Could someone let me know if the following is Malware or related?

Could someone let me know if the following is Malware or related?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Could someone let me know if the following is Malware or related? HelenD 04-30-2007
Posted by David H. Lipman on May 5, 2007, 3:27 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| David, Thanks for this. Is there anywhere I can go to get a good listing of
| what these vulnerabilties are and how they are being exploited. See if I can
| establish a pattern?
|
| HelenD
|


Yes, use the Secunia Software Inspector, It will identify software with known
vulnerabilities.
http://secunia.com/software_inspector

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Malke on May 1, 2007, 9:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
HelenD wrote:
> A few weeks ago, I found that a large number of adult material files appeared
> on my computer over the weekend when it was not connected to the internet and
> I was not using the computer. Last week, I found that a similar incident had
> occurred one week earlier when I did not have the computer but it was
> connected to the company network.
>
> From quick analysis I found the following:
> * Both events were bounded by two failed logon attempts under my user ID
> * Time time duration between the two failed logon attempts was two days and
> twenty one hours.
> * Over the time period between the two failed logon attempts 72 event ID
> 636 and 72 event ID 637 occurred. Event ID 636 is : A user or group account
> was added to a local security group on the computer or on the domain, and
> Event ID 637 is:A user or group account was removed from a local security
> group on the computer or on the domain.
> * MS Installer events occured post the creation of the adult material files
> when the computer was next logged onto the network.
>
> I am interested in knowing whether anyone thinks this is still Malware or if
> these two events are related.
>
> I have attached the logs over the two incidents below just in case.

(snip logs)

A machine on your company network is infected with some malware that is
network-aware. You have File/Printer Sharing turned on or are
synchronizing files from a company share (or the like) and so your
machine is affected. To make sure your own machine (apparently a laptop
that goes back and forth to work?) is clean, go through the following
general malware removal steps systematically:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

You will need to log onto the machine as local Administrator to do this.
If you don't have the ability to do this, you must contact your systems
administrator and have them clean your machine. In any case, you need to
tell your systems administrator about the problem so they can find the
infected machine on the network and make sure it and all other machines
(including the server) have not been compromised.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by =?Utf-8?B?SGVsZW5E?= on May 1, 2007, 9:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Malke,

How can we be sure that this is the cause? Is it possible that someone may
have planted the issue on the computer? Why just this computer?

Was there anything from the vulnerability things I sent through on the last
thread that point to anything in particular.

HelenD

"Malke" wrote:

> HelenD wrote:
> > A few weeks ago, I found that a large number of adult material files
appeared
> > on my computer over the weekend when it was not connected to the internet
and
> > I was not using the computer. Last week, I found that a similar incident
had
> > occurred one week earlier when I did not have the computer but it was
> > connected to the company network.
> >
> > From quick analysis I found the following:
> > * Both events were bounded by two failed logon attempts under my user ID
> > * Time time duration between the two failed logon attempts was two days and
> > twenty one hours.
> > * Over the time period between the two failed logon attempts 72 event ID
> > 636 and 72 event ID 637 occurred. Event ID 636 is : A user or group account
> > was added to a local security group on the computer or on the domain, and
> > Event ID 637 is:A user or group account was removed from a local security
> > group on the computer or on the domain.
> > * MS Installer events occured post the creation of the adult material files
> > when the computer was next logged onto the network.
> >
> > I am interested in knowing whether anyone thinks this is still Malware or if
> > these two events are related.
> >
> > I have attached the logs over the two incidents below just in case.
>
> (snip logs)
>
> A machine on your company network is infected with some malware that is
> network-aware. You have File/Printer Sharing turned on or are
> synchronizing files from a company share (or the like) and so your
> machine is affected. To make sure your own machine (apparently a laptop
> that goes back and forth to work?) is clean, go through the following
> general malware removal steps systematically:
>
> http://www.elephantboycomputers.com/page2.html#Removing_Malware
>
> You will need to log onto the machine as local Administrator to do this.
> If you don't have the ability to do this, you must contact your systems
> administrator and have them clean your machine. In any case, you need to
> tell your systems administrator about the problem so they can find the
> infected machine on the network and make sure it and all other machines
> (including the server) have not been compromised.
>
> Malke
> --
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
> MS-MVP Windows - Shell/User
>

Posted by Malke on May 1, 2007, 10:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
HelenD wrote:
> Malke,
>
> How can we be sure that this is the cause? Is it possible that someone may
> have planted the issue on the computer? Why just this computer?
>
> Was there anything from the vulnerability things I sent through on the last
> thread that point to anything in particular.

It is not possible for me to answer those questions without being
on-site and seeing the machine hands-on. There are obvious limitations
to doing tech support via newsgroup without being able to see the
machines. You don't know that the issue is constrained to your
particular computer if you haven't done investigation on the rest of the
machines, including the server.

You need to contact your IT people. If your company is too small to have
its own system administrator, have a local professional come on-site to
sort things out. This will not be someone from your local Geek Squad, etc.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on May 1, 2007, 2:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If youre are in the United States or Canada please call this number
866 727 2338 ( Microsoft PCSafety )

and if you are outside the Continental America please send me the hijackthis
log file via email on available on my profile download this first
http://tinyurl.com/67reb and run it through choose the one that said scan and
save a log file
--
Milo
MSPSS - ESCA


Similar ThreadsPosted
Security Warning. (HOSTS related??) November 4, 2005, 12:34 am
HELP!! Virus affecting installing security-related programs? October 22, 2006, 10:07 pm
New Malware.j August 29, 2005, 6:02 am
malware September 5, 2005, 11:16 am
Malware March 5, 2006, 7:39 am
VBS: Malware (GEN) March 14, 2006, 3:11 pm
Spyware/malware July 20, 2005, 6:09 am
Is ewgef.exe malware? November 12, 2005, 12:03 am
RE: SafetyDefender MalWare April 22, 2006, 5:41 am
Re: SafetyDefender MalWare April 30, 2006, 5:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy