SimpleSi Posted May 11, 2012 Posted May 11, 2012 I'm not winning here Had Conficker in a school once in past - eliminated it by removing everything from network and then cleaning each machine before rejoining to network, setting them all to not autorun anything and making sure all pendrive/cameras/anything with a memory card in in were certified before being allowed to be used again. Did this at Easter at a school that got infected - though I was OK but then people noticed Sophos reporting that COnficker was being quarantined So, started again, got head to issue beheading notices to anyone putting anything into a USB slot - finished last Friday - on Tues Conficker being reported in quarantine on domain clients (not on one teachers machine that I've removed from the domain but still on network and using server as file/dhcp/print server etc. 1. Where's the little f.... gettting back in from??? (And how can I stop it keep on doing it!) 2. Is it an actual issue if all machines all fully patched and Sophos is quaratineing it (e.g can we live with it or will it cripple the network?) Si
Michael Posted May 11, 2012 Posted May 11, 2012 What about the server(s)? And the odds are, someone's home computer is probably unprotected and out-of-date.
DavidYoung Posted May 11, 2012 Posted May 11, 2012 When we had a similar situation at one of our sites (Conficker was spreading to PCs but Sophos was quarantining it), we found that it was spreading using the Task Scheduler, and using the fact that you can remotely-manage scheduled tasks from remote PCs to spread itself. Firstly, I suggest you use Windows Firewall GPOs to block any remote-management/administration ports, maybe disable the Task Scheduler if you don't need it. You'll probably find that there is a PC-zero, which is likely un-patched (we found that our one was several years out of date with Windows update), maybe Sophos isn't running, likely the user is running with admin rights. We found the PC and updated Windows and Sophos and then manually cleaned the virus from Safe Mode. 1
jamesfed Posted May 11, 2012 Posted May 11, 2012 I thought Microsoft released a patch that prevented Conflicker getting on things? Conficker Worm: Help Protect Windows from Conficker
JonWPS Posted May 11, 2012 Posted May 11, 2012 There's a Microsoft tech article which talks you through shutting this bandit down. Helped me when I was hit with this within weeks of starting in this job. Restrict access to svchost across the site, and run MSRT at startup on all clients for a while. Check Scheduled Tasks on all servers. I eventually traced our outbreak back to a couple of vanilla machines in our canteen. There is also a patch which was pre-SP3 I think. 1
themightymrp Posted May 11, 2012 Posted May 11, 2012 We also had to block task scheduler and disable file and print sharing on client machines (via group policy). Plus install the patch mentioned above. You can use the features of Sophos Enterprise Console to block off USB drives if I remember correctly 1
X-13 Posted May 11, 2012 Posted May 11, 2012 I thought Microsoft released a patch that prevented Conflicker getting on things? Conficker Worm: Help Protect Windows from Conficker That only works if you apply the patch...
Zenden Posted May 11, 2012 Posted May 11, 2012 I have dealt with this on a wide scale. Make sure all Pcs and servers have the patch KB948644 (havent double checked that but pretty sure it is right, i had to install it enough times!). If all of them do then it is an inactive infection being pulled either from autorun or task scheduler and wont be causing any damage. Make sure to disable autorun through group policy. Biggest thing to know is that if the PCs are patched then the infection is null and will not spread further, however if any PCs dont have the patch then it will spread using the admin$ share by keylogging passwords of anyone who logs in. 1
McChikenhanger Posted May 11, 2012 Posted May 11, 2012 Oh dear. You are going to need a lot of help and long hours to completely kill it off. It would be a good idea if you talk to Sophos and get them to help you. We just started using KAspersky on our network when we had a big outbreak. There's a small tool that we got from kaspersly specifically designed to target Conficker and kill any open processes that were infected. We ended up unplugging EVERYTHING (and I do mean EVERYTHING) from the network. Make sure that all servers are clean and patched, there's like three different patches that you need for each machine flavour, before replugging them to the network. Make sure that you haven't got anything connecting wirelessly to the network too, and disinfect every workstation prior to plugging it back to the network. It could be a good time to make new images for the workstations with all updates and latest AV releases just to make sure that Conficker it's truly dead. It took us about 2 weeks solid to completely kill it off. Good luck.
ZeroHour Posted May 11, 2012 Posted May 11, 2012 Doesnt sophos tell you the user account that triggered the quarantine? Also what settings do you use for sophos? On machines you have had issues with I would reset windows update store by stopping automatic updates service and renaming the directory c:\windows\softwaredistribution then starting the service back up. Also which variant are you seeing?
zag Posted May 11, 2012 Posted May 11, 2012 Should be really easy to stop. Just make the root of all your shared drives read only. It cant spread then.
ZeroHour Posted May 11, 2012 Posted May 11, 2012 (edited) One other thing, I would consider using sophos with on-write checking to prevent it making it onto file servers etc, then do scheduled full scans at nights to prevent things sneaking on. Edited May 11, 2012 by ZeroHour
CAM Posted May 11, 2012 Posted May 11, 2012 (edited) Sounds like you missed one. I've been down this road before and have a blog post about it: How to remove Conficker (AKA Downadup and Kido) - Blogs - EduGeek.net Little beggar never came back. We've since had warnings from infected USB drives pop up but the virus has never latched on again. Shut everything down, check every PC, check every PC again, reconnect things slowly starting with your servers then bringing up one lab at a time. One that is done, pray it never comes back. We ended up with a USB ban after the incident and even after bringing things up, we were still spotting warnings from Sophos about infected sticks on staff laptops and running straight up to class to confiscate both items for cleaning. Even though notices went round! Edited May 11, 2012 by CAM
SYNACK Posted May 11, 2012 Posted May 11, 2012 I thought this was a solved problem, is Windows not imune to it now?
