Jump to content

Recommended Posts

Posted

Hi,

 

I appear to have picked up the W32/Confick-E virus. Not entirely sure where from as the servers were all bang up to date with Windows Updates and Sophos Anti-Virus.

The Sophos website says to install the MS08-067 hotfix from Microsoft (which when I've checked was actually installed on my machines last year.) It then says to use Sophos to clean the virus.

Now I've tried doing this, I do a full Sophos scan, it picks the virus up, I perform a clean and it says clean successful. At this point a few services (such as the server service) are turned off (presumably to allow a proper clean) so I have to reboot. Upon reboot I run another scan and the virus is still there.

Is it possible that some of my desktop machines have the virus and are transmitting it back to the server when the server reboots and reconnects to the network?

If this is the case it looks like I may have to go round every PC and ensure they're all up to date with Updates and do a virus scan on them all.

Has anyone any experiences with this virus or have any suggestions?

 

Many thanks.

Posted
Yes. Along with the exploit referenced in MS08-067 Confick also spreads via UNC network shares, mapped drives and USB storage devices. I suggest you shut down your network and bring up machines one by one while isolated to perform a full cleanup. You also have to round up everyones USB storage devices (pen drives, music players, phones, etc) and inspect and clean those.
Posted

Further to everything Geoff has said, I'd recommend you download a tool specifically crated to remove this Worm such as this one by F-Secure.

 

ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip

 

As many on here point out, Sophos can be a pain in the neck when it comes to actually removing anything it finds.

 

Also turn off system restore on every workstation before scanning.

 

Do you get paid for overtime? :smash:

Posted
Hi,

 

Thanks for the prompt reply. Is it possible to get rid of this without shutting the network down (this isn't really an option at this moment in time)?

 

If you want to rid your network of it, no.

 

If the head kicks up a fuss, direct him towards the news stories about how many machines worldwide are affected, emphasizing the Sheffield teaching hospitals.

 

Good luck.

Posted
Also, if you can, try and identify the original source of the infection. As you say you have kept up with patching on your servers, it's likely that a USB flash drive is the cause. You may wish to review your proceedures and policies to prevent similar infections in future.
Posted

I get that. I was thinking more along the lines of doing it room by room, disconnecting each as I go. Then reconnecting them all at the end.

 

What's pissing me off is where it's come from and why Sophos didn't pick it up.

 

So my plan should basically be:

 

1) Disconnect the servers from the network.

2) Go round every PC and run the removal tool from above and also run Windows Update.

Posted

Most virus removal tools cannot get rid of the virus from some machines. We have Kaspersky on our network which picked up hacking attempts from machines which our AV and the removal tool showed as being clean. I came across these removal instructions online which has now erradicated the virus. You need to ensure that the random name in step 3 is definately the virus. I would recommend googling it before you delete it.

 

1. Install the Microsoft Patch for MS08-067.

 

2. Open Regedit and go to the following

 

HKLM>Software>Microsoft>Windows NT>CurrentVersion>svchost

 

3. In right hand pane double click on “netsvcs” and scroll down to the bottom line. There will be a random name such as rbydwcit. Make a note of this random name and delete the line of text.

 

4. Now go to

 

HKLM>System>controlset001>services>”virus name”(from step 3)>Parameters.

 

5. In right hand pane make a note of the dll which contains the virus.

 

Now delete the “virus name” key from the left hand pane.

 

6. Reboot to safe mode.

 

7. Delete the dll from step 5 found in c:\windows\system32\

Posted

Thanks for all the replies, I think Sophos does actually remove it, it's just as soon as it reconnects to the network it picks it back up again.

 

I did try what Trekmad said above but when I got to step 5 there wasn't actually a DLL named there.

 

Looks like it could be a late night for me. :mad:

Posted

Depending upon your network ....

 

Disconnect all uplinks to your servers so they are on their own.

