Jump to content

Recommended Posts

Posted

I am struggling to remove kido/conficker from my network at the moment. I have a tool from mcaffee which scans your network to let you know which machines are infected. Bizarrly it only showed three machines whereas Kaspersky is telling me that every machine has an infection (perhaps it isn't a full infection?)

Anyway when i ran the scanner I found two of the three machines and ran a kido removal tool. They are now showing up as clean on the scanner. My problem is with the third which is showing as a laptop (Old naming convention we used to have).

I would like to block it from the network via dhcp so it won't connect to my network. Hopefully then the owner will show up complaining and then I can zap it and them!

 

So I'm looking at dhcp and scratching my head?

 

Can someone help?

 

Thanks

Posted
Only thing I can think of at the moment is if it's part of a domain, could you not disable the computer account?

 

Hope this helps,

 

Dan

 

Please Someone correct me if i am wrong...

But disabling the account is fine, thus stopping any user from logging onto the machine. But if it still connects or is connected to the network, via wireless / ethernet cable it will still spread the virus!

  • Thanks 1
Posted
Please Someone correct me if i am wrong...

But disabling the account is fine, thus stopping any user from logging onto the machine. But if it still connects or is connected to the network, via wireless / ethernet cable it will still spread the virus!

 

 

Correct; if it gets an IP from DHCP it will still be able to communicate on the network.

 

Reggiep, try connecting to the laptop from another machine via \\nameofmachine\c$ and look in Documents and Settings and see who's username is the newest modified one, might help pinpoint the owner.

Posted (edited)
Correct; if it gets an IP from DHCP it will still be able to communicate on the network.

 

Reggiep, try connecting to the laptop from another machine via \\nameofmachine\c$ and look in Documents and Settings and see who's username is the newest modified one, might help pinpoint the owner.

 

if you are worried about the virus spreading maybe try disabling ports on the firewall?

 

I know we have 2 domains here and had a really bad virus outbreak a few years back and our network technician i believe blocked firewall access to stop it from spreading to the other domain.

 

Not sure if you are running 2 domains, but just and idea if you are.

Edited by leon999uk
Posted

Try assigning a bogus(an address not in your normal IP range) ip address that is associated to that mac address via DHCP. This should prevent them from connecting to the interent and local LAN, thus seeking your help!

-Steve

Posted

Assuming you have a record of the laptop's current (or previous) IPs, search in the AD security log to find out which user logged into the domain from that machine?

 

Blackholing them on DNS would work too. If they connect wirelessly, you should be able to block them from connecting via blocking them either at the radius server or on the APs / controller.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...