Mcshammer_dj Posted May 11, 2012 Posted May 11, 2012 We cleared our network, by using the sophos specific tool and ensuring the correct patch has been applied to the machines. Start with the server and then do all the workstations. We still get warnings when infected datasticks are inserted but the virus cannot jump between the machines. We don't clean the sticks as we wanted to avoid wiping data that could be vital (even if it is infected). Regular offenders are warned that there is a problem and given some guidance on how to check their own home systems.
m25man Posted May 11, 2012 Posted May 11, 2012 Another common oversight and aid to getting ontop of this fast is changing all admin capable passwords. If a user account can open c$ on a remote machine it can use this to spread as quickly as you can clean. If you use the same local admin username and password on all workstations its like wasps and jam. Even worse on servers if the payload has hijacked an admin/tech or service account it has so many ways in. Check the security logs carefully and audit object access, one payload I found had used a service account with Admin rights to start deleting servers from AD and chunks out of registry keys. At least change the password of the account that your using to login and clean up with! In case its already been compromised. If you are running TS or RDP Servers make sure that the local admin accounts are locked down with a strong password these are another easy way in. If Sophos is sucessfully blocking and cleaning it on re-infection it sounds like you have it contained but have not yet cleaned the source. Increasing the Audit logging gives you a chance to catch whatever user/machine account is being used. Changing the password results in Audit Failures as the process tries to spread and these start to appear as red dots in the logs as opposed to a valid account/password that just copies the payload and deletes stuff with an Audit Sucess Message! Remember with these types of infections its only the virus mechanism that spreads the real damage is caused by the scripts and payloads it can download after its infected the host! There are some devestating variants of this type of beast and some clever people still finding ways to squeeze them into unplugged code holes out there. @ZeroHour 's recommendation is the one thing that Sophos tell you in the manuals that is to be avoided, because of the slight risk of Sophos deleting system files BUT it's the first thing thier support team will tell you to do when trying to fight such an outbreak so a +1 for that idea especially on your critical stuff if you cannot leave it switched off until you have cleaned everything! Check your firewall logs if you can for unusual outgoing connections from your clients, in Sonicwalls you can just enable the uncategorized CFS option and enable HTTPS filtering this normally flags up any machines that are trying to sneak out and phone home for a payload update. Best of luck.
sted Posted May 11, 2012 Posted May 11, 2012 its worth for the duration disabling ALL access to the task scheduler folder including system granted no tasks can run but also no confiker tasks can be created/run. I once had a startup script that EVERY bootup did a full pc scan because people kept bringing it back made pcs take 10-20 mins to bootup but eventually got rid
SimpleSi Posted May 11, 2012 Author Posted May 11, 2012 Shut everything down, check every PC, check every PC again, reconnect things slowly starting with your servers then bringing up one lab at a time. One that is done, pray it never comes back. Done that twice now so can't comprehend how fully patched machines with auto-run disabled that come up clean with virus sweeps can be re-infected but off to investigate shutting down task scheduler. (but why doesn't the av know about such things - where is it being re-created from?????) I can understand how something can spread if it exists but having trouble understanding how something is spreading without existing - where is the chicken (or the egg) hiding????? Of course, if I find anyone plugging in an infected pendrive, then you'll be reading about it on the 6 O'clock news! Simon
zag Posted May 11, 2012 Posted May 11, 2012 It doesn't really matter if the virus infects individual machines. The only way it spreads is through making an autorun.inf on a shared/mapped drive. Stop that and you stop the infection for good The file is hidden so you need to go onto the server to see it usually. I just made it a 0kb file and read only permissions for all.
ascott2 Posted May 11, 2012 Posted May 11, 2012 Take a look at the scheduled tasks on you machines. once it is in, whichever way it was, in my experience it tends to repropogate itself this way.
SimpleSi Posted May 11, 2012 Author Posted May 11, 2012 (edited) Could someone point me in the right direction to stop the task scheduler from running? I am assuming this is indeed the culprit as the 'ficker hasn't returned since Tuesday Simon Edited May 11, 2012 by SimpleSi
6Foot2 Posted May 11, 2012 Posted May 11, 2012 Doesnt sophos tell you the user account that triggered the quarantine?... On that point I have a question: I get on access notifications from the station/user account: User: Domain\Username Scan: On-access Machine: StationName File "E:\Other\Emulator\Console Emulator\Visual Boy Advanace\VisualBoyAdvance.exe" of controlled application 'Nintendo Gameboy / DS emulator' (of type Game) has been detected. I also get notifications from the station as follows: User: NT AUTHORITY\SYSTEM Scan: On-access Machine: StationName File "E:\autorun.inf" belongs to virus/spyware 'Mal/AutoInf-C'. File "E:\autorun.inf" belongs to virus/spyware 'Mal/AutoInf-C'. File "E:\autorun.inf" belongs to virus/spyware 'Mal/AutoInf-C'. My question is: How do these notifications differ and what triggers this notification and what triggers another? Thanks.
ZeroHour Posted May 12, 2012 Posted May 12, 2012 The system account one is caused when someone say plugs an infected stick in before logging on. Because no one is on sophos is using system account.
6Foot2 Posted May 12, 2012 Posted May 12, 2012 The system account one is caused when someone say plugs an infected stick in before logging on. Because no one is on sophos is using system account. I should have realised that myself. Makes sense now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now