SBS 2002 infected with Conficker virus - how to remove??

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View


We've just taken over the IT support of a new client. The previous IT
company didn't look after the server or workstations very well.

One of the problems they left was a Conficker virus infection. I know
their server is infected and I'm visiting site to check the
workstations some of which I expect to be infected.

Their server SBS 2003 had not had any windows updates installed since
around 2008 - when I ran windows updates the other day there were
hundreds of updates installed. Similarly the workstations only have XP
SP2 as the last update. Workstations are running AVG Home Edition,
server is running AVG SBS out of date as of May.


I want to remove Conficker from the server first.

So far I've done the following on the server:

1. Managed to access windows update and installed every update
available - including the conficker patch.
2. Ran the MS malicious software removal tool. This identifies 3
Conficker infections and indicates it has removed them.
3. Disabled autorun via group policy as per microsoft instructions.
4. Rebooted the server

However upon reboot the server clearly gets reinfected as the windows
update site becomes inaccessible, the related services are disabled
and the malicious software tool indicates it has found conficker
infection again.


Can anyone tell me how best to prevent reinfection? I was under the
impression that having all patches installed and autorun disabled via
group policy would prevent reinfection.

Thanks in advance.



Re: SBS 2002 infected with Conficker virus - how to remove??




| We've just taken over the IT support of a new client. The previous IT
| company didn't look after the server or workstations very well.

Flatten, wipe disks and reinstall OS.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Re: SBS 2002 infected with Conficker virus - how to remove??



I'm not even going to take on the support for the client - it's far
more trouble than it's worth.

On a side note though is that really what's necessary to get rid of
conficker?  I mean they've got around 14 workstations all infected
plus their domain controller. Surely nobody is going to want to
undertake that?

Re: SBS 2002 infected with Conficker virus - how to remove??




| I'm not even going to take on the support for the client - it's far
| more trouble than it's worth.

| On a side note though is that really what's necessary to get rid of
| conficker?  I mean they've got around 14 workstations all infected
| plus their domain controller. Surely nobody is going to want to
| undertake that?

Well it is my professional opinion based upon the note "...just taken over the
IT support
of a new client. The previous IT company didn't look after the server or
workstations very
well" and I believe you need to start them on a clean slate free of defects and
malware
and thus my suggestion to wipe and re-instal from scratch.

If you had conficker and this was a company you belonged to and were a part of I
would
suggest trying to slug it out.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Re: SBS 2002 infected with Conficker virus - how to remove??




[...]

Quoted text here. Click to load it

No, most good AV programs and some of the better antimalware programs
should be able to rid you of Conficker.

...but the condition these machines were left in makes me think that
Conficker probably isn't your only problem.



Re: SBS 2002 infected with Conficker virus - how to remove??




Quoted text here. Click to load it

I agree, bit defender had the conficker removal tools for single and
networked computers and I had tried it successfully ......
check it here...
http://www.bdtools.net /

Roy

Site Timeline