?
Solved

Windows AD accounts are looked out

Posted on 2010-03-29
6
Medium Priority
?
3,133 Views
Last Modified: 2013-11-22
Hi,
There are lots of machines are infected by a virus/worm in our company, an antivirus pop-up message says: please reboot your machine to complete removing the viruses. After reboot the machine, user can log on and a pop-up message says “your account has been locked out".

Another problem is one of two domain controllers is producing lots TCP traffic (source port 139, destination IP is 172.16.11.x, destination port TCP 2xxx~32xxx) which has been blocked by our firewall. I have run our antivirus software and Malwarebytes' Anti-Malware on this domain controller (win2k3), and removed two virus infected files (one is WORM_DOWNAD.AD and another is MAl_DownadJ). The problem remains after reboot (lots traffic from this controller).

On some machines, users are unable to map any network drives, pop-up message says “can not access the network path..."

Is there anyone be able to tell us "How to" fix these problems.

Many thanks in advance.

Regards

John
0
Comment
Question by:mbsadmin1
6 Comments
 

Author Comment

by:mbsadmin1
ID: 29051498
Sorry, I should say: user can't log on and a pop-up message says “your account has been locked out".
0
 
LVL 20

Accepted Solution

by:
jimmymcp02 earned 2000 total points
ID: 29106002
That looks like the Conficker virus
You might want to take a look at the following article
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?vname=WORM_DOWNAD.AD 
0
 
LVL 24

Expert Comment

by:Mohammed Hamada
ID: 29124532
Jimmy is right,
Try using the following removal, If it detects it you will have to do several reboots for the infected systems as conficker involves it self in system services that should be rebooted to be uninstalled.

http://download.cnet.com/Conficker-Removal-Tool/3000-2239_4-10911447.html
GL
0
The new generation of project management tools

With monday.com’s project management tool, you can see what everyone on your team is working in a single glance. Its intuitive dashboards are customizable, so you can create systems that work for you.

 
LVL 3

Expert Comment

by:sb7785
ID: 29346625
In addition to the other great suggestions posted; if they all fail, try creating a bootable antivirus CD. If that doesn't fix it, then you've got some serious problems. It's always good to keep on hand at anytime:
http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/Q_25347695.html 
http://www.experts-exchange.com/articles/Storage/Misc/Creating-a-bootable-CD-USB.html
0
 

Author Closing Comment

by:mbsadmin1
ID: 31708731
Yes, the patch MS08-67 has fixed this issue.

Thanks.

Regards

John
0
 

Author Comment

by:mbsadmin1
ID: 30071262
Hi, all

Thanks for all your help, the patch MS08-67 has fixed this issue.

Thanks.

Regards
0

Featured Post

Take Control of Web Hosting For Your Clients

As a web developer or IT admin, successfully managing multiple client accounts can be challenging. In this webinar we will look at the tools provided by Media Temple and Plesk to make managing your clients’ hosting easier.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Curious about the latest ransomware attack? Check out our timeline of events surrounding the spread of this new virus along with tips on how to mitigate the damage.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

601 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question