Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 15th, 2009, 06:23 PM
hankach hankach is offline
Regular Poster
 
Join Date: Nov 2004
Posts: 56
Default How to detect, kill and prevent conficker on a network?

Hello everybody,

After being infected i tried using the enigma conficker remover tool, which first cleaned my system, the problem is that after i got connected to a computer on the network or maybe having used a flash disk, the worm reappeared again on my computer as well as on other network computers and had regenerated under different (xxx.exe)

After the cleaning, my browsers are not connecting to internet no more , how can i fix that please?

What are the softwares to use in order to clean all network computers and prevent recent trojans and worms in the future, despite the use of spybot,super antispyware,NAV etc..

I appreciate very much your help to solve this problem .Thank you
  #2  
Old April 16th, 2009, 02:52 AM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: How to detect, kill and prevent conficker on a network?

hankach, perhaps you want to check out this Network Removal Tool, courtesy of EsoxLucius.

Also, read How to use the removal tools for Network administrators (scroll down the page a bit). Keep us posted.
  #3  
Old April 16th, 2009, 07:02 AM
hankach hankach is offline
Regular Poster
 
Join Date: Nov 2004
Posts: 56
Default Re: How to detect, kill and prevent conficker on a network?

i will check that and revert , what about the internet connection i cant connect to the internet should it work after using the tool?
  #4  
Old April 16th, 2009, 01:15 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: How to detect, kill and prevent conficker on a network?

hankach, the fact that conficker replicated itself could mean you still have it somewhere in the Network. Run the tool. If the Internet connection is still not there, please give more details about browsers, OS, your network, etc., so someone with that expertise can reply.
  #5  
Old April 17th, 2009, 04:23 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,417
Default Re: How to detect, kill and prevent conficker on a network?

I'll address only the third item: prevention.

Patch your systems.
Use basic firewall.
Don't let users execute random crap on their machines.
Optionally disable autorun feature on removable drives.

Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #6  
Old April 17th, 2009, 04:32 AM
EASTER's Avatar
EASTER EASTER is online now
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,501
Default Re: How to detect, kill and prevent conficker on a network?

Sound Advice.

Time for users to realize that on the networks they are walking thru some bad neighborhoods along the way, and all it takes is a some real threat hurled your way to make you change your paths to a more safe and less aggressive one.
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit, O/S (UEFI/GPT) Secure Boot
  #7  
Old April 17th, 2009, 07:57 AM
hankach hankach is offline
Regular Poster
 
Join Date: Nov 2004
Posts: 56
Default Re: How to detect, kill and prevent conficker on a network?

Guys thank you all for your concern and advices!

The connection worked after cleaning using Windows malicious removal tool.

Can anyone please advice if it's normal to have 8 svchost.exe running in my processes by System,Local service and network service?? cause i've read somewhere it could be caused by conficker, if so how to fix it ?

Thank you again !
  #8  
Old April 17th, 2009, 08:50 AM
EsoxLucius's Avatar
EsoxLucius EsoxLucius is offline
Regular Poster
 
Join Date: Oct 2006
Location: Bucharest, Romania
Posts: 125
Default Re: How to detect, kill and prevent conficker on a network?

Quote:
Originally Posted by JRViejo
hankach, perhaps you want to check out this Network Removal Tool, courtesy of EsoxLucius.

Also, read How to use the removal tools for Network administrators (scroll down the page a bit). Keep us posted.

It's not courtesy to me it's courtesy to BitDefender, I'm just bringing some news and tools when necessary.

@hankach

Did you use the network tool from bitdefender or something else? The fact the connection isn't available could also occur because of this tool. After cleaning you should always restart, even if you don't have conficker infections.
__________________
Protected by: BitDefender Antivirus and Firefox 3.0.10
  #9  
Old April 17th, 2009, 12:35 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: How to detect, kill and prevent conficker on a network?

Quote:
Originally Posted by EsoxLucius
It's not courtesy to me it's courtesy to BitDefender, I'm just bringing some news and tools when necessary.
And that's why I gave you the credit! Thank you for sharing knowledge.
  #10  
Old April 18th, 2009, 12:34 PM
hankach hankach is offline
Regular Poster
 
Join Date: Nov 2004
Posts: 56
Default Re: How to detect, kill and prevent conficker on a network?

How can i fix the 8 svchost.exe running in my processes by System,Local service and network service ?

Should i post a new thread subject ?

I appreciate your help on that!
  #11  
Old April 18th, 2009, 01:31 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: How to detect, kill and prevent conficker on a network?

hankach, just because you have 8 svchost.exe's running, does not mean they are nefarious in any way. I have 9 running in my PC at the moment and they are all legit.

Using Process Explorer, you'll be able to see the relationship of each individual svchost to a service in your PC.

This article: What is svchost.exe And Why Is It Running? might aid you in understanding what they are all about. Hope this helps.
  #12  
Old April 20th, 2009, 06:05 AM
hankach hankach is offline
Regular Poster
 
Join Date: Nov 2004
Posts: 56
Default Re: How to detect, kill and prevent conficker on a network?

I thought it worth to worry about , thank you much for your assistance!
  #13  
Old April 20th, 2009, 01:25 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: How to detect, kill and prevent conficker on a network?

hankach, you are welcome! Keep using Process Explorer to check on those svchosts from time to time. Take care.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:53 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums