Endpoint Protection

 View Only
Expand all | Collapse all

Very unusual pattern

  • 1.  Very unusual pattern

    Posted Feb 24, 2014 03:13 PM

    I have a user who works out of Charleston South Carolina. SEP found malicious