IanT Posted November 28, 2009 Posted November 28, 2009 This is driving me crazy! admin accounts just getting locked!! Anyway of turning this feature off?
mossj Posted November 28, 2009 Posted November 28, 2009 How up to date is your AV? Sounds like conficker to me.... one of the first signs is accounts getting locked out as it trys to guess passwords.
IanT Posted November 28, 2009 Author Posted November 28, 2009 is it worth having this feature as I can turn it off
pete Posted November 28, 2009 Posted November 28, 2009 You can turn it off under group policy, but I'd prefer admin accounts were locked out than brute-forced. Possibilities aside from viruses. 1) A scheduled task running using admin credentials that hasn't been updated after an admin password changed? 2) A kid messing around, especially if "admin" or "administrator" or "name he can guess" is an admin account. What do the event logs say - where are the failed logins coming from? What IP/host? Is it happening to any sort of schedule?
IanT Posted November 28, 2009 Author Posted November 28, 2009 Anyone know of any good Conflicker Network Scanners?
Soulfish Posted November 28, 2009 Posted November 28, 2009 Best way I've found is to use NMap. Download the latest version and run nmap -PN -T4 -p139,445 -n -v --script=smb-check-vulns --script-args safe=1 [targetnetworks]
ChrisH Posted November 28, 2009 Posted November 28, 2009 Use the Microsoft Malicious Software Removal tool in a startup script. Worked best for me.
Soulfish Posted November 28, 2009 Posted November 28, 2009 Use the Microsoft Malicious Software Removal tool in a startup script. Worked best for me. To remove conficker I've also used the Spohos removal tool and the Kaspersky removal tool. Both seem to work well
rh91uk Posted November 28, 2009 Posted November 28, 2009 Oh god Conficker is horrible. I, along with Soulfish at our place, deployed out the Sohpos tool. Works a treat. Sophos Conficker Clean-up Tool (network version) 1
p858snake Posted November 28, 2009 Posted November 28, 2009 Symantec detects it as DownUp (theres multipul names for this nasty). Make sure you disable autorun on your network, it is how this nasty gets around in some cases.
ChrisH Posted November 29, 2009 Posted November 29, 2009 The microsoft Tool seemed to be more thorough with scheduled tasks and services that Conficker creates.
rh91uk Posted November 29, 2009 Posted November 29, 2009 The microsoft tool didn't clean it up here ... which was quite weird!
ChrisH Posted November 29, 2009 Posted November 29, 2009 The microsoft tool didn't clean it up here ... which was quite weird! Maybe your machines were getting re-infected straight away?
IanT Posted November 29, 2009 Author Posted November 29, 2009 Still getting these lock outs, I've installed the Acctinfo.dll tab in AD to look at the lockout info, gonna have to do some digging on this one, been checking over the weekend and some machines are infected with conflicker!
PEO Posted November 29, 2009 Posted November 29, 2009 Anyone know of any good Conflicker Network Scanners? Hi mate I have a conflicker tool that sshould help, but I think it was mainly to work with nod32, I can send you it if its thats any good
rh91uk Posted November 29, 2009 Posted November 29, 2009 What I would do is get the Sophos tool to run on PC startup so tmw it runs. I can send you our modified vbscript if you want
ChrisH Posted November 29, 2009 Posted November 29, 2009 Still getting these lock outs, I've installed the Acctinfo.dll tab in AD to look at the lockout info, gonna have to do some digging on this one, been checking over the weekend and some machines are infected with conflicker! Make doubly sure it isn't on your servers else you will be going round in circles.
IanT Posted December 2, 2009 Author Posted December 2, 2009 eekk!!! head got locked out this morning!!
Hokalus Posted December 2, 2009 Posted December 2, 2009 Conficker is a right pain, we got infected a few weeks back when a student teacher plugged their home laptop in to the network (time to look in to 802.1x i think...). Only a few machines got infected as they weren't updating from WSUS for some reason but it was all it took to cause choas with account lockouts. We used the Symantec tool to remove it, wish I'd known of the Sophos network one as it sounds much quicker. Check the security event logs on the DC's as it will help you track down the infected machines, enable audit account logon events for failure if it isn't already in the domain controller security policy.
IanT Posted December 2, 2009 Author Posted December 2, 2009 (edited) I've installed M$ Patch MS08-067 on all are servers, running the sophos removal tool atm Im in the Security Log atm, what would I be looking for in there to pin point machines? Edited December 2, 2009 by IanT
Hokalus Posted December 2, 2009 Posted December 2, 2009 Look for Failure Audits of category Logon/Logoff, open the event and it will give you the IP of the offending machine (Source Network Address). If there is more than one or two from the same machine in a short period of time then chances are that machine is infected.
IanT Posted December 2, 2009 Author Posted December 2, 2009 looks like this is under control now, using Conficker Detection Tool from McAfee
mikes Posted December 10, 2009 Posted December 10, 2009 You can disable account lockouts in Domain Security Policy. I had to disable it as students would lock eachother's accounts out, forcing them to come to my office to get it unblocked ! (sometimes they even purposely block themselves to get 5 minutes out of a lesson!)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now