines and ran a kido removal tool. They are now showing up as clean on the scanner. My problem is with the third which is showing as a laptop (Old naming convention we used to have). I would like to block it from the network via dhcp so it won't connect to my network. Hopefully then the owner will show up complaining and then I can zap it and them! So I'm looking at dhcp and scratching my head? Can someone help? Thanks
bladedanny Posted October 9, 2009 Posted October 9, 2009 Only thing I can think of at the moment is if it's part of a domain, could you not disable the computer account? Hope this helps, Dan
leon999uk Posted October 9, 2009 Posted October 9, 2009 Only thing I can think of at the moment is if it's part of a domain, could you not disable the computer account? Hope this helps, Dan Please Someone correct me if i am wrong... But disabling the account is fine, thus stopping any user from logging onto the machine. But if it still connects or is connected to the network, via wireless / ethernet cable it will still spread the virus! 1
kmount Posted October 9, 2009 Posted October 9, 2009 Please Someone correct me if i am wrong... But disabling the account is fine, thus stopping any user from logging onto the machine. But if it still connects or is connected to the network, via wireless / ethernet cable it will still spread the virus! Correct; if it gets an IP from DHCP it will still be able to communicate on the network. Reggiep, try connecting to the laptop from another machine via \\nameofmachine\c$ and look in Documents and Settings and see who's username is the newest modified one, might help pinpoint the owner.
leon999uk Posted October 9, 2009 Posted October 9, 2009 (edited) Correct; if it gets an IP from DHCP it will still be able to communicate on the network. Reggiep, try connecting to the laptop from another machine via \\nameofmachine\c$ and look in Documents and Settings and see who's username is the newest modified one, might help pinpoint the owner. if you are worried about the virus spreading maybe try disabling ports on the firewall? I know we have 2 domains here and had a really bad virus outbreak a few years back and our network technician i believe blocked firewall access to stop it from spreading to the other domain. Not sure if you are running 2 domains, but just and idea if you are. Edited October 9, 2009 by leon999uk
ccs Posted October 9, 2009 Posted October 9, 2009 Try assigning a bogus(an address not in your normal IP range) ip address that is associated to that mac address via DHCP. This should prevent them from connecting to the interent and local LAN, thus seeking your help! -Steve
Shortround Posted October 9, 2009 Posted October 9, 2009 not sure if this might be of use to you:- Network Access Control Advanced - Sophos
pete Posted October 9, 2009 Posted October 9, 2009 Assuming you have a record of the laptop's current (or previous) IPs, search in the AD security log to find out which user logged into the domain from that machine? Blackholing them on DNS would work too. If they connect wirelessly, you should be able to block them from connecting via blocking them either at the radius server or on the APs / controller.
ChrisH Posted October 9, 2009 Posted October 9, 2009 I found the best way to disinfect everyone was to run the MS Malicious Software Removal tool in a startup or shutdown script. There are all kinds of service entries and other files it leaves around. Make sure you disable system restore in GP as well.
Cache Posted October 9, 2009 Posted October 9, 2009 You could try using the callout dll Microsoft Windows DHCP Team Blog : DHCP Server Callout DLL for MAC Address based filtering If I remember rightly from when I played about with it it worked well, although if the laptop already has a lease it might take until the lease has expired before it will stop working completely, but I can't remember if that's exactly right or not.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now