Sign in
Stuff n Things
Content from a CSS Security Engineer usually covering FCS and Incident Response
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
FCS
FCS ADM
FCS Client
FCS Database
FCS Definitions
FCS Policy
Forefront Client Security
Incident Response
SCE
Scheduled Scans
System Center Essentials
WSUS
Archive
Archives
April 2010
(1)
March 2010
(1)
January 2010
(1)
December 2009
(2)
October 2009
(1)
July 2009
(1)
May 2009
(2)
April 2009
(1)
March 2009
(2)
February 2009
(2)
January 2009
(4)
November 2008
(2)
October 2008
(3)
September 2008
(1)
August 2008
(2)
January, 2009
TechNet Blogs
>
Stuff n Things
>
January, 2009
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Stuff n Things
Malware Win32/Conficker.B W32.Downadup.B
Posted
over 4 years ago
by
Kurt Falde
17
Comments
So for the past 2 weeks now we are absolutely getting hammered with calls in CSS Security here at MS with organizations contracting this piece of malware. You can find write-ups from various AV companies at the following URL’s http://www.ca.com...
Stuff n Things
Using Logparser + Eventcomb to find malware
Posted
over 4 years ago
by
Kurt Falde
5
Comments
During the course of these Conficker / Downadup issues we typically see cases that started because accounts are getting locked out. I pause briefly here to point out that account lockouts are the work of the devil and are a sorry excuse for most...
Stuff n Things
How-to: Removal of Conficker in your FCS environment
Posted
over 4 years ago
by
Kurt Falde
3
Comments
Another Conficker post :) however this one is aimed at our FCS customers. It semi-applies to other customers however other AV vendors operated differently with regards to updates etc so this won’t necessarily be applicable to all. So today is Patch...
Stuff n Things
More on File Shares and Autorun.inf with regards to malware
Posted
over 4 years ago
by
Kurt Falde
0
Comments
So in my last post I mentioned the fact that Conficker/Downad whatever can also have a component that will spread through file shares that allow everyone to write at the root level of the file share. So a typical autorun.inf looks something like this...
Page 1 of 1 (4 items)