Jump to content

Recommended Posts

Posted
How up to date is your AV? Sounds like conficker to me.... one of the first signs is accounts getting locked out as it trys to guess passwords.
Posted

You can turn it off under group policy, but I'd prefer admin accounts were locked out than brute-forced.

 

Possibilities aside from viruses.

 

1) A scheduled task running using admin credentials that hasn't been updated after an admin password changed?

2) A kid messing around, especially if "admin" or "administrator" or "name he can guess" is an admin account.

 

What do the event logs say - where are the failed logins coming from? What IP/host? Is it happening to any sort of schedule?

Posted

Best way I've found is to use NMap. Download the latest version and run nmap -PN -T4 -p139,445 -n -v --script=smb-check-vulns --script-args safe=1 [targetnetworks]

 

:)

Posted
Use the Microsoft Malicious Software Removal tool in a startup script. Worked best for me.

 

To remove conficker I've also used the Spohos removal tool and the Kaspersky removal tool. Both seem to work well :)

Posted

Symantec detects it as DownUp (theres multipul names for this nasty).

 

Make sure you disable autorun on your network, it is how this nasty gets around in some cases.

Posted
Still getting these lock outs, I've installed the Acctinfo.dll tab in AD to look at the lockout info, gonna have to do some digging on this one, been checking over the weekend and some machines are infected with conflicker! :(
Posted
Anyone know of any good Conflicker Network Scanners?

 

Hi mate I have a conflicker tool that sshould help, but I think it was mainly to work with nod32, I can send you it if its thats any good

Posted
Still getting these lock outs, I've installed the Acctinfo.dll tab in AD to look at the lockout info, gonna have to do some digging on this one, been checking over the weekend and some machines are infected with conflicker! :(

 

Make doubly sure it isn't on your servers else you will be going round in circles.

Posted

Conficker is a right pain, we got infected a few weeks back when a student teacher plugged their home laptop in to the network (time to look in to 802.1x i think...). Only a few machines got infected as they weren't updating from WSUS for some reason but it was all it took to cause choas with account lockouts.

 

We used the Symantec tool to remove it, wish I'd known of the Sophos network one as it sounds much quicker. Check the security event logs on the DC's as it will help you track down the infected machines, enable audit account logon events for failure if it isn't already in the domain controller security policy.

Posted (edited)

I've installed M$ Patch MS08-067 on all are servers, running the sophos removal tool atm

 

Im in the Security Log atm, what would I be looking for in there to pin point machines?

Edited by IanT
Posted
Look for Failure Audits of category Logon/Logoff, open the event and it will give you the IP of the offending machine (Source Network Address). If there is more than one or two from the same machine in a short period of time then chances are that machine is infected.
  • 2 weeks later...
Posted

You can disable account lockouts in Domain Security Policy.

I had to disable it as students would lock eachother's accounts out, forcing them to come to my office to get it unblocked !

(sometimes they even purposely block themselves to get 5 minutes out of a lesson!)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...