Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

W32.Downadup.B: How could you find the source if there are 1k+ infected?

Updated: 25 Oct 2010 | 21 comments
Nel Ramos's picture
0 0 Votes
Login to vote

Hi Team,

How do you find the source of W32.Downadup.B in a Network of more than 1000 computers?

thanks...

Comments

Nel Ramos's picture
11
Mar
2010
0 Votes 0
Login to vote

Hi Team, Just for starters,

Hi Team,

Just for starters, W32Downadup.B virus infects just a small part of our network but had locked up many login Accounts. as in Many... this is because it tries to login as many login accounts in the office... good thing at 3 misses they account will no longer take retries but bad thing is the account is locked. 

Nel Ramos

Brian81's picture
11
Mar
2010
0 Votes 0
Login to vote

I used the risk log in SEPM

I used the risk log in SEPM to track it down. It will show the source. In my case, Conficker brute forced a domain admins password and tried to propagate using those credentials. When I saw the credentials being used on numerous machines, I knew that was the problem. Once the password was changed, the problem went away.

Nel Ramos's picture
11
Mar
2010
0 Votes 0
Login to vote

but for ours... the accounts

but for ours... the accounts keeps on being locked... because the virus again tries to login to them... how did you use SEPM? when did you see that it was the source? the first one?

Nel Ramos

AravindKM's picture
11
Mar
2010
0 Votes 0
Login to vote

Take the help of risk

Take the help of risk tracker
Refer this article
Worms and threats that spread across networks by network shares have become more common in recent years.--Like Downadup/Conficker 

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind

Mahesh Roja's picture
11
Mar
2010
0 Votes 0
Login to vote

Run Combo Fix

run Combo Fix And try to remove permanently

http://www.combofix.org/download.php

If this Info helps to resolve the issue please Mark as Solution

Thanks

VinodhRaj K's picture
11
Mar
2010
0 Votes 0
Login to vote

W32.Downadup is a worm that

W32.Downadup is a worm that spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability. SO applying the Microsoft patches is mandatory

Patches for Downadup(1 for RPC and another for IE)
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx

This virus copy itself in the recycle bin, uses scheduled jobs and autorun function to load the content in memory and infect the system. It also change the registry disabling the "show hidden files" function so the operating system itself is unable to show this file to the administrator and our antivirus is unable to detect the file.

How to proceed after applying the patches

1. Disable autorun(Reference: Microsoft KB)
http://support.microsoft.com/kb/953252

2. Temporarily Disable the "Server" and "Computer Browser" services (if possible)
Disabling the Computer Browser and Server service on the affected systems will help protect systems from remote attempts to exploit this vulnerability.

3. Temporarily Disable the "Task Scheduler" service
Disabling the "Task Scheduler" will help protect systems from local attempts to use scheduled tasks to copy infected files all over the network.

4. Disconnect the network drives/shares(Admin$ and C$)

Then install the latest available definitions from Symantec and run a full system scan on all the machines on the network to resolve the issue.

dvdmeer's picture
11
Mar
2010
0 Votes 0
Login to vote

If you have a corporate

If you have a corporate firewall, the sources can be traced from there as well, as the sources try to connect to the firewall ALOT.

You can also use the program  "eventcomb" to track down from which computer the accounts are locked.

Brian81's picture
17
Mar
2010
0 Votes 0
Login to vote

Yes, I do have risk tracer

Yes, I do have risk tracer on. And yes, I had to do some back tracking through the logs to see when it all started plus I have a good amount of notifications setup to warn me of outbreaks, etc. Then was able see in the risk log what the source username/pc it was coming from was. Because it was only 1 network account trying to propagate, I had them change their password as well as run the Conficker removal tool.

Mithun Sanghavi's picture
17
Mar
2010
1 Vote +1
Login to vote

Run Risk Tracer.

Hello,

What is Risk Tracer?

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Mithun Sanghavi's picture
17
Mar
2010
1 Vote +1
Login to vote

Try NMAP

Hello,

Incase, we don't have Network Threat Protection Installed on Machines, then we could try NMAP (http://insecure.org/)

NOTE: NMAP is not Supported by Symantec. However, have proved to be effective.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Nel Ramos's picture
17
Mar
2010
0 Votes 0
Login to vote

hi dvdmeer, Do you have a

hi dvdmeer,

Do you have a link where I could get a eventcomb?
Many thanks.

Nel Ramos

Nel Ramos's picture
17
Mar
2010
0 Votes 0
Login to vote

HI Brian81, How do you use

HI Brian81,

How do you use the risktracer?

could you possibly give me a link where I could download it.
Does it really gets who the source is and will I need to install this only to my PC or on all computers?

Thanks. 

 

Nel Ramos

Mithun Sanghavi's picture
17
Mar
2010
0 Votes 0
Login to vote

Hello..please check link

Hello Nel,

Please check the link provided above, the same would explain you all in regards to the Risk Tracer and NMAP.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Nel Ramos's picture
17
Mar
2010
0 Votes 0
Login to vote

Hi Mithun, How does an NMAP

Hi Mithun,

How does an NMAP works?
do I need to install this to all machines?
I will check on the other links provided by the others also.
But I sure need this to give me breathing room.
Viruses are getting too big to get attention from the IT Leaders here.
thanks. 

 
 

Nel Ramos

Mithun Sanghavi's picture
17
Mar
2010
0 Votes 0
Login to vote

Please check the link...

Hello Nel,

Please check the link provided above, the same would explain you all in regards to the Risk Tracer and NMAP.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Mithun Sanghavi's picture
17
Mar
2010
0 Votes 0
Login to vote

100% Assurance - complete Solution

Inaddition to this, Check the following link:

Best Practice for Downadup.B and Additional information on the same.

https://www-secure.symantec.com/connect/articles/best-practice-downadupb-and-additional-information-same

 

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo

Brian81's picture
18
Mar
2010
0 Votes 0
Login to vote

First, make sure it's

First, make sure it's enabled:

Then navigate to:

Now mind you, I had to do some back tracking thru the logs to see when the first attacks started. Once you find it, highlight the line and select "Details"

The details page will come up and show you the source of the attacks:

Nel Ramos's picture
29
Mar
2010
0 Votes 0
Login to vote

Thanks all for the kind

Thanks all for the kind feedback...
We shall check this... 

Nel Ramos

Nel Ramos's picture
29
Mar
2010
0 Votes 0
Login to vote

Is NMAP compliant over SAV

Is NMAP compliant over SAV 10.1?

Nel Ramos

mon_raralio's picture
23
Apr
2010
0 Votes 0
Login to vote

NMAP is a different software,

NMAP is a different software, it only checks for open ports and does not conflict with Symantec security products.

“Your most unhappy customers are your greatest source of learning.”

Ramji Iyyer's picture
23
Apr
2010
0 Votes 0
Login to vote

Do this !!!!

Install NTP on all the PC's
Do not use weak passwords.
Do not keep open sharing.
Export  NTP logs & check for event description :- [SID: 23179] MSRPC Server Service BO detected.  Traffic has been blocked from this application: C:\WINDOWS\system32\ntoskrnl.exe
Check the Remote IP PC.
Login to that attacker PC go to C:\windows\system32 & search for hidden .dll
Note :-  there should not be any .dll file hidden.
Use fixdownadup remover & scan the PC this will remove Downadup.b virus.

Regards...
Ramji Iyyer

 

Regards...
Ramji Iyyer