 

Isolate the servers and run a scan across them, any detection of infection and my advice would be to flatten it and reinstall restoring files from a known good back up before infection.

 

Reimage if you can each room in turn (ensuring they don't boot into windows before booting from the imaging device (usb/cdrom/floppy etc). - Once this is done, the room can be live.

 

If you can't reimage for whatever reason then yes, isolate, scan, check, reconnect.

 

I can't see which area you're in but it might be worth calling in some help from neighbouring schools, many hands make light work and all.

 

Good luck.

Posted
We had a similar problem when i was relatively new to the education environment, and well the usb sticks was the hardest part to stop, so we simply stoped auto-run on everything and also put in software restrictions to stop the virus being run, also good idea for future is to always make sure you have decent permissions set on each share area like within are environment we have a common area which only admins can write directly into the path which stops spreading from other accounts.
Posted

Malwarebytes Anti Malware is a great little app that will entirely remove an infection from a machine, but if it's networked, as above you'll need to repeat the process on all machines. Install it, run it, job done.

 

Now, depending on the level of infection and the specific variation of that worm, you might not be able to run the installer let alone the program itself. Thankfully it's a bit "thick". Rename the mbam.exe installer file to "fluffy.exe"

 

Install.

 

Once installed, go to the installation folder (c:\program files\malwarebytes etc) and rename the EXE file to fluffy.exe. Update or make a new shortcut to that. It'll now run and you'll be able to murder the infection safely. You can of course choose any name you want, "fluffy" is just my preferred alternative name. Sometimes if it's a bad infection i like the name "moist.exe".

 

No reason. :)

Posted

Again thanks to all who replied. I couldn't do this tonight as there was something very important on that needed to use the network. I'm going to tackle it tomorrow.

 

The servers are detecting the virus (even though they were right up to date with Windows updates and anti virus). When I removed it with Sophos, the server service was stopped, I ran another virus scan straight away and nothing was detected, I rebooted in safe mode and ran another scan and nothing was detected again but as soon as I rebooted normally and was connected to the network it reappeared.

There's no way I'm flattening them, so need to remove.

Going to turn everything off tomorrow, go round each workstation and run the hotfix and a virus scan. Once I've done that I'll do the same on the servers and then re-connect everything.

I'll turn autorun off so USB sticks don't spread it and then will insist any sticks get brought to myself for a scan before use.

 

Is this Malwarebytes Anti Malware free? I've never heard of it, but I am willing to try anything that will make life easier.

 

Thanks again for everyones help.

Posted

Also another suggestion, Turn off the switches, just because there is always someone who either doesn't get the message about all the pcs need to be off etc because of the virus, that or someone always turns them back on thinking off i thought it just this one wouldn't make a difference. I'm sure we have all seen it before.

 

And ye Malwarebytes Anti Malware is free really nice program :)

Posted
Malwarebytes Anti Malware is a great little app that will entirely remove an infection from a machine, but if it's networked, as above you'll need to repeat the process on all machines. Install it, run it, job done.

 

Now, depending on the level of infection and the specific variation of that worm, you might not be able to run the installer let alone the program itself. Thankfully it's a bit "thick". Rename the mbam.exe installer file to "fluffy.exe"

 

Install.

 

Once installed, go to the installation folder (c:\program files\malwarebytes etc) and rename the EXE file to fluffy.exe. Update or make a new shortcut to that. It'll now run and you'll be able to murder the infection safely. You can of course choose any name you want, "fluffy" is just my preferred alternative name. Sometimes if it's a bad infection i like the name "moist.exe".

 

No reason. :)

 

Me thinks Siggy Fraud would have a field day with you. :D

 

To the OP, yes Malwarebytes Anti-Malware is free (though paid for versions are available) and should be a firm part of your arsenal. It's got me out of quite a few sticky issues.

Posted

and probably anyone who typos his name :rolleyes: *freud

 

if you were to packet sniff your connection as you join the network it might be possible to see where the infection is coming from. Of course it could be all over the place....

