J
John Daragon
I'm a contract developer working on-site for a client in the UK with
about 600 Windows machines - a mix of XP, Win2003, some Win2000 and a
couple of NT4.0 boxes. The network appears to be well maintained, and we
have up-to-date McAfee virus protection on all of the boxes.
Alas, we appear to have a virus infection, and I've been unable so far
to identify the culprit, so I thought I'd describe the symptoms here to
see if anyone recognised it...
The symptoms we have noticed so far are these:
On the Win2003 and XP boxes Windows File Protection has replaced all
files with extensions of .exe and .dll in %SYSTEMROOT%, with the
exception of explorer.exe. This appears to happen intermittently and
during login.
On the Win2000 machines (which are mainly members of a Citrix
application farm), where there is no WFP, the damage has consisted of
the deletion of .exe and .dll files from %SYSTEMROOT%, so I sort of
assume that's what would be happening on XP/2003, too.
There appears to be no unusual network traffic, and no unexpected ports
appear to have listeners associated with them (although I use typical
developer PCs with 4 different RDBMS systems &c on them, so my port map
is a bit cluttered at the best of times...)
All in all, although we have to take down the odd 2000 machine to
re-image it, the impact we've noticed so far has been pretty light but
I'm worried that there may be other payloads that I'm not yet aware of.
Does this ring any bells with anyone ?
jd
about 600 Windows machines - a mix of XP, Win2003, some Win2000 and a
couple of NT4.0 boxes. The network appears to be well maintained, and we
have up-to-date McAfee virus protection on all of the boxes.
Alas, we appear to have a virus infection, and I've been unable so far
to identify the culprit, so I thought I'd describe the symptoms here to
see if anyone recognised it...
The symptoms we have noticed so far are these:
On the Win2003 and XP boxes Windows File Protection has replaced all
files with extensions of .exe and .dll in %SYSTEMROOT%, with the
exception of explorer.exe. This appears to happen intermittently and
during login.
On the Win2000 machines (which are mainly members of a Citrix
application farm), where there is no WFP, the damage has consisted of
the deletion of .exe and .dll files from %SYSTEMROOT%, so I sort of
assume that's what would be happening on XP/2003, too.
There appears to be no unusual network traffic, and no unexpected ports
appear to have listeners associated with them (although I use typical
developer PCs with 4 different RDBMS systems &c on them, so my port map
is a bit cluttered at the best of times...)
All in all, although we have to take down the odd 2000 machine to
re-image it, the impact we've noticed so far has been pretty light but
I'm worried that there may be other payloads that I'm not yet aware of.
Does this ring any bells with anyone ?
jd