Conficker Standalone Removal Tool

Reading Time: < 1 minute

The below tool provided by Sophos will scan for the below Conficker Viruses:

To download tool – click Conficker Removal Tool

Mal/Conficker-A
Mal/Confick-Dam
Mal/Conficker-B
Mal/ConfInf-A
Troj/ConfData-A
Troj/ConfDr-B
Troj/ConfDr-C
Troj/ConfDr-Gen
W32/ConfDr-Gen
W32/Confick-A
W32/Confick-B
W32/Confick-C
W32/Confick-D
W32/Confick-F
W32/Confick-G
W32/Confick-H
W32/Confick-I
W32/Confick-K
W32/Confick-L
W32/Confick-M
W32/ConfikMem-A
W32/ConfikMem-B

For more info on Conficker or ways to remove it from your network, use the search box towards the top right. Type the word conficker.

Create security enhanced redirected folders

Reading Time: < 1 minute

Create security enhanced redirected folders

To make sure that only the user and the domain administrators have permissions to open a particular redirected folder, do the following:

1) Select a location in your environment where you would like to store Folder Redirection, and then share the selected folder. In this example, FLDREDIR is used.
2) Set Share Permissions for the Everyone group to Full Control.
3) Use the following settings for NTFS Permissions:
4) CREATOR OWNER – Full Control (Apply onto: Subfolders and Files Only)
5) System – Full Control (Apply onto: This Folder, Subfolders and Files)
6) Domain Admins – Full Control (Apply onto: This Folder, Subfolders and Files)
7) Everyone – Create Folder/Append Data (Apply onto: This Folder Only)
8.) Everyone – List Folder/Read Data (Apply onto: This Folder Only)
9) Everyone – Read Attributes (Apply onto: This Folder Only)
10) Everyone – Traverse Folder/Execute File (Apply onto: This Folder Only)

Use a path similar to \\server\FLDREDIR\username to create a folder under the shared folder, FLDREDIR.
Because the Everyone group has the Create Folder/Append Data right, the group members have the proper permissions to create the folder; however, the members are not able to read the data afterwards. The Username group is the name of the user that was logged on when you created the folder. Because the folder is a child of the parent folder, it inherits the permissions that you assigned to FLDREDIR. Also, because the user is creating the folder, the user gains full control of the folder because of the Creator Owner Permission setting.

More at Microsoft

Registry editor permissions on Windows Server

Reading Time: < 1 minute

By default any user can launch registry editor. This could cause issues if users start to amend or delete keys or values, so should be secured.

1) Browse to %SystemRoot%\Windows\system32
2) Right click on regedt32.exe
3) Click properties
4) Click on the security tab
5) Remove all groups except administrators and system
6) Click apply and ok
7) Repeat the above steps for file Regedit.exe if it exists in the same location

Securing access to SAM database

Reading Time: < 1 minute

The SAM database is located in teh repair directory under the Windows folder. The SAM database contains password information and is quite secure but for a higher level of security change permissions on the repair directory.

1) Right click on the repair directory located under C:\Windows
2) Click properties
3) Click the security tab
4) Allow administrators and system should have full control permissions. Remove any other users.

Secure Remote Desktop on a Windows 2003 Terminal Server

Reading Time: < 1 minute

1) Open Administrative Tools and then Terminal Services Configuration
2) Select connections from the left pane and then RDP-TCP
3) Click the action menu and properties
4) Select the permissions tab
5) Ensure that only admins (Full Control) and System available. Remove any other users. If you have an admin group you use for RDP access, add and allow full control.
If you wish you can also disable other features such as drive mapping, windows printer mapping etc. These can be found by clicking the client settings tab.