Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Stay Abreast

Updated: 22 May 2010 | 14 comments
Sandeep Cheema's picture
+5 5 Votes
Login to vote

Just to keep everyone upto date, Today’s topics on full-disclosure include a conficker scanner for the network.

Reference: http://security.bkis.vn/?p=560

It's developed by BKIS, The same group who had found out the vulnerability against chrome some time back amongst others

Comments

Symantec World's picture
21
Apr
2009
2 Votes -2
Login to vote

Re

Thanks Sandeep after spreading downadup to whole world this could be a very helpfull for all.

Regards, M.R

Tejas Shah's picture
21
Apr
2009
0 Votes 0
Login to vote

We get scared on downloading

We get scared on downloading any software from internet, especially on the corporate network. Thogh Sandeep's name tag suggest he is a Trusted Advisor. However my point is not refering to his suggestion. I need a best practice in general.

Can someone suggest, how?

SAM_SHAIKH's picture
21
Apr
2009
1 Vote +1
Login to vote

Hi, Good one sandeep, but

Hi,

Good one sandeep, but "eeye retina" also publish such tools wherein you can detect which machines are infected and which machines are having MS08-067 Vulnerability.

Rgrds,
SAM

Sandeep Cheema's picture
21
Apr
2009
1 Vote +1
Login to vote

Quite possible

Yeah, There are ways with Nmap as well to remotely detect the conficker worm
http://insecure.org/#conficker

De facto when AV does something, it starts jumping up and down, waving its arms, and shouting "Hey!  I found a virus!  Look at me!  I'm soooo goooood!"

Sapta's picture
21
Apr
2009
1 Vote +1
Login to vote

hi sandeep,

hi sandeep this is really a good one, very helpful...

Vikram Kumar-SAV to SEP's picture
21
Apr
2009
6 Votes +6
Login to vote

Microsoft has its own way..

I guess this should be the best one.

This is a MS-KB on the removal process/best practice of w32.downadup.B

http://support.microsoft.com/kb/962007

Enabling debug logging for the Net Logon service

http://support.microsoft.com/kb/109626

MS Account Lockout Tools

http://www.microsoft.com/downloads/details.aspx?Fa...

MS08-67 patch download [KB 958644]

http://www.microsoft.com/technet/security/Bulletin...

Disable Auto play with GPO

http://support.microsoft.com/kb/953252

Disable Scheduled Tasks with GPO

http://support.microsoft.com/kb/310208

Enable Security Auditing with GPO

http://support.microsoft.com/kb/300549

Once you have Enable Debugging for Netlogon Service you will be able to see which clients are attacking.
Once the source is found it can be remidiated and cleaned.

By disabling Scheduled Task Service
We can stop Downadup from spreading .As it created Schduled Jobs and spread across the network.

Disable autoplay
That is the most important for every worm

binayak's picture
21
Apr
2009
1 Vote +1
Login to vote

Good

Good one Sandeep

Tejas Shah's picture
04
May
2009
0 Votes 0
Login to vote

How to disable Auto Play?

How to disable Auto Play?

Paul Mapacpac's picture
04
May
2009
0 Votes 0
Login to vote

Re

Hi Tejas, pls check SAV to SEP's post.

Nel Ramos's picture
05
May
2009
0 Votes 0
Login to vote

Nice one Sandeep. @SAV to

Nice one Sandeep.

@SAV to SEP: Great references.
Disabling autoplay really did it.
thanks.

Nel Ramos

ShadowsPapa's picture
05
May
2009
0 Votes 0
Login to vote

I used GPO to disable

I used GPO to disable autoplay and used SEP to block access to any autoplay.inf file. Nothing at all can possibly start automatically around here. of course most important is the MS patches!
Doesn't help much to have a guard dog if you leave all the windows and doors on a 3 story house wide open at night.

Nel Ramos's picture
06
May
2009
0 Votes 0
Login to vote

@ShadowsPapa: Definitely

@ShadowsPapa: Definitely agree with you on that.
By the way is there a method to disable USB devices and not disabling USB KB and mouse?
Made a test environment and USB was successfully blocked on the specific client.
the problem is the mouse was also disabled.
thanks.  

Nel Ramos

Sandeep Cheema's picture
06
May
2009
0 Votes 0
Login to vote
Nel Ramos's picture
07
May
2009
0 Votes 0
Login to vote

@Sandeep Cheema: Nice... Now

@Sandeep Cheema: Nice... Now I have something to play in the test area... you are a life saver friend... thanks!

Nel Ramos