Author Topic: Avast found virus. (Win32:Confi [Wrm]) Help needed!  (Read 72972 times)

0 Members and 1 Guest are viewing this topic.

rom109

  • Guest
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #15 on: January 19, 2009, 10:22:27 PM »
HELP!  I've:
1. Updated windows.
2. Run the MSRT -- it finds and "removes" the Conficker worm
3. Shut off system restore.
4. Running Avast Pro 4.8.1296 with 12/18/09 VPS
5. Shut down all shared drives.
6. Updated passwords to 13 characters with caps, alpha, and numbers
7. Scanned attached USB drive and renamed autorun.inf to autorun.bak
8. Run Avast boot scan and delte baddies

Result... Avast still keeps popping up telling me the worm has been found.  What do I do???

zepete

  • Guest
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #16 on: January 20, 2009, 12:03:11 AM »
Worm win32:confi also named worm.win32.kido or downadup.
Virus infiltrate via removable drive (autorun.inf file) or net server service.
They corrupt work dns client, if your computer have is virus, you can not connect to avast or anower antivir sites and microsoft.
For erase worm you mast:
1. Disable service access to shared files and printers microsoft nets.
2. Run AVAST test in boot mode.
3. Install patch from microsoft MS08-067
4. Correct multystring Windows reestor key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs (delete last string consist name of dll file with virus, this name you view in boot time test).
5. Enable service access to shared files and printers microsoft nets.
In russian language you may read in:
http://www.viruslist.com/ru/viruses/encyclopedia?virusid=21782725
http://zepete.livejournal.com/9966.html
http://zepete.livejournal.com/10188.html
« Last Edit: January 20, 2009, 12:05:50 AM by zepete »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33533
  • malware fighter
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #17 on: January 20, 2009, 12:34:10 AM »
Hi zepete,

Yes, we know of this worm spreading like wildfire, within Intranets the spreading is mainly through autorun.inf on USB sticks, people should disable this or use the autorun disinfector from here: http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
Because the worm disable various av solutions and MS update service, try the Microsoft Malicious Removal Tool from here:
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

But be reassured avast has a very good detection rate of this and protects the user from getting infected, but as your computer has not been infected yet the best policy will be to install the out-of-band patch to prevent this worm from infecting:

http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

micky77

  • Guest
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #18 on: January 20, 2009, 12:43:24 AM »
HELP!  I've:
1. Updated windows.
2. Run the MSRT -- it finds and "removes" the Conficker worm
3. Shut off system restore.
4. Running Avast Pro 4.8.1296 with 12/18/09 VPS
5. Shut down all shared drives.
6. Updated passwords to 13 characters with caps, alpha, and numbers
7. Scanned attached USB drive and renamed autorun.inf to autorun.bak
8. Run Avast boot scan and delte baddies

Result... Avast still keeps popping up telling me the worm has been found.  What do I do???


Another removal tool

http://www.symantec.com/norton/security_response/writeup.jsp?docid=2009-011316-0247-99

zepete

  • Guest
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #19 on: January 20, 2009, 10:20:15 AM »
Quote
HELP!  I've:
1. Updated windows.
2. Run the MSRT -- it finds and "removes" the Conficker worm
3. Shut off system restore.
4. Running Avast Pro 4.8.1296 with 12/18/09 VPS
5. Shut down all shared drives.
6. Updated passwords to 13 characters with caps, alpha, and numbers
7. Scanned attached USB drive and renamed autorun.inf to autorun.bak
8. Run Avast boot scan and delte baddies

Result... Avast still keeps popping up telling me the worm has been found.  What do I do???
1. He dont install patch on windows
2. You need disable server service (service access to shared files and printers microsoft nets), disable net drives not enough. This virus may spreaded if even not shared folder. Install firewall and you seen how worm spreaded to you.



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33533
  • malware fighter
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #20 on: January 20, 2009, 10:05:38 PM »
Hi zepete,

I must say that is a very good observation, "sprytny" and that means clever. The fact that worms like Conficker (Downadup) can spread so easily and successfully through network shares comes through a bug in  Shell32.dll. Microsoft knows about this bug, and developed a patch for it half a year ago, but thought it was not necessary to implement it for Windows XP, Windows 2003 Server or older as a security patch within the monthly patch cycle (they only did that for Vista through MS08-038, re: http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx

NoDriveTypeAutoRun

The bug is found in how the registry value"NoDriveTypeAutoRun" is being processed (this is a  "REG_DWORD" value that standard is found for every user under the keyl HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, and system wide does not exist as by default). The buggy version of Explorer (actually Shell32.dll) only looks for the register value at mounting a drive, when a pendrive is being inserted or mapping a networkdrive for a drive-letter, then it will work as expected. Only if one doubleclicks the drive inside explorer to open it, or give a right mouse-click or choose to "Open" or "Explore", Explorer will no longer check  "NoDriveTypeAutoRun" but check the contents of a Autorun.inf file in the root of the drive and evaluate this. Just depending on what the contents is of Autorun.inf it is possible to automatically execute a fie - and bingo!
So, zepete, you have found the real crux of the problem.
AutoRunSettings is a free tool: http://www.uwe-sieber.de/drivetools_e.html#autorun to adopt the registry settings manually,

Import the following into the registry is also a good alternative for XP3 i.m.h.o.:
Code: [Select]
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"
If you want to disable completely go here for a tool: http://nick.brown.free.fr/blog/2007/10/memory-stick-worms.html

Stay safe and secure,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

uniquename

  • Guest
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #21 on: January 25, 2009, 10:57:38 PM »
I've also got this virus in the network at work, there are about 200 computers there, DrWeb is installed by default, I installed also Avast deactivated DrWeb but it hasn't helped.
Every 10-40 minutes I receive virus found Alert Window in Avast and file qv....dll in system32 folder is deleted but the situation repeates again.
Password is strong enough 10 letters, that don't make any word, boot time scane disn't helped, MSN-067 were installed didn't helped.
So Avast and it's network shield is not capable to prevent network attack, it just sees the virus file and every time delete it. And finally every time after such attack a planned task (at1.job) in control panel is added with the string "rundll32.exe vqtctkpg.i".

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33533
  • malware fighter
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #22 on: January 25, 2009, 11:55:24 PM »
Hi uniquename,

Try the proposed registry solution given: http://forum.avast.com/index.php?topic=41941.msg351614#msg351614 read down the rest of this thread and apply the hotfix given,

What you experience is all of an explorer bug that has been fixed for Vista and now had to be hotfixed for XP also,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9407
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #23 on: January 28, 2009, 08:15:30 AM »
@Maxx, what about 64bit OS where boot scan is not available? Or is 64bit version not affected?
Visit my webpage Angry Sheep Blog

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #24 on: January 28, 2009, 11:15:35 AM »
RejZoR: there's a possibility to clean the 64bit machine from BART CD (using cacls and avast scan or manual remove), afaik..

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11818
    • AVAST Software
Re: Avast found virus. (Win32:Confi [Wrm]) Help needed!
« Reply #25 on: January 28, 2009, 11:18:15 AM »
No need to cacls with the latest beta of BART 3.0.

josephillips

  • Guest