Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Is the malware removed from our server?

  • 24-03-2011 6:16pm
    #1
    Closed Accounts Posts: 89 ✭✭


    We had a problem with our server where malwarebytes picked up an infection earlier today and deleted it.

    The only details I have on that infection are from the MWB log -
    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    Since then, the networking on the server has gone very inconsistent. It is dropping on and off the network. We have a very simple setup with a drive shared out over a workgroup, and don't use a domain at all.

    I've followed the main steps in the 'I think I have a virus' thread, although things like Erunt, TFC and DDS won't run on the Windows SBS 2003 that we have. The superantispyware is running now.

    There is an intermittent unusual looking yellow triangle with an exclamation point in the system tray.

    What should I do next, please?


Comments

  • Closed Accounts Posts: 89 ✭✭suas


    So far, after 2 hours, superantispyware hasn't found anything except some cookies, and the AVG scan (paid version) has just a file with a broken digital signature.

    I used winsockfixxp, a colleague recommended it, but only after using it did I read that it's not suitable for SBS03. In any case, it seems to have fixed things up and the network connection is stable now for the past 30 minutes or so.

    Any other tips please? Is there an equivalent of Hijack This for SBS03, is it any use to run something like that?


  • Closed Accounts Posts: 89 ✭✭suas


    The malwarebytes scan completed on the server and found nothing, the AVG (paid) scan also found nothing and the superantispyware also just reported tracking cookies and nothing serious.

    Yet, in the system tray, there is this odd looking (non Windows) yellow triangle with an exclamation mark, like this one:
    stock-photo-yellow-warning-triangle-sign-with-exclamation-mark-isolated-on-white-background-52413376.jpg

    When I clicked on it, it disappeared.

    The problem that we're seeing is that the server is randomly dropping off the network, and I suspect malware since all this started when the item was removed by malwarebytes yesterday.

    Are there any investigative tools I can safely run on the server, please?


  • Registered Users, Registered Users 2 Posts: 3,491 ✭✭✭francois


    Is there intermittent connectivity? May be a dodgy cable or NIC, do you use a static IP for the server?


  • Closed Accounts Posts: 89 ✭✭suas


    That would be my first suspect if this problem hadn't started at exactly the same time as this malware was removed - and also if the odd triangle wasn't appearing.

    The NIC may have failed, or the driver for it may be corrupted/buggy. I'll try reinstalling the driver this evening when people have left, and will also replace the ethernet cable.

    We do use a static IP. Bizarrely yesterday, something was replying to a ping to that static IP even when the server was physically disconnected from the network, and that confused me!


  • Registered Users, Registered Users 2 Posts: 3,491 ✭✭✭francois


    suas wrote: »
    That would be my first suspect if this problem hadn't started at exactly the same time as this malware was removed - and also if the odd triangle wasn't appearing.

    The NIC may have failed, or the driver for it may be corrupted/buggy. I'll try reinstalling the driver this evening when people have left, and will also replace the ethernet cable.

    We do use a static IP. Bizarrely yesterday, something was replying to a ping to that static IP even when the server was physically disconnected from the network, and that confused me!

    Well that sounds like the cause-something else has that IP by the sounds of it, change the server IP and see if you still have problems


  • Advertisement
  • Closed Accounts Posts: 89 ✭✭suas


    I rebooted every computer in the office so that they'd pick up a new IP from the DHCP server (which is the firewall) and also checked the assigned leases to see if that IP had been assigned by the firewall and it hadn't.

    I have a niggling suspicion that there are traces of the removed infection causing problems - is there a tool like hijack this or something that I can use to investigate? I'm just not sure which of those tools will run on SBS 03, and how to interpret them.

    thx


  • Closed Accounts Posts: 46 obrien.cathal


    Hi,

    Microsoft have a suite of tools called SysInternals which are the job. I use them for manually removing malware and they are excellent and comprehensive. This should not be confused with the 'Sysinternals Antvirus' malware which is floating about. There are quite a few tools in there but Process Explorer and Autoruns should see you right. If you have any questions you can PM me or contact me through the contact section of my webpage.

    Cheers,
    Cathal


Advertisement