Results 1 to 7 of 7

Thread: Cannot get rid of Conficker on company network

  1. #1
    Registered+
    Join Date
    Nov 2008
    Posts
    74
    Thanks
    11
    Thanked
    2 times in 2 posts

    Cannot get rid of Conficker on company network

    Hi Guys

    We got a network of about 30 PC's most on XP SP2, 1 win2k and couple of win2k servers, all patched MS08-67 and all running trend officescan, we've also got a SBS 2003 server again patched, the problem is trend officescan keeps sending us alerts on different machines saying downadup detected cannot clean so it quarantines it.
    I cant put SP3 on the machines as the IT manager doesn't want any big changes as in service packs yet.

    The SBS server also keeps getting alerts once every couple of days, the virus is normally found in "temporary internet files", I dont understand how its getting thru as its patched now and also no weak passwords, we've ran several tools including symentec which scans the system and confirms the virus has been removed and no infections but then it comes back from somewhere which trend detects again and removes, trend doesnt display the source IP address unfortunately!

    I'm at a bit of a loss, any ideas appreciated!

  2. #2
    HEXUS.social member Agent's Avatar
    Join Date
    Jul 2003
    Location
    Internet
    Posts
    19,185
    Thanks
    738
    Thanked
    1,609 times in 1,048 posts

    Re: Cannot get rid of Conficker on company network

    Probably an obvious one, but did you turn off system restore when doing this? All sorts of nastys can hide there
    Quote Originally Posted by Saracen View Post
    And by trying to force me to like small pants, they've alienated me.

  3. #3
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: Cannot get rid of Conficker on company network

    A system won't be magically permanently cleaned because of one detected infected file being deleted and the infection vector (MS08-067) being disabed.

    Check scheduled tasks.
    Check the "at" command via the command prompt.
    Check for processes started via rundll32.exe.

    Even if, for example, PC2 is 100&#37; patched, if the user of PC1 can run to the c$ share of PC2 and copy a file, then PC2 will get a Conficker binary and several scheduled tasks to run the copied .exe at a later time. This gets MUCH worse if a domain admin or server becomes infected....

    My sledgehamemer solution: deny all incoming network connections via GPO (local security policy->user rights assignment->access this computer from the network->add "Everyone" to it)

    To see which PCs are trying to log on multiple times, enable audit logging on one PC and watch a few hundred attempts from infected PCs to log on with various common administrator accounts. Sometimes it just tries to log on a few times with the currently logged on user of the currently infected PC.

  4. #4
    Senior Member
    Join Date
    Sep 2008
    Location
    UK
    Posts
    302
    Thanks
    3
    Thanked
    18 times in 18 posts
    • synaesthesia's system
      • Motherboard:
      • MSI Z77MA-G45
      • CPU:
      • Intel Core i5 3570K
      • Memory:
      • GSkill RipjawX 2133Mhz 8GB
      • Storage:
      • 128GB Samsung 830/2 x 2TB WD Black
      • Graphics card(s):
      • AMD Radeon 6870
      • PSU:
      • Silverstone 750w Modular
      • Case:
      • Corsair Carbide 200R
      • Operating System:
      • Windows 7 RC1
      • Monitor(s):
      • Samsung 245B 24" TFT
      • Internet:
      • 16Mbit DSL

    Re: Cannot get rid of Conficker on company network

    Since its only 30 odd machines, schedule a day's downtime (or half if you're feeling nippy).

    Download a couple of items:

    1. Sophos's Conficker Cleaner tool ( http://www.sophos.com/support/cleaners/scct_10_sfx.exe )
    2. Malwarebytes Anti Malware package ( http://www.malwarebytes.org/ )

    Copy them to each machine locally over the network (or use a USB pen you can destroy/disinfect later)

    Disconnect the network. Everything.

    Starting from the server, manually run the above two tools and disinfect the lot as you see fit (one at a time, multiple machines at a time). If one or both tools refuse to run or strangely don't start as a result of the infection, just rename the tool (i.e. if you cant install Malwarebytes, rename mbamsetup.exe or whatever its called to fluffy.exe. Install, and after installation go into the program files folder and rename mbam.exe to whatever.exe too. Hey presto, it'll run)
    Malwarebytes is capable of removing conficker entirely on it's own, however I'd suggest playing safe and running the Sophos removal tool first, then Malwarebytes as a "mop up" afterwards.

    Find a standalone machine (laptop is ideal) that you wont mind losing the data from. Get EVERYONE's USB pen, stick it in, copy the docs to the machine and format (fully) the pen. Copy docs back over to pen, hand back to owner.

    Only when you're absolutely sure everything is clean, you should be good to go. Use a standalone machine to clean and format the original USB pen use then blat the standalone.

    Long old process but preventing re-infection will be just as important as disinfection in the first place. Thankfully I've only had a couple of large sites (200-300 PC's) to unburden this infection from and the rest have been entirely isolatable due to security restrictions in place stopping the infection from actually doing anything other than being present.
    Moo.

  5. #5
    Senior Member
    Join Date
    Aug 2005
    Posts
    1,528
    Thanks
    18
    Thanked
    76 times in 63 posts
    • lodore's system
      • Motherboard:
      • X570 AORUS MASTER
      • CPU:
      • Amd Ryzen 5900x
      • Memory:
      • 32GB DDR4 2666 Mhz
      • Storage:
      • 1TB Gigabyte AORUS 7000s SSD and sandisk 1tb sata 3
      • Graphics card(s):
      • EVGA 1080TI 11gb
      • PSU:
      • Ion+ 860W
      • Case:
      • Corsair 4000D AIRFLOW
      • Operating System:
      • Windows 10 pro 64bit
      • Monitor(s):
      • Iiyama 34inch ultra wide quad HD 144hz and 24inch asus HD
      • Internet:
      • 80Mbps Zen

    Re: Cannot get rid of Conficker on company network


  6. #6
    Senior[ish] Member Singh400's Avatar
    Join Date
    Jun 2008
    Posts
    2,935
    Thanks
    136
    Thanked
    310 times in 247 posts

    Re: Cannot get rid of Conficker on company network

    Disconnect every machine from the network. Isolate every machine from one another. Then disinfect one by one.

  7. #7
    Registered+
    Join Date
    Nov 2008
    Posts
    74
    Thanks
    11
    Thanked
    2 times in 2 posts

    Re: Cannot get rid of Conficker on company network

    Thanks guys, I had a feeling I would have to do manual scans on each PC and was trying to avoid it, but has to be done.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Computer on network has lost connection to network
    By Furton in forum Networking and Broadband
    Replies: 9
    Last Post: 19-08-2011, 04:31 PM
  2. PCMCIA Network card in old laptop
    By pringle in forum Networking and Broadband
    Replies: 2
    Last Post: 17-08-2005, 01:18 PM
  3. Small Home Network Setup Problems
    By ToxicPanda in forum Help! Quick Relief From Tech Headaches
    Replies: 2
    Last Post: 08-09-2004, 11:36 PM
  4. Wired+Wireless home network purchasing recommendations...
    By D001 in forum Networking and Broadband
    Replies: 4
    Last Post: 01-09-2003, 11:03 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •