<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>From Source to Secure : Conficker Removal</title><link>http://blogs.msdn.com/rockyh/archive/tags/Conficker+Removal/default.aspx</link><description>Tags: Conficker Removal</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Conficker Removal with MSRT</title><link>http://blogs.msdn.com/rockyh/archive/2009/01/14/conficker-removal-with-msrt.aspx</link><pubDate>Wed, 14 Jan 2009 03:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9317623</guid><dc:creator>RockyH</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/rockyh/comments/9317623.aspx</comments><wfw:commentRss>http://blogs.msdn.com/rockyh/commentrss.aspx?PostID=9317623</wfw:commentRss><wfw:comment>http://blogs.msdn.com/rockyh/rsscomments.aspx?PostID=9317623</wfw:comment><description>&lt;P&gt;1. Symptoms to help you determine if you are infected &lt;/P&gt;
&lt;P&gt;· Account lockout policies are being tripped &lt;/P&gt;
&lt;P&gt;· Domain Controllers are being hammered&lt;/P&gt;
&lt;P&gt;· Network congestion &lt;/P&gt;
&lt;P&gt;· Sluggish Client Behavior&lt;/P&gt;
&lt;P&gt;2. Steps to help you recover&lt;/P&gt;
&lt;P&gt;Patch and clean – apply MS08-067 and review this info on weak passwords&lt;/P&gt;
&lt;P&gt;· Weak Password and Lockout policy info&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;FONT color=#000000&gt;&lt;SPAN&gt;What you should know about strong passwords: &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/readiness/content/documents/password_tips_for_administrators.doc" mce_href="http://www.microsoft.com/technet/security/readiness/content/documents/password_tips_for_administrators.doc"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/readiness/content/documents/password_tips_for_administrators.doc&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt; &lt;/SPAN&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/topics/hardsys/tcg/tcgch00.mspx" mce_href="http://www.microsoft.com/technet/security/topics/hardsys/tcg/tcgch00.mspx"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/topics/hardsys/tcg/tcgch00.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/prodtech/win2003/w2003hg/sgch00.asp" mce_href="http://www.microsoft.com/technet/security/prodtech/win2003/w2003hg/sgch00.asp"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/prodtech/win2003/w2003hg/sgch00.asp&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/security/prodtech/win2000/secwin2k/default.mspx" mce_href="http://www.microsoft.com/technet/security/prodtech/win2000/secwin2k/default.mspx"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/technet/security/prodtech/win2000/secwin2k/default.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_tips.asp" mce_href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_tips.asp"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_tips.asp&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN&gt;&lt;FONT color=#000000&gt;Password Best Practices:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;FONT color=#000000&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_protect.asp" mce_href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_protect.asp"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/enterprise/proddocs/en-us/windows_password_protect.asp&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;/SPAN&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;BR&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'"&gt;Accounts Passwords and Lockout Policies:&lt;/SPAN&gt;&amp;nbsp; &lt;BR&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx" mce_href="http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx"&gt;&lt;SPAN style="COLOR: black; FONT-SIZE: 10pt"&gt;http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/bpactlck.mspx&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;BR&gt;&lt;/SPAN&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT color=#000000&gt;Account Lockout and Management Tools:&lt;/FONT&gt; &lt;BR&gt;&lt;FONT color=#000000&gt;&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7af2e69c-91f3-4e63-8629-b999adde0b9e&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7af2e69c-91f3-4e63-8629-b999adde0b9e&amp;amp;displaylang=en"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt"&gt;&lt;FONT color=#0000ff&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=7af2e69c-91f3-4e63-8629-b999adde0b9e&amp;amp;displaylang=en&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;· Passgen is a tool that allows you to reset local passwords on large blocks of systems: &lt;BR&gt;&lt;A href="http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx" mce_href="http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx"&gt;http://blogs.technet.com/steriley/archive/2008/09/29/passgen-tool-from-my-book.aspx&lt;/A&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href="http://www.rockyh.net/files/Passgen.zip" target=_blank mce_href="http://www.rockyh.net/files/Passgen.zip"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=clip_image004 border=0 alt=clip_image004 src="http://blogs.msdn.com/blogfiles/rockyh/WindowsLiveWriter/ConfickerRemovalwithMSRT_98E1/clip_image004_3.gif" width=96 height=81 mce_src="http://blogs.msdn.com/blogfiles/rockyh/WindowsLiveWriter/ConfickerRemovalwithMSRT_98E1/clip_image004_3.gif"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3. Malware Removal&lt;/P&gt;
&lt;P&gt;1. MSRT - The updated MSRT will be live Tuesday 13 January; however you must remember that conficker breaks automatic updates, so we will need to also reference these KBs for &lt;B&gt;manual download&lt;/B&gt; information and alternate &lt;B&gt;enterprise deployment&lt;/B&gt; steps:&lt;/P&gt;
&lt;P&gt;KB890830 The Microsoft Windows Malicious Software Removal Tool helps remove specific, prevalent malicious software from computers that are running Windows Vista, Windows Server 2003, Windows XP, or Windows 2000&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/890830" mce_href="http://support.microsoft.com/kb/890830"&gt;http://support.microsoft.com/kb/890830&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;KB891716 Deployment of the Microsoft Windows Malicious Software Removal Tool in an enterprise environment&lt;/P&gt;
&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/891716" mce_href="http://support.microsoft.com/kb/891716"&gt;http://support.microsoft.com/kb/891716&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. FCS/ OneCare&lt;/P&gt;
&lt;P&gt;3. Competitive AV&lt;/P&gt;
&lt;P&gt;4. &lt;STRONG&gt;&lt;A href="http://blogs.msdn.com/rockyh/archive/2009/01/14/manual-removal-of-conficker.aspx" target=_blank mce_href="http://blogs.msdn.com/rockyh/archive/2009/01/14/manual-removal-of-conficker.aspx"&gt;Manual Cleanup&lt;/A&gt;&lt;/STRONG&gt; - This template supplies the manual cleanup steps and a script. (in a &lt;A href="http://blogs.msdn.com/rockyh/archive/2009/01/14/manual-removal-of-conficker.aspx" target=_blank mce_href="http://blogs.msdn.com/rockyh/archive/2009/01/14/manual-removal-of-conficker.aspx"&gt;separate post&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;See these blog posts for additional resources &lt;BR&gt;&lt;A href="http://www.microsoft.com/security/portal/Entry.aspx?name=Worm%3aWin32%2fConficker.B" mce_href="http://www.microsoft.com/security/portal/Entry.aspx?name=Worm%3aWin32%2fConficker.B"&gt;http://www.microsoft.com/security/portal/Entry.aspx?name=Worm%3aWin32%2fConficker.B&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx" mce_href="http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx"&gt;http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.technet.com/mmpc/archive/2008/12/31/just-in-time-for-new-years.aspx" mce_href="http://blogs.technet.com/mmpc/archive/2008/12/31/just-in-time-for-new-years.aspx"&gt;http://blogs.technet.com/mmpc/archive/2008/12/31/just-in-time-for-new-years.aspx&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9317623" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/rockyh/archive/tags/Conficker+Removal/default.aspx">Conficker Removal</category><category domain="http://blogs.msdn.com/rockyh/archive/tags/Anti+Virus/default.aspx">Anti Virus</category></item></channel></rss>