Virus create an unknown user, service, enccrypted files

Virus create an unknown user, service, enccrypted files

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Virus create an unknown user, service, enccrypted files Vida 08-09-2006
Posted by Vida on August 9, 2006, 6:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear Messrs,

In our domain infrastructure we found, in some W2KPRO, the problem
mentioned in the object.
After I logged on as administrator of domain, and the proxy setting's
has been removed, I run windows update.
Then after reboot, the computer work very slowly and it seems that the
virtual memory doesn't work properly.
Every process in progress need a high memory consumption.
So please be informed that the following infections were found:
- in "document and settings" folder there is a strange folder user
- in that folder I find a new folder with the machine name like "COMP$"
- on the user management a strange user was set as administrators
- on the user right assignment I found the strange user with particular
settings
- in c:\winnt\temp I found an .exe file and symantec security response
found a new virus
- after antivirus update (corporate edition 10.0.2) this file is kept
in quarantine, but immediatey a new .exe file was created.
- I found that this (or a new) file is called in
HKLM\sofware\microsoft\windows\currentversion\run.
- in c:\programmi\file comuni\system (or microsoft shared) I found one
or more .exe files that are encrypted by the strange user.
- I found a service that use this .exe file and the strange user on
logon tab

If someone has encountered similar problems and can help me, please
contact me a.s.a.p.
Thanks in advance for your cooperation.
Best regards


Posted by Malke on August 9, 2006, 8:37 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Vida wrote:

> Dear Messrs,
>
> In our domain infrastructure we found, in some W2KPRO, the problem
> mentioned in the object.
> After I logged on as administrator of domain, and the proxy setting's
> has been removed, I run windows update.
> Then after reboot, the computer work very slowly and it seems that the
> virtual memory doesn't work properly.
> Every process in progress need a high memory consumption.
> So please be informed that the following infections were found:
> - in "document and settings" folder there is a strange folder user
> - in that folder I find a new folder with the machine name like "COMP$"
> - on the user management a strange user was set as administrators
> - on the user right assignment I found the strange user with particular
> settings
> - in c:\winnt\temp I found an .exe file and symantec security response
> found a new virus
> - after antivirus update (corporate edition 10.0.2) this file is kept
> in quarantine, but immediatey a new .exe file was created.
> - I found that this (or a new) file is called in
> HKLM\sofware\microsoft\windows\currentversion\run.
> - in c:\programmi\file comuni\system (or microsoft shared) I found one
> or more .exe files that are encrypted by the strange user.
> - I found a service that use this .exe file and the strange user on
> logon tab

You will need to take the network down and either individually clean all
workstations and servers or - the better choice - flatten all systems and
apply your backup images. There is no other way to be 100% sure you've
gotten all infection and your machines are no longer compromised.

If your IT Dept. didn't make backup images and you cannot flatten the
systems, then take down the network and go machine-by-machine. Do not bring
the network back up until all machines are clean. Afterwards, review your
security, deployment, and backup policies and make necessary changes.

Here are some general cleanup instructions. Without knowing the name of the
virus Symantec av found, I can't comment on it.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

If you are a small company and do not have an on-staff IT person or
department, then the smartest thing for you to do now is have a competent
professional computer repair person come on-site and clean up the mess.
Afterwards s/he can offer recommendations to you to help prevent this
happening again. Do not use "a friend of your brother's" or the like. Find
someone who is skilled and has experience working with networks.

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by vida on August 9, 2006, 9:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thank you Malke.
I am a member of IT departement of a Company with 200 client.
Symantec support is now working about this problem. Infact it seem to
be a new type of virus.
Your solutions is correct but the risk of a new infections remain.


Posted by Malke on August 9, 2006, 9:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
vida wrote:

> Thank you Malke.
> I am a member of IT departement of a Company with 200 client.
> Symantec support is now working about this problem. Infact it seem to
> be a new type of virus.
> Your solutions is correct but the risk of a new infections remain.

Then yes, the solution is to flatten everything, apply backup images, and
then figure out what went wrong. New virus or not, you've got a hole (or
holes) somewhere. You need to find out where and change/patch/fix because
there will always be new viruses.

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by Leythos on August 9, 2006, 9:32 am
If you were  Registered and logged in, you could reply and use other advanced thread options
guido.concini@francescoparisi.com says...
> Thank you Malke.
> I am a member of IT departement of a Company with 200 client.
> Symantec support is now working about this problem. Infact it seem to
> be a new type of virus.
> Your solutions is correct but the risk of a new infections remain.

And if you had a proper firewall, one that blocks attachments and http
content that could be malicious, you would not have a means for the
malware to enter your network through the most common path.

--

spam999free@rrohio.com
remove 999 in order to email me

Similar ThreadsPosted
Virus create an unknown user, service, enccrypted files August 9, 2006, 5:42 am
Virus/Spyware Creates New User Account? December 14, 2005, 8:25 pm
Diskmanager service is it a virus September 25, 2008, 11:46 am
how to remove "service manager" virus? May 11, 2006, 10:30 pm
McAfee virus removal service - Genuine? February 27, 2008, 3:19 am
Re: Help on an unknown virus!! January 9, 2007, 6:56 am
Re: Help on an unknown virus!! January 9, 2007, 6:57 am
Re: Help on an unknown virus!! January 9, 2007, 12:44 pm
Re: Help on an unknown virus!! January 10, 2007, 2:11 am
Unknown virus can anybody help me? March 22, 2007, 1:32 am

The site map in XML format XML site map

Contact Us | Privacy Policy