Question

HELP!! Confliker attack?

Asked by: jhaff

we had an outbreak on campus today, all the clients with symantec endpoint protection installed started getting pop-ups saying it found the downadup.b virus and it was cleaned by deletion, although, the pop ups never ceased!  we also got notification that endpoint was blocking traffic from certain ip's on and around campus.

At this point the virus had spread all across campus.  i enabled windows firewall on our client machines via group policy to stop replication, but my servers are infected!  i ran the removal tool, ran microsofts patch (again, i think) and all seemed to be fine, i could get to windows update, symantec sites, etc.  but when i went to check on my servers again, i was unable to get to symantecs site or windows update... characteristics of the worm returned!

This is the strange part.  Our xp machines have already had the microsoft patch installed, why are my machines getting infected?  and my servers??  after removal and patch, the virus came back?!?

is it a possible variant?  anyone seen this before?  any help would be much appreciated.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-23 at 17:17:34ID24756986
Tags

confliker

,

downadup.b

,

windows xp

,

windows server 2003

,

windows server 2008

Topics

Windows XP Operating System

,

Enterprise Anti-Virus

,

Windows Network Security

Participating Experts
3
Points
500
Comments
13

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Virus infection
    I am running windows 2000 pro. on my machine and the file tskmgr32.exe (Task Manager) is infected with the w32.HLLW.Lolol virus ... i cant remove it !! i delete it but it comes back how do i replace the file with a new copy?? its a critical file for windows how do i go about ...
  2. Help, W32.NIMDA.E@mm (dr) attack !
    My PC (a stand alone machine with Win2000 Pro and IIS installed) has been recently attacked by W32.NIMDA.E@mm (dr) and js.Trojan.WindowBomb. These two viruses were found by Norton Antivirus2002 that I have installed after the attack (files infected: D:\Inetpub\Scripts\TFTp1...
  3. Infected with W32.Sasser.B.Worm..PLSSSSS HELP
    Hi, My computer is infected with the Sasser.B Worm. When infected the computer slows down...Moving from application to application is slow.. Boot and Logins are painfully slow. *** I ran the Symantec Fix tool a couple of times in the last week [yes i turned off the System ...
  4. big infection?
    Hi guys, I have a little big problem on many PC's of my office. It's difficult to exactly explain what happens but I try to ask your help. I find in winnt directory (windows 2000 professional) a file named as random sequence of characters .exe, that is started on windows boot...
  5. Fast Spreading infection, Unknown to all Virus, Spyware…
    We have an environment that quickly had a "Malware" infection. Sympton is Internet Explorer Tab reads: "Fuck Th3 W0rld!" and it is injected into the source code of every Java enabled Website. We cannot clean nor find the source of the spreading. Here is...
  6. Computers infected with Virus
    my servers are infected with a virus called w32.sality.ae according symantec endpoint protection and win32/heur or win32/Tanatos.m according to AVG. we have used avg enterprise edition for the longest time it has worked . recently our server and computers got attacked and ev...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: alienvoicePosted on 2009-09-23 at 17:20:43ID: 25409269

To check if it is a conficker infection go to this link and click on 'check for infection'. Can determine if your infected/what type of infection variant of conflicker you have.

http://www.confickerworkinggroup.org/wiki/

 

by: alienvoicePosted on 2009-09-23 at 17:21:41ID: 25409279

Once  you know what it is/which variant, you'll be in a better position to determine how it is spreading and how to prevent it.

 

by: jayasankerPosted on 2009-09-23 at 17:23:35ID: 25409294

how many pc's you have in network, how many machine's displaying the message?/ if it's single pc, try switch of the pc and on check

 

by: jhaffPosted on 2009-09-23 at 17:41:22ID: 25409377

it is definitely confiker a/b variant.  your test confirms it, as did endpoint protection...  why can't i remove it from our systems?

 

by: alienvoicePosted on 2009-09-23 at 17:45:35ID: 25409406

Conflicker in general very difficult to remove in the best of circumstances. Problem with Confilcker it can be 'upgraded' to later version of the virus by the authors when the infected computer 'reports back' to the servers conflicker upgrades from.

