Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Conficker Infected Entire Network: How To Remove?

  1. #1
    Banned verified ictponder's Avatar
    Join Date
    Sep 2010
    Owner Since
    2006

    Location
    Owosso, MI
    Posts
    286
    Thanks
    55
    Thanked 55 Times in 37 Posts

    Conficker Infected Entire Network: How To Remove?

    Our entire network is infected from a stupid fucking customers USB drive. Can someone with experience with this please help me remove it?

  2. #2
    Forum User
    Join Date
    Sep 2010
    Owner Since
    Before 3Si.

    Location
    Outer Banks
    Posts
    113
    Thanks
    16
    Thanked 10 Times in 6 Posts
    Do you have enterprise virus support?

  3. #3
    Banned verified ictponder's Avatar
    Join Date
    Sep 2010
    Owner Since
    2006

    Location
    Owosso, MI
    Posts
    286
    Thanks
    55
    Thanked 55 Times in 37 Posts
    Only virus software we have is Avast on some of the computers. We do not have a tech department and a lot of these computers do not get updates like they should. Unfortunately the only person who can run a program or executable file is the owner as all others do not have priviledges and all websites not pertaining to the daily operation of the businesses are blocked on our domain via Internet Explorer. This is the only PC with firefox on it, which I managed to install before it was hooked to the network.
    Last edited by ictponder; 10-18-2010 at 12:26 PM.

  4. #4
    Forum User
    Join Date
    Sep 2010
    Owner Since
    Before 3Si.

    Location
    Outer Banks
    Posts
    113
    Thanks
    16
    Thanked 10 Times in 6 Posts
    How many workstations are we talking?

    Quote Originally Posted by ictponder View Post
    Only virus software we have is Avast on some of the computers. We do not have a tech department and a lot of these computers do not get updates like they should. Unfortunately the only person who can run a program or executable file is the owner as all others do not have priviledges and all websites not pertaining to the daily operation of the businesses are blocked on our domain via Internet Explorer. This is the only PC with firefox on it, which I managed to install before it was hooked to the network.

  5. #5
    YOUUSSS TRROOOLLLIN supporter
    Join Date
    Sep 2010
    Owner Since
    8/2008

    Location
    Boston, MA
    Posts
    528
    Thanks
    29
    Thanked 62 Times in 45 Posts
    how many workstations?
    are they on a domain?
    how is your network infrastructure setup?

  6. #6
    DR-750 club Not Verified
    Join Date
    Sep 2010
    Owner Since
    I could drive.

    Location
    Portland, Texas
    Posts
    2,546
    Thanks
    96
    Thanked 172 Times in 124 Posts
    Provide us with more information and we can help.
    July 2014 COTM
    We follow the earth. The earth follows the stars. The stars know their way and though the body dies. The stars will remain, like the waves of the sea and restless slate.

  7. #7
    Banned verified ictponder's Avatar
    Join Date
    Sep 2010
    Owner Since
    2006

    Location
    Owosso, MI
    Posts
    286
    Thanks
    55
    Thanked 55 Times in 37 Posts
    It's on a domain, about 8 computers are infected (haven't checked the server yet). Each host is assigned address dynamically and each host has 2 mapped drives to the server, not sure if that helps. This all started after troubleshooting a customers computer using their USB drive which was apparently infected. I've managed to run Malicious Software Removal Tool from a USB drive on one computer and install Microsoft updates, fixing the problem. The other computers get infected after running removal tool before I can get the updates to download.

    For those who will ask why we were troubleshooting a computer when we are getting infected ourselves..

    We sell Verizon and sometimes customers can't figure out how to install the VZ Access Manager software on their PC or get drivers to work with certain phones. So we use their USB drives to copy drivers and such.
    Last edited by ictponder; 10-18-2010 at 04:40 PM.

  8. #8
    Member
    Join Date
    Sep 2010
    Owner Since

    Posts
    136
    Thanks
    40
    Thanked 41 Times in 36 Posts
    http://support.microsoft.com/kb/962007

    About half way down it has all the step by step instructions for manual removal.

    It is a worm, so make sure these infected computers are disconnected from your network.

    Let us know how it goes.

  9. #9
    2012.03.28
    Join Date
    Sep 2010
    Owner Since
    April 11, 2008

    Location
    Allover, MI
    Posts
    19
    Thanks
    0
    Thanked 1 Time in 1 Post
    Seperation from non-infected machines is a great start, make sure to clean all temp. files per user/system. Also, never hurts to have a flash drive of your own around for tasks like that, having one you know is clean can help prevent these situations.
    Have fun bro, my job practically is virus removal. haha

  10. #10
    Twin Turbo verified
    Join Date
    Sep 2010
    Owner Since
    2007

    Location
    Melbourne, Australia
    Posts
    2,123
    Thanks
    76
    Thanked 91 Times in 75 Posts
    I recommend an SD card with a usb card reader. This way you can copy tools/software to it then lock it to block any write access. Load up combofix and run on every pc. Only use the combo fix from the below link. There are fake ones out there.

    http://www.bleepingcomputer.com/down...virus/combofix
    1990 JDM GTO TT with Vi-PEC plug-in V44 EMS, TD04-13T's, 3SX Downpipe, MP Hi-flow cat, ARC SMIC's, Aeromotive Stealth 340LPH pump, Fuelab 515 FPR, Ninja Performance 75amp hotwire kit, oohnoo fuel loop & rail adapters, Nylon braided ethanol fuel line, NGK AFX Wideband, K&N FIPK, Iridium plugs, HKS Twin Power DLI, Turbo XS racing BOV, 3SX poly mounts, Custom 280km/h speedo.

    Waiting install
    Injector Dynamics 725cc Injectors.

    Build Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
The 3000GT/Stealth/GTO Web History Project
3000gt.com
3000GT / Stealth International WWWboard Archive
Jim's (RED3KGT) Reststop
3000GT/Stealth/GTO Information and Resources
Team 3S
3000GT / Stealth / GTO Information
daveblack.net
3000GT/Stealth/GTO Clubs and Groups
Michigan 3S
MInnesota 3S
Wisconsin 3S
Iowa, Nebraska, Kansas 3S
North California 3000GT/Stealth
United Society of 3S Owners
3000GT/Stealth/GTO Forums
3000GT/Stealth International
3000GT/Stealth/GTO Event Pages
3S National Gathering
East Coast Gathering
Upper Mid-West Gathering
Blue Ridge Gathering