Stuff n Things

Content from a CSS Security Engineer usually covering FCS and Incident Response

January, 2009

Posts
  • Stuff n Things

    Malware Win32/Conficker.B W32.Downadup.B

    • 17 Comments
    So for the past 2 weeks now we are absolutely getting hammered with calls in CSS Security here at MS with organizations contracting this piece of malware. You can find write-ups from various AV companies at the following URL’s http://www.ca.com...
  • Stuff n Things

    Using Logparser + Eventcomb to find malware

    • 5 Comments
    During the course of these Conficker / Downadup issues we typically see cases that started because accounts are getting locked out.  I pause briefly here to point out that account lockouts are the work of the devil and are a sorry excuse for most...
  • Stuff n Things

    How-to: Removal of Conficker in your FCS environment

    • 3 Comments
    Another Conficker post :) however this one is aimed at our FCS customers. It semi-applies to other customers however other AV vendors operated differently with regards to updates etc so this won’t necessarily be applicable to all. So today is Patch...
  • Stuff n Things

    More on File Shares and Autorun.inf with regards to malware

    • 0 Comments
    So in my last post I mentioned the fact that Conficker/Downad whatever can also have a component that will spread through file shares that allow everyone to write at the root level of the file share. So a typical autorun.inf looks something like this...
Page 1 of 1 (4 items)