Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Obliterating downadup from our network

Updated: 21 May 2010 | 9 comments
GarethRobson's picture
0 0 Votes
Login to vote
This issue has been solved. See solution.

Hi everyone,

In April, our network became infested by the downadup b worm. We took all measures that wer listed on the worms info site, and every computer and server on the network has the MS vulnerability patch on it. All computers are scanned daily, and random computers are still getting the worm appearing in the scans. The worm is removed from those computers, but then appear on a different computer another day. I thought the patch was supposed to stop the worm from spreading?

Comments

pbogu's picture
24
Nov
2009
0 Votes 0
Login to vote

you have some rogue machine

you have some rogue machine on your network, unpatched machione, or virus exists on USB

GarethRobson's picture
24
Nov
2009
0 Votes 0
Login to vote

what would be the best way to

what would be the best way to track down this machine using endpoint? We have 250 machines on our network and most are not accessible during work hours, so doing them all manually isnt a viable option.

Vikram Kumar-SAV to SEP's picture
24
Nov
2009
0 Votes 0
Login to vote

 https://www-secure.symantec.

 https://www-secure.symantec.com/connect/forums/w32downadup

Using IPS or Risk Tracer you can find the Unpatched system

GarethRobson's picture
24
Nov
2009
0 Votes 0
Login to vote

done that, found the main

done that, found the main attacker, but it is definately already patched...? What else could be allowing the worm to spread?

pete_4u2002's picture
24
Nov
2009
0 Votes 0
Login to vote

since it is a worm, there

since it is a worm, there could be another system in network that is spreading the infection

GarethRobson's picture
24
Nov
2009
0 Votes 0
Login to vote

but this is the computer that

but this is the computer that has been the source of 22 attacks in teh last couple of months, it has to be spreading it somehow.

Vikram Kumar-SAV to SEP's picture
24
Nov
2009
0 Votes 0
Login to vote

 1. Remove this computer from

 1. Remove this computer from network
2. Disable autorun on it.
3.Apply Rapid Release definitions and scan this machine in safe mode.
4. Clear out %temp% folder, C:\Windows\Temp and Temporary Internet Files ( or just delete all cookies,files etc..)
5. Enable SEP with all the features installed on it with latest Defs then connect it back to the network.

Aaed Alqarta's picture
14
Jan
2010
0 Votes 0
Login to vote

How to beat W32.Dowandup infections - Outbreak Scenario

Hi everyone,

I've been solving virus infection problems since a long time, and W32.Downadup has a complete chapter. I've added a new article called (How to beat W32.Dowandup infections - Outbreak Scenario)

https://www-secure.symantec.com/connect/articles/how-beat-w32downadup-infections-outbreak-scenario

If you have any comments/issues you are welcome to speak

 

Authorized Symantec Consultant - Symantec Certified Specialist - Experts-Exchange Certified Guru

Please don't forget to mark your thread solved

Davinci_uk's picture
14
Jan
2010
0 Votes 0
Login to vote

If you have found the 'main'

If you have found the 'main' machine - a clean/delete/removal may not be 'deep enough'  - still may be traces of it that can spawn again - you may need to rebuild the machine (drastic, but you will be sure it is clean) - if you have a PC build, should be straight forward enough?