<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msforums.ph/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Protect your Enterprise Network (Corporate and Office)</title><link>http://msforums.ph/forums/54.aspx</link><description>For the IT Professional seeking for ways to help keep the enterprise infrastructure a safe place to work.</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/251824.aspx</link><pubDate>Wed, 28 Jan 2009 11:24:40 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:251824</guid><dc:creator>Crashoverride</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/251824.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=251824</wfw:commentRss><description>&lt;p&gt;those are just variants or so different naming convention for conficker ( as detected by other AV products ), and MS08-067 exploit is the one its using and recently other avenues as well.&lt;/p&gt;
&lt;p&gt;Just an update there is now are 2 new variant Conficker.c and conficker.D &lt;br /&gt;&lt;br /&gt;This would help&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx"&gt;http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/251818.aspx</link><pubDate>Wed, 28 Jan 2009 07:13:38 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:251818</guid><dc:creator>securityguy</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/251818.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=251818</wfw:commentRss><description>&lt;p&gt;sirs,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;are both downadup and downadup.b covered by MS08-067 patch?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/251287.aspx</link><pubDate>Wed, 21 Jan 2009 07:01:16 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:251287</guid><dc:creator>badzmanaois</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/251287.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=251287</wfw:commentRss><description>&lt;p&gt;Bump...&lt;/p&gt;
&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&amp;nbsp;&lt;/p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;&amp;quot;Widespread Confickr/Downadup Worm Hard To Kill - Attack more dangerous in the potential of its scope and the way it was waged than the worm itself&amp;quot;:&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;Their biggest victims have been the enterprise, not the typical home user, experts note. And that could mean millions of enterprise bots. &amp;quot;There&amp;#39;s still no botnet activity. But that could easily change at any given moment,&amp;quot; says Patrik Runald, chief security advisor for F-Secure, which has been watching the worm closely. &amp;quot;These millions of PCs try to connect to hundreds of Websites daily, and the people behind this could easily change the behavior of an infected computer if they wanted to.&amp;quot; &lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;&amp;nbsp;&lt;/span&gt; 
&lt;p class="MsoNormal" style="MARGIN:0cm 0cm 0pt;mso-layout-grid-align:none;"&gt;&lt;span&gt;How did enterprises fall for a worm? Security experts say poor patch management, antivirus software shortcomings, and lack of detection of outbound command and control traffic contributed to the worm&amp;#39;s success. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;&lt;font size="3"&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;mso-ansi-language:EN-US;"&gt;&lt;a href="http://www.darkreading.com/story/showArticle.jhtml?articleID=212901489"&gt;&lt;span style="COLOR:blue;"&gt;http://www.darkreading.com/story/showArticle.jhtml?articleID=212901489&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250888.aspx</link><pubDate>Thu, 15 Jan 2009 08:23:22 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250888</guid><dc:creator>jpaloma</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250888.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250888</wfw:commentRss><description>&lt;p&gt;Check out the &lt;a class="" href="http://www.microsoft.com/technet/security/bulletin/ms09-001.mspx" target="_blank"&gt;Microsoft Security Bulletin MS09-001&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250816.aspx</link><pubDate>Wed, 14 Jan 2009 11:24:30 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250816</guid><dc:creator>jasperjugan</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250816.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250816</wfw:commentRss><description>&lt;p&gt;FYI guys, patching alone is not a guarantee. You need to make sure that the whole network is clean. As mentioned in the articles it spreads via&amp;nbsp;4 ways generally:&lt;/p&gt;
&lt;p&gt;1. removal drives&lt;/p&gt;
&lt;p&gt;2. network shares&lt;/p&gt;
&lt;p&gt;3. MS08-067 exploit&lt;/p&gt;
&lt;p&gt;4. trying to run itself using a weak admin password list&lt;/p&gt;
&lt;p&gt;So meaning, even if you deployed the patch, if one of these symptoms are still present, chances are it will spread out (especially if it exploits as admin account).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Also, we DO NOT recommend logging in using domain account especially domain admin accounts when cleaning up. use the local user accounts as much as possible.&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250811.aspx</link><pubDate>Wed, 14 Jan 2009 10:17:57 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250811</guid><dc:creator>rockshock_zid</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250811.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250811</wfw:commentRss><description>&lt;p&gt;aside patch from microsoft, what we did is we also run removal tool from our anti virus.&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250809.aspx</link><pubDate>Wed, 14 Jan 2009 10:03:22 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250809</guid><dc:creator>securityguy</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250809.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250809</wfw:commentRss><description>&lt;p&gt;is it possible that we have already applied the patches but there are still damages done to the computers infected?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;because from our experience after applying the patch our anti-virus stopped its autoprotect against the downadup(also known as conficker worm)&lt;/p&gt;
&lt;p&gt;points is, is applying the patch enough or there are further steps to be done?&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250806.aspx</link><pubDate>Wed, 14 Jan 2009 09:35:29 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250806</guid><dc:creator>jpaloma</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250806.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250806</wfw:commentRss><description>&lt;p&gt;The &lt;a class="" href="http://www.microsoft.com/technet/security/bulletin/MS09-Jan.mspx" target="_blank"&gt;Jan 2009 MSRT&lt;/a&gt; includes the removal for Conficker.&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250794.aspx</link><pubDate>Wed, 14 Jan 2009 06:29:54 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250794</guid><dc:creator>Crashoverride</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250794.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250794</wfw:commentRss><description>&lt;p&gt;I sure want to keep this thread alive for reason that we found significant number of Conficker/Downad Worm variants that has evolved significantly now using the original rootkit module,brute force and dictionary attack on&amp;nbsp;user&amp;nbsp;password,&amp;nbsp;file and registry locking sequence, autorun worm addetives, DoS capability as well as DNS poisioning package all in one - with the end product of backdoor access.&lt;br /&gt;&lt;br /&gt;Again &lt;strong&gt;PLEASE proceed to Windows Update ASAP and update your Latest Security Application to the most recent pattern&lt;/strong&gt;, as well as locking down external storages alien to your infrastructure or home PC&amp;#39;s. &lt;/p&gt;
&lt;p&gt;Just yesterday we found 2 unique variant in South East asia.&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250442.aspx</link><pubDate>Fri, 09 Jan 2009 10:21:06 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250442</guid><dc:creator>Crashoverride</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250442.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250442</wfw:commentRss><description>&lt;p&gt;Hmmm well you should get not only the removal for the actual file but as well as the remnant files.... Patch up dude and clog down the use of removable drives and online drives. 
