Untangle Networks [home]


Go Back   Untangle Forums > General Forums > Networking

Closed Thread
 
LinkBack Thread Tools
Old 01-26-2009, 06:25 PM   #1 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default are you infected? how to check. (conficker/kido update)

Everyone is probably aware there is a virus/worm going around under many names. Its currently idle so people may not necessarily know they are infected.

You can easily check for suspicious machines on your network by dropping to a shell and running the following command on your untangle server

edit:
for 7.0+
Code:
curl -q http://untangle.com/download/patches/7.1/conficker_query.sh | sh
for 6.2 and before:
Code:
curl -q http://untangle.com/download/patches/6.0/conficker_query.sh | sh
This will find hits to website that the conficker is known to visit after infection. It lists the internal IP followed by the number of visits to suspicious websites. If some machines have many visits it may be worth investigating.

If you do have infected machines, kaspersky has a free removal utility here:
http://support.kaspersky.com/faq/?qid=208279973


This is a good opportunity to reiterate a couple basics:
1) Don't give windows machines a public IP - put them behind NAT and use port forwards
2) Patch your machines - autoinstallation of patches works great for most computers.

The virus vendors in Untangle do have the signatures, but this one has many ways to spread. This one can even spread by USB fobs using autoexec - so be careful!

edit:
easy way to check on the host itself:
http://www.confickerworkinggroup.org...feyechart.html
dmorris is online now  
Old 01-26-2009, 06:38 PM   #2 (permalink)
Master Untangler
 
Join Date: Sep 2008
URLs submitted: 1
Posts: 308
dknyinva is on a distinguished road
Default

Thanks for the tip dmorris. The command shows only my primary laptop with 2073 counts. Currrently running a thorough scan on all my laptops using Avira and Avast.
dknyinva is offline  
Old 01-26-2009, 06:41 PM   #3 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default

Quote:
Originally Posted by dknyinva View Post
Thanks for the tip dmorris. The command shows only my primary laptop with 2073 counts.
umm... thats kinda scary...

try this command for more details on what visits are suspicious:

Code:
curl -q http://untangle.com/download/patches/6.0/conficker_query_detail.sh | sh
dmorris is online now  
Old 01-26-2009, 06:41 PM   #4 (permalink)
Untangler
 
Join Date: Jan 2009
Posts: 31
sabertooth is on a distinguished road
Unhappy

Good post !!!

But I get "curl: (6) Couldn't resolve host 'metaloft.com'" after running the following command on my UT server....
Am I going wrong...?
sabertooth is offline  
Old 01-26-2009, 06:44 PM   #5 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default

Quote:
Originally Posted by sabertooth View Post
But I get "curl: (6) Couldn't resolve host 'metaloft.com'" after running the following command on my UT server....
Am I going wrong...?
I just updated it to point at untangle.com instead.

You may have to check your DNS settings.
dmorris is online now  
Old 01-26-2009, 06:45 PM   #6 (permalink)
Master Untangler
 
Join Date: Sep 2008
URLs submitted: 1
Posts: 308
dknyinva is on a distinguished road
Default

Quote:
Originally Posted by dmorris View Post
umm... thats kinda scary...

try this command for more details on what visits are suspicious:

Code:
curl -q http://untangle.com/download/patches/6.0/conficker_query_detail.sh | sh
all shows site is checkip.dyndns.org. I'm infected. I'm using the Kaspeersky utility to remove it now. Looks like a lot of people are downloading the free utility. Site keeps saying taking too long to respond.

Last edited by dknyinva; 01-26-2009 at 06:56 PM..
dknyinva is offline  
Old 01-26-2009, 07:12 PM   #7 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default

Quote:
Originally Posted by dknyinva View Post
all shows site is checkip.dyndns.org. I'm infected. I'm using the Kaspeersky utility to remove it now. Looks like a lot of people are downloading the free utility. Site keeps saying taking too long to respond.
still can't get it? I can download it fine. I have heard that it can prevent downloads from certain antivirus vendor sites. try it from here:

http://untangle.com/download/KidoKiller_v2.zip
dmorris is online now  
Old 01-26-2009, 07:23 PM   #8 (permalink)
Master Untangler
 
Join Date: Sep 2008
URLs submitted: 1
Posts: 308
dknyinva is on a distinguished road
Default

Quote:
Originally Posted by dmorris View Post
still can't get it? I can download it fine. I have heard that it can prevent downloads from certain antivirus vendor sites. try it from here: http://untangle.com/download/KidoKiller_v2.zip
Thanks for the link dmorris. I just downloaded and running on the infected laptop now.

Thanks again
dknyinva is offline  
Old 01-26-2009, 07:45 PM   #9 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 6,694
dmorris is on a distinguished road
Default

np - glad to help
dmorris is online now  
Old 01-26-2009, 08:38 PM   #10 (permalink)
mdh
Untangle Ninja
 
mdh's Avatar
 
Join Date: Aug 2007
URLs submitted: 171
Posts: 4,802
mdh is on a distinguished road
Default

I just love seeing zero as a result. <smile>
__________________
This space reserved for profound thought.....which does happen on occasion."
mdh is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:45 PM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.3.2