Posted

Yeah it's free in it's basic "run and disinfect" form - there is a paid version which runs in the background keeping a constant eye but the former will be sufficient for your needs.

I tend to be very wary of most anti spyware programs esepcially if it's one I've not heard of, as there's a stupid amount of fake ones out there which are malware in their own right. Did one infection of Conficker yesterday which the laptops owner decided to try and correct himself by downloading something called XoftSpySE which is malicious software itself, more than doubling the original problem :)

 

Ah, edit : looks like a few people pipped me to the post on that one. But to expand on browolf's point about packet sniffing, Ethereal is a great app for that.

Posted
The removal tool that was mentioned (from f-secure) works well to detect and remove this thing...however be really careful about running it on the servers. We used on a server hoping it would disinfect -> reboot -> done.....well we rebooted the server and it didn't come back up. Seems this tool sometimes corrupts the boot record and other windows essentials. Haven't had any issues with desktop removals though....
Posted

Would be worth checking but I doubt that's the fault of the tool, more likely that an "important" file(s) was infected and the tool wiped it for clean. Restore from back up the files pre infection, or repair the installation yourself and it should work.

 

Mind you, once infected, I'd never trust a device again until it's been formatted.

Posted

I'm not the only paranoid one then, thank god for that! :D

 

On the positive side real viruses are very rare these days, I've not had a viral infection to deal with in years - it's mostly all worms, spy/adware. Conficker is definitely the worst infection of it's type for a long time and I've certainly had to deal with more infections of that than Sasser a few years ago. Trouble is with this one it's leaving entire networks wide open for abuse and there's a niggling doubt that once an infections taken hold it'd be near impossible to entirely get rid without an entire network rebuild. I'm just thankful the only one I've had to deal with in a school was a standalone machine.

Posted

i'll second the thought of turning switches off.

at my old school we had a virus (cant remember its name) that spread via unc so the moment any pc came online it was infected again. we asked for all machines to stay off and then found one teacher 'had' to get those documents from the shared area.

get all tools needed on to a usb stick or external hdd, down the switches, then work round the rooms. and dont be tempted once a room is clean to turn that switch back on, it only needs one usb stick to re-infect and start from scratch. once EVERY machine is clean, then get the switches online, preferably leaving half an hour between turn on of each to check that nothing is resurfacing.

good luck with this, i feel your pain!

Posted

Had this last week at one site.

 

You must shut down the network - no arguments everything.

The servers that are infected simply shutdown services and are useless anyway, so turn them off or unplug them until cleaned.

 

Patch them first, run the MSRT to isolate/clean the infection.

Make sure you have a working and updated AV solution.

If you are using Sophos - (there is nothing wrong with it, if it's not working for you, then look in the mirror and blame the first person you see!) make sure your servers are set for on access scanning read/write.

 

Set the Default Domain Policy to disable Autorun on all drives!!!

Run a full scan on your server and keep the on access scanning turned on for a week at least!

 

Then start on all of your administrative level access systems.

Technician accounts, workstations that run with local administrator or power user rights... Patches, MSRT AV updates.

If you run WSUS and have a healthy AV system the chances are the impact will be minimal but USB device usage in schools so liberally policed the risk of infection is high.

 

In my case the culprit was a workstation used by the Network Administrator logged in as himself a user with Full Admin Rights!

 

His own PC was out of date with it's patches and the AV was not configured to clean an infection, not that it would have helped much as that was out of date too! - AVG Pro!!

He had foolishly used his administrative workstation to inspect a suspected defective USB stick, it must of had at least 18 - 24 hrs head start to get a hold on the network.

 

11 Hrs from 1st detection to site cleaned.

I know that other schools in the same LEA that refuse to shutdown were still trying to clean it 4 days later!

 

Same old dog, with new tricks. Clever Confiker!

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...