Jump to content

Recommended Posts

Posted

i had it pop back up last week, first indication was that machines with av installed where poping up with alerts saying that the av had detected the virus dropped in the system 32 folder.

 

okay first thing i did was ensure account lockout was turned on, (default domain policy/security settings/account something settings)

 

watch the domain controller logs for account lockout events, they tell you which machine is causing the lockout, if there are 100's from the same machine and its 3am you can be pretty sure its conficker. so most of my machines were protected they had the ms patch installed and av installed and the av was catching it on being dropped on those machines, i just had actually two machines one was an old laptop that had probably been at someones house for ages and the second was a test machine someone had setup and not installed av on, so i basically just nuked them by deleting hal.dll and ntoskrnl.exe via the admin share and shutdown -f -r -t 0 -m \\COMPUTER

 

i'm pretty sure the laptop got brought in and then infected the second machine.

 

any technicians no longer have domain admin rights, spent a lot of time delegating very specific permissions after this as the test machine was left logged in as an admin.

Posted

Thanks for all the advice - I understand about 50% of it (as I'm not a domain padawan) and can implement about 20% of what I understand :(

 

Can I try some simple questions please?

 

Assuming all machines off network and server declared clean and I log on as local admin to the first computer (not net connected) and only finds 1 instance now in c:\windows\system32 - I sweep again - nothing found - I join it to the network,log on as local admin and make sure its fully windows updated (Which it was).

 

1. Do I need to find some manual patches or can I rely on MrGates company to have supplied everything and not holding something back in the "techs only" store?

 

If I now do another machine the same way

 

2. Can Conf*cker resurrect itself out of seemingly nowhere?

 

Si

Posted

 

Assuming all machines off network and server declared clean and I log on as local admin to the first computer (not net connected) and only finds 1 instance now in c:\windows\system32 - I sweep again - nothing found - I join it to the network,log on as local admin and make sure its fully windows updated (Which it was).

 

1. Do I need to find some manual patches or can I rely on MrGates company to have supplied everything and not holding something back in the "techs only" store?

 

do you have wsus? and is the patch approved, is wsus working the patch number is earlier in the thread. and no you can't rely on bill gates :) or m$ you need antivirus software, i'm using trend and its very good we basically didn't have any problems on any machines with trend installed, it only appeared to because they were actually catching the virus as soon as it was dropped on the machine

 

2. Can Conf*cker resurrect itself out of seemingly nowhere?

no

it ressurects itself from someone bringing itself in again on a memory stick (and that point of entry not being secure, ie. pants antivirus and not patched) or not all machines being cleaned in the first place.

Posted

@oxide54 - lets keep this simple says si :)

 

If I take a machine,connect it to the internet and use Windows Update till nothing more is downloaded - will the machine by fully patched? (I think it will and I don't think I then need to manually apply anything but this where I stand to be corrected :) )

 

Si

Posted
@oxide54 - lets keep this simple says si :)

 

If I take a machine,connect it to the internet and use Windows Update till nothing more is downloaded - will the machine by fully patched? (I think it will and I don't think I then need to manually apply anything but this where I stand to be corrected :) )

 

Si

 

if its using windows update and not wsus then it should be, but there is the possibility that the someone refused windows installing the update. (i'm not 100% on this as i don't use windows update directly)

 

I know I keep this but you still need av as well as the patch.

 

i'm pretty sure its this patch.

MS08-067: Vulnerability in Server service could allow remote code execution

 

you should also be able to check it is installed by going to add/remove programs and ticking "show updates" and look for 958644

--------------------------------------------

the patch only prevents the exploit in the windows server service, it won't help you with machines that are already compromised and have gained access to admin credentials, this is what makes this virus a bit of a pig because it exploits more than one method to infect machines.

Posted

@oxide54 - I'm talking about me doing this manually on each machine - I just wanted to check the thought process that a fully Windows Updated machine == to a fully patched machine and that there is no need to check to see if individual patches have been installed.

 

And I did think I didn't need to agree that I needed av as well :)

 

My basic driving force on this one is that either the 'f*cker can spotaneously re-combust on its own and therefore I'm doomed

 

or

 

It can't do that then I haven't cleaned and the machines sufficiently and I need shooting

 

or

 

They is another mode of re-infection involving another sort of f*cker of the person variety that doesn't understand what is going to happen to them when I find them! :)

 

At the moment we've only been running with the classroom teacher machines and 6 laptops and the library computer - all others have had their network cables and mains leads removed and the other (older) laptops are in a cupboard wired with 11KV on the handles. :)

 

Si

Posted

Well, I've returned this week and no sign of cnf*cker on any machine that I've looked at so far but why not his week when it re-appeared last week ?????

Si

Posted

This has just popped up our on EIS grid list from another School - similar issue.

 

As always once I see a scare in another school I do some checks, make sure EPO is fully updated and deploying to all clients and windows updates on any machines I can check.

 

We have not had a virus here since the Blaster/Welcha? first came out years ago - oh what a nightmare that was (worst thing was my colleague refused to admit that we had a problem). After spending ages making sure every PC was updated etc we managed to get rid of it.

@SimpleSi

You could find a PC updated it self or worse the infected machine has been switched off and not turned on. Once that is turned on BAM :(

Posted

Well - good news and bad news - good news is still hasn't returned again since last weeks re-surfacing - bad news is I still don't know how/why it resurfaced (and then went again)???? and....

 

.... the schools just got the OFSTED call 15 mins ago (coming on Monday) so I'll be camped out there till next Tuesday with a large hammer in my back pocket to hit it on the head if I see any sign of it!

 

Si

Posted
Well - good news and bad news - good news is still hasn't returned again since last weeks re-surfacing - bad news is I still don't know how/why it resurfaced (and then went again)???? and....

 

.... the schools just got the OFSTED call 15 mins ago (coming on Monday) so I'll be camped out there till next Tuesday with a large hammer in my back pocket to hit it on the head if I see any sign of it!

 

Si

 

Last network when I got this returning was fixed when we found a home laptop that a staff member had connected thenselves for music and internet......

Posted
when we found a home laptop that a staff member had connected thenselves for music and internet......

Well if it is something like that, then the member of staff concerned here has the sense to be lying low now!

 

And unless its on a 2 week break, cnf*cker's not been back again :)

 

Si

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...