New virus out

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
So I made a post awhile ago in OT about a virus I was dealing with that would create two letter executables and was sending out mass amounts of network traffic. It crippled us for a few hours the first day it has hit.

We were first hit about a month ago and I have been trying to clean us up the entire time. The problem is that we keep getting reinfected because of how many users and holes we've had for so long.

I'll post some links to the virus that we're dealing with, Keep in mind, none of these links were showing up in a Google result when I was trying to clean this up, so I was trying to do it without any info.

I have since been able to get most of our PCs installed with antivirus and windows firewall turned on for those that didn't have it.

The servers that keep getting reinfected do not have a firewall installed on them and only have avast server edition trial on them. Originally they did not have antivirus installed (long story, I was not in charge of these servers).

I am unable to bring these servers down much, as they are public safety related. Here is my plan, I would like some feedback on it.

Restart all servers at once (7 total) and do a boot time scan to remove the virus (it removes it each time, but they keep getting reinfected). My thought is that if I remove them all at once then they can't reinfect the servers again. Then I will bring the servers up one by one and install the firewall and lock it down. Once all the servers are up with the firewalls configured, I wait and pray they continue to stay uninfected.

I will then go around to all the computers in our network and ensure they are locked down. We have about 200 desktops and 100 mobile units connecting via a VPN.

This is where I'm asking for firewall suggestions.

Link to virus info.
link 1
link 2
link 3


I apologize if this isn't making any sense. I've worked an 18 hour day so far...
 
Mar 26, 2008
148
0
0
If these are Windows servers you should make sure that they have the latest Service Packs and patches. Of course, installing Service Packs and patches on mission-critical servers is a risk in itself because in doing so it may, or may not, break something critical to your operation.
 

StormSide

Diamond Member
Oct 9, 1999
4,203
47
91
Are you certain they are getting reinfected from the network? Sounds like you haven't really gotten them 100% clean
and it is just running again after you reboot. Have you tried systernals autoruns and process explorer?
 

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
I'm pretty sure they are clean. Unless I haven't figured out all the locations it runs in. It usually takes 2 days for it to reappear. My reason for thinking its passing through the network is because
1. That's what I'm finding online on how it passes
2. When I've cleaned the servers I did them seperately, on different days

Hope I made sense, quick reply on my phone.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,049
182
116
ok so after this did you try to scan with F Secure online scanner and malwarebytes to make sure everything was gone?
you must make sure your servers are not compromised.

do you know how it got into your system yet?
 

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
These servers do not have a direct route out. Scanned with malwarebytes and it takes care of some of it, but not all. Avast server edition boot scan does a pretty good job of getting rid of it.

the virus got in through our netmotion VPN via an infected mobile unit.
 
Mar 26, 2008
148
0
0
Maybe your servers are being re-infected through the administrative shares, something to consider. If this is the case, you need to make sure all the clients are cleaned, or haven't been compromised.
 

pstylesss

Platinum Member
Mar 21, 2007
2,914
0
0
Originally posted by: snikt
Maybe your servers are being re-infected through the administrative shares, something to consider. If this is the case, you need to make sure all the clients are cleaned, or haven't been compromised.

No shared drive on these specific servers.

To get rid of it I did a boot scan with Avast server edition. Brought all the servers down at the same time. This removed all of the two letter executable files in made in the system32 folder. Then once the scan was done I turned off the servers and turned them on one at a time and brought it up in safe mode. I used a program called GMER to look at all the processes, files, registry, etc, and go through all the locations and manually delete the exe's as well as the registry entries. It's been almost 24 hours and it has not shown back up. I think I have it all taken care of now. It took me 3 hours to do this on 6(?) servers.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |