|
|
#1 (permalink) |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
![]() |
Everyone is probably aware there is a virus/worm going around under many names. Its currently idle so people may not necessarily know they are infected.
You can easily check for suspicious machines on your network by dropping to a shell and running the following command on your untangle server edit: for 7.0+ Code:
curl -q http://untangle.com/download/patches/7.1/conficker_query.sh | sh Code:
curl -q http://untangle.com/download/patches/6.0/conficker_query.sh | sh If you do have infected machines, kaspersky has a free removal utility here: http://support.kaspersky.com/faq/?qid=208279973 This is a good opportunity to reiterate a couple basics: 1) Don't give windows machines a public IP - put them behind NAT and use port forwards 2) Patch your machines - autoinstallation of patches works great for most computers. The virus vendors in Untangle do have the signatures, but this one has many ways to spread. This one can even spread by USB fobs using autoexec - so be careful! edit: easy way to check on the host itself: http://www.confickerworkinggroup.org...feyechart.html
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
#3 (permalink) | |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
![]() |
Quote:
![]() ![]() try this command for more details on what visits are suspicious: Code:
curl -q http://untangle.com/download/patches/6.0/conficker_query_detail.sh | sh
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
|
#5 (permalink) | |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
![]() |
Quote:
You may have to check your DNS settings.
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
|
#6 (permalink) |
|
Master Untangler
Join Date: Sep 2008
URLs submitted: 1
Posts: 328
![]() |
all shows site is checkip.dyndns.org. I'm infected. I'm using the Kaspeersky utility to remove it now. Looks like a lot of people are downloading the free utility. Site keeps saying taking too long to respond.
Last edited by dknyinva; 01-26-2009 at 07:56 PM.. |
|
|
|
|
#7 (permalink) | |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
![]() |
Quote:
http://untangle.com/download/KidoKiller_v2.zip
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
|
|
|
#8 (permalink) | |
|
Master Untangler
Join Date: Sep 2008
URLs submitted: 1
Posts: 328
![]() |
Quote:
Thanks again |
|
|
|
|
|
#9 (permalink) |
|
Untangle Junkie
![]() Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,189
![]() |
np - glad to help
![]()
__________________
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself. If you need Untangle support please call or email support@untangle.com |
|
|
![]() |
| Thread Tools | |
|
|