&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="/Themes/default/images/icon-quote.gif"&gt; &lt;strong&gt;rockshock_zid:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt; 
&lt;p&gt;This is what we troubleshoot yesterday, the whole day and night &lt;img alt="Sleep" src="http://msforums.ph/emoticons/emotion-20.gif" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;If you still have such issue buzz us we may extend some tools for you to use... for cleanup&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250413.aspx</link><pubDate>Fri, 09 Jan 2009 05:39:42 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250413</guid><dc:creator>badzmanaois</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250413.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250413</wfw:commentRss><description>&lt;p&gt;The bloody patch was released in October; an out-of-band one at that (which would have already sent an administrator worth his salt a-patching).&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve a script which &amp;quot;tries&amp;quot; to identify the rogue services randomly generated by this worm (I didn&amp;#39;t include any cleanup mechanism for lack of time):&lt;/p&gt;
&lt;p&gt;&lt;a href="http://badzmanaois.blogspot.com/2009/01/confickervbs-conficker-wormdownad.html"&gt;http://badzmanaois.blogspot.com/2009/01/confickervbs-conficker-wormdownad.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250402.aspx</link><pubDate>Fri, 09 Jan 2009 04:43:40 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250402</guid><dc:creator>rockshock_zid</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250402.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250402</wfw:commentRss><description>&lt;p&gt;This is what we troubleshoot yesterday, the whole day and night &lt;img src="http://msforums.ph/emoticons/emotion-20.gif" alt="Sleep" /&gt;&lt;/p&gt;</description></item><item><title>Re: Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250401.aspx</link><pubDate>Fri, 09 Jan 2009 04:40:26 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250401</guid><dc:creator>Crashoverride</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250401.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250401</wfw:commentRss><description>And well it could be prevented by having the current windows update/patches in your system and checking USB/removable drives and similar before introducing such to any PC system.</description></item><item><title>Conficker Worm Going Around</title><link>http://msforums.ph/forums/thread/250336.aspx</link><pubDate>Thu, 08 Jan 2009 12:23:15 GMT</pubDate><guid isPermaLink="false">dc4eba4f-2479-40d1-a3a5-5d9867a7b143:250336</guid><dc:creator>jpaloma</dc:creator><slash:comments>0</slash:comments><comments>http://msforums.ph/forums/thread/250336.aspx</comments><wfw:commentRss>http://msforums.ph/forums/commentrss.aspx?SectionID=54&amp;PostID=250336</wfw:commentRss><description>&lt;p&gt;Word has it that this worm is going&amp;nbsp;around certain regions in Asia.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;From the &lt;a class="" href="http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx"&gt;Microsoft Malware Protection Center&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;As expected, we are seeing another wave of attacks exploiting the vulnerability detailed in security bulletin MS08-067.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Early last week we &lt;/em&gt;&lt;a class="" href="http://blogs.technet.com/mmpc/archive/2008/11/17/a-quick-update-about-ms08_2D00_067-exploits.aspx"&gt;&lt;em&gt;blogged&lt;/em&gt;&lt;/a&gt;&lt;em&gt; about &lt;/em&gt;&lt;a class="" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;&lt;em&gt;MS08-067&lt;/em&gt;&lt;/a&gt;&lt;em&gt; exploits. At that time, the number of exploits in the wild was still low and they were mostly targeted attacks. However, during the weekend we started receiving customer reports&amp;nbsp;for new malware that exploits this vulnerability. During the last two days that malware gained momentum and as a result we see an increased support call volume. The SHA1 hash of the malware is 0x5815B13044FC9248BF7C2DBA771F0E6496D9E536 and we detect it as &lt;/em&gt;&lt;a class="" title="Worm:Win32/Conficker.A" href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.A"&gt;&lt;em&gt;Worm:Win32/Conficker.A&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt; &lt;/p&gt;
&lt;p&gt;Regarding the worm &lt;a class="" href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.B" target="_blank"&gt;Worm:Win32/Conficker.B&lt;/a&gt;&lt;/p&gt;
&lt;div align="left"&gt;&lt;em&gt;Worm:Win32/Conficker.B is a worm that infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE).&amp;nbsp;If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. It may also spread via removable drives and weak administrator passwords. It disables several important system services and security products.&lt;/em&gt;&lt;/div&gt;
&lt;div align="left"&gt;&lt;em&gt;&lt;/em&gt;&amp;nbsp;&lt;/div&gt;
&lt;div align="left"&gt;&lt;strong&gt;&lt;em&gt;Microsoft strongly recommends that&amp;nbsp;users&amp;nbsp;apply the update referred to in&amp;nbsp;&lt;/em&gt;&lt;/strong&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;&lt;strong&gt;&lt;em&gt;Security Bulletin MS08-067&lt;/em&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;em&gt; immediately.&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt;</description></item></channel></rss>