Best site to help you with this is the Conficker Work Group.

Repair tools are list on their site with the link below.

http://www.confickerworkinggroup.org/wiki/pmwiki.php/ANY/RepairTools

I've had a 50% success rate in removing the virus without re-infection. But they were isolated PCs I was able to remove from the network. Other 50% I ended up formatting because I wasnt 100% sure they were conflicker free.

 

by: jhaffPosted on 2009-09-23 at 20:34:42ID: 25409914

we currently do not have av software on our servers... in the past it ended up being a pain in the neck.  at this point it seems absolutely necessary, due to the fact that i keep removing the virus, everything checks out ok for all of an hour and then returns...even with the microsoft patch installed.  I thought the patch was supposed to prevent future exploits?

any av software you could recommend?  we currently use symantec endpoint protection on our clients, is that safe to install on the servers?

 

by: alienvoicePosted on 2009-09-23 at 20:43:42ID: 25409934

I've had a little experience with Symantec, found it a bit hungry on the resources when installed on the servers, but it did work quite well nonetheless.

Personally we use Trendmicro for our AV on our servers and in another location we use Sophos antivirus.

http://www.trendmicro.com.au/au/products/enterprise/neatsuite/index.html

http://www.sophos.com/products/small-business/

Hope this helps.

Symantec is still reputable antivires software. Do you have a licensing agreement with them for your servers?

 

by: jayasankerPosted on 2009-09-23 at 21:52:36ID: 25410164

you are taking very risk by not installing AV!!
i was using Norton corporate edition before, but i changed to ESET now,  but if you have certain budget limitation you can try with corporate edition  or SEP

there was lots of reviews and were suggesting NOD32

check this

http://forums.cnet.com/5208-6122_102-0.html?threadID=7785

http://www.hardforum.com/archive/index.php/t-972653.html

http://www.pcmag.com/article2/0,2817,978452,00.asp

 

by: JonveePosted on 2009-09-24 at 00:40:00ID: 25410804

The infection does appear rather difficult to remove, but this tool has been described
as the only tool that can really remove it >

"Remove Downadup from infected computers":
http://www.bdtools.net/

Another option is the Conficker Removal Tool:
http://www.sophos.com/products/free-tools/conficker-removal-tool.html

 

by: JonveePosted on 2009-09-24 at 00:55:04ID: 25410895

Ah, there was a previous case with an 'accepted solution' at E_E in August, where the second option above was used with success.
Please scroll to the comment by "demazter" which suggested this was the best tool for dealing with Conficker > 
http://www.sophos.com/products/free-tools/conficker-removal-tool.html

You'll probably wish to study his successful Group Policy used to stop it spreading.  It's attached with appropriate comments >

"How to remove WORM/Conficker.M from network and cure the symptoms caused by it?":
http://www.experts-exchange.com/Virus_and_Spyware/Latest_Threats/Q_24615864.html

 

by: JonveePosted on 2009-09-24 at 01:00:40ID: 25410919

Note that "demazter" also refers to disabling the Task Scheduler, to stop Conficker from spreading.

 

by: jhaffPosted on 2009-09-28 at 19:27:30ID: 31632774

What a pain.  apparently, the infection was able to update itself and replicate across our domain in hours... at least to the machines without symantec installed.  we had our machines patched for this outbreak in march, but obviously still prone to attack in september.  

it wreaked havoc!  locked out accounts, killed our file servers' rpc service which then killed file sharing, logons would take 10 minutes due to the amount of failed auth. attempts on our dc's.  the only way to truly get rid of the damn thing was to install av software on EVERY machine.  we were able to contain and rid ourselves of the bugger this afternoon.

although, they have their short comings, symantec's endpoint protection really did the trick.  the central management/deployment (although deployment was a bit tricky on a domain like ours...) made it relatively easy to get out to and report on  the clients.  some of the legacy machines on campus are a bit sluggish at startup, but relatively the same.  and the unmanaged client on the servers is nice because it adds the appropriate exclusions at install.  

lesson learned: install av software on your machines

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...