neon Posted March 16, 2010 Posted March 16, 2010 I have come in this morning after not a good monday to find all hell breaking loose! My log on scripts dont work is the main one, we have had a new photocopier with account tracking, the nice people at konica came and set it up, however since this my logon script is causing a error (please see attached) also looks like the conflicker virus has come back as people cannot get to the server and some can? am i right in thinking the conflicker virus is a DoS attack? does anyone have a definate way to get rid of it? have e-mailed and rang symantec but they tell me tp consult the website... useless.
danrhodes Posted March 16, 2010 Posted March 16, 2010 Only way to really erradicate would be to re-ghost I'd say if it keeps coming back. You don't want that flying around your network. D
m0nty Posted March 16, 2010 Posted March 16, 2010 (edited) looks like the conflicker virus has come back ... does anyone have a definate way to get rid of it? have e-mailed and rang symantec but they tell me tp consult the website... useless. In the short run, download KKiller (a Kaspersky tool) to kill off conficker on each workstation. Funnily enough, it's much better than Kaspersky AV itself. I run it as a scheduled task on my Windows servers and use it to disinfect workstations. Another thing you can do is block conficker's command-and-control by looking in your server logs for URLs like this one: http://221.7.91.31/search?q=227 and blocking them. I use a rule in my squid config to do this: I'm sure other proxies will do the same. It looks a bit like a Google search URL with the ?q= part but it only ever uses IP addresses, so the rule blocks those with search?q=nnn appended. HTH, good luck. (Another thing I meant to say: download Microsoft Security Essentials and schedule updates with this tool if you're not using WSUS: http://lifehacker.com/5406683/mse-update-utility-keeps-security-up-to-date-without-windows-update Long-winded but works better than the commercial AV imo.) -- Simon Edited March 16, 2010 by m0nty
robyholmes Posted March 16, 2010 Posted March 16, 2010 (Another thing I meant to say: download Microsoft Security Essentials and schedule updates with this tool if you're not using WSUS: MSE Update Utility Keeps Security Up to Date Without Windows Update - Microsoft security essentials - Lifehacker Long-winded but works better than the commercial AV imo.) -- Simon As far as I understand it MSE is for home use only, not schools. So be careful where you use it.
srochford Posted March 17, 2010 Posted March 17, 2010 sorry forgot to attach error :S Looks like you're trying to unmap a drive which isn't currently mapped. The "tidy" way to fix that is to enumerate network drives and only unmap if they're not already mapped. The way to get it working now is to stick "on error resume next" before the unmap section - the error will happen but no-one will see and this buys you time to fix things properly. The other thing to do is to make sure your login scripts run with cscript (rather than wscript which is what you are using) the benefit of this is that error messages etc are not done in message boxes (which confuse users and need "OK" clicking) but just written to the console (where users will ignore them but everything will just work :-))
jahbulon Posted March 17, 2010 Posted March 17, 2010 There are lots of conficker threads on this site already- worth your time checking. We got hit with it Jan '09- took down everything e.g. because of its constant attacks on the administrator account eventually everyone's accounts got disabled automatically by the AD. Besides all of the problems it causes the single all-conquering best thing to do is to update your images and implement a mass reimaging plan. We had our staff told that the internet would be out of use for a couple of weeks, ofc this is in the most dire of situations. If you can catch it in isolated areas- then disconnect those machines, sort them out while windows updating all the non-infected. This whole experience has caused me to use WSUS much more regularly! We haven't had a take down of any sorts for over a year now Good luck.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now