Tuesday, September 29, 2009

Fighting Conficker Update - Network World

Fighting Conficker - Network World

Before you tear all of your hair out, you do some more research and realize that running your anti-virus software alone may not clean the virus. Conficker has five known variants and can utilize the various versions to help itself spread fast and via different vectors. Looking at the research done by the Conficker Work Group, you find that the major anti-virus vendors have published a variety of repair tools that may clean the virus better than anti-virus alone.

Furthermore, you start reading the fine print in the Microsoft Knowledge Base article on Conficker and you see that there is a Group Policy Object (GPO) that can be used to help stop the propagation of the worm.

Now what? First up: get the GPO in place as soon as possible and make sure you enforce it to all Organizational Units. This is not the right time to block inheritance of a policy! Next, you need to test how best to clean an infected machine. Typically, running a couple of tools (one being a full scan of the anti-virus) to find and clean the infection, then rebooting, then running the anti-virus again (full scan), along with having the GPO in place, will help clean and stop the spreading. Start with systems that are showing the account lockout traffic in your logs to focus efforts on known infected machines.

