- For individual users
- Instant access to solutions
- Ask your tech questions
- Start your 30-day Free Trial
Main Topics
Browse All TopicsHi experts
We have the conficker worm spreading through our network like wild fire and it is locking accounts constantly on our DC's. It is highly unlikely we will be able to take the network down to clean all infected machines or disable file and print sharing as it is a corporate network. All machines are patched and have Sophos AV installed. The virus is being quarantined and the accounts are being unlocked automatically to keep the users having access to shared resources. How do we determine the source and stop the spread to give us time at cleaning network clients, local and remote?
All help sincerely appreciated.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: xmachinePosted on 2009-02-26 at 07:09:10ID: 23745423
Hi,
com/downlo ad/4/a/3/4 a36c1ea-75 55- 4a88-98 ac-b0909cc 83c18/Wind ows2000-KB 958644-x86 -ENU.EXE
com/downlo ad/e/e/3/e e322649-7f 38- 4553-a2 6b-a2ac40a 0b205/Wind owsServer2 003-KB9586 44-x86- ENU .exe
com/downlo ad/4/f/a/4 fabe08e-53 58- 418b-81 dd-d503873 0b324/Wind owsXP-KB95 8644-x86-E NU.exe
com/downlo ad/d/c/0/d c047ab9-53 f8- 481c-8c 46-528b7f4 93fc1/Wind ows6.0-KB9 58644-x86. msu
ntent/en/u s/global/r emoval_too l/ threat_w riteups/Fi xDownadup. exe
com/en-us/ sysinterna ls/ bb89755 3.aspx) to import a text file that contains the infected machines and run it using a privileged account like a Windows domain admin.
m/products /networksc anner/)
nload/), and scan all machines using this plugin ID (34476) to check if they have MS08-067 patch installed or not. (BTW, you can use a different tool to check for the installed patch, but this just an example)
You came to the right place, you are not alone in this.
1) To start working, first you need to download the required patches + fix tool:
Windows 2000: http://download.microsoft.
Windows 2003: http://download.microsoft.
Windows XP: http://download.microsoft.
Windows Vista SP0 + SP1: http://download.microsoft.
Symantec FixDownadupTool: http://www.symantec.com/co
2) Create a shared folder on some server to contain the downloaded files (Apply Read-only permission for all users).
3) And you can use Psexec (http://technet.microsoft.
4) In the batch file, you should replace the server name and shared folder name.
so, for example (run this as domain administrator):
c:\psexec @infected.txt -d -c Clean-Downadup.bat
infected.txt should contains one name/ip per line, like:
...
192.168.1.2
192.168.1.3
192.168.1.4
...
Use netscan to ping a range of IP's and save the results as a text file (http://www.softperfect.co
Another important points:
1) Review the current Passwords policy, you can configure a Windows GPO that will require a complex password, with a minimum number of characters.
2) Use Nessus (http://www.nessus.org/dow
A Symantec Certified Specialist @ your service
Select allOpen in new window