Worm + Spyware?

Phoenix86

Supreme [H]ardness
Joined
Mar 28, 2002
Messages
6,653
Well, this is early in the discovery process, but here's what we're seeing.

We have several machines, about 8 out of about 600 that are getting either massive spyware issues or sasser like 60 second shutdown warning windows.

This all happened after we deployed a number of recent patches (I will get a list shortly if someone has some wants it, IIRC it was the recent slew of MS patches) through our SUS sever. We do not force patching/reboots, so it's likely many of the machines have not been patched. The patches may or may not have anything to do with the issue. We had people report they ran the patch, rebooted and were having issues. We had another who hadn't run the patch, and was seeing the issue.

One of the machines was cleaned by hand, we used automated tools (MS Antispy+ one other) to get as much off as possible. Then we used hijackthis to get the rest off. It appeared to work, we were able to reboot several times and the process weren't starting.

The second machine was re-imaged.

After doing little work on the machines (testing standard apps on the first, adding the other to the domain, and opening outlook) both were "infected" again. Once infected the machine appears to download an install other various spyware (making finding the cause a little harder). I'll get a hijack this log in a bit to let you see what's going on.

So what it looks like is a worm that installs spyware, that downloads and installs other spyware. :rolleyes:

Again, we JUST started TSing this problem, some of all of this may be incorrect/incomplete. :p

Anyways I'm not so much asking for help, we seem to be making headway. This is kinda a heads up, I guess...

 
Post any new info, as it would affect our 140,000 machines as well, I'm sure.

And what's with the <reserved>? Cheap method of raising post count??? :D
 
postcount ++ ;)

Heh, no, it's a seperate post for the logs. We are re-imaging the machine (3rd time, was reinfected both previous re-images) so we can get a clean hijack this log. Well, cleaner, as I mentioned it seems to d/l OTHER spyware so gimme some time to post it...

Heh, I'm teasing my own posts.

***ALERT!!! DANGEROUS NEW MALWARE***

See the report on News 5 at 10. :p

 
I was gonna add to this joke... but no.

If you get the hijack this logs or can track down a name, I'd be interested. A few of my friends keep getting hit with everything imaginable. I'm like a doctor... they don't listen to me.

 
arkamw said:
I was gonna add to this joke... but no.

It's all in good fun. I've been talking to Phoenix86 away from the forum and he knows we're just playin'.....and waiting for the logs as well so we can begin to disect.
 
Yeah, I know. I'm just not funny enough to think of anything to add that would be funny. I was gonna add another <reserved> but it seemed repetetive. Will you settle for a postcount ++?
 
Well as fast as it came it went... :confused:

There really is a whole lot more information we collected, but it's so convoluted with other spyware we couldn't find the culprit. Since the "clean" machine never got it again, we never got a good log. Unfortunately I wasn't the only person working on this, and for a while everyone else was in "clean it" mode and wasn't collecting information. By the time we realized what was going on, it stopped and we didn't get good data.

We'll see what happens today... I kinda suspect this came in on an outside machine that connected to the network. "It" stopped later in the day, like someone took a laptop off the network and went home for the day (early too, bastards).

 
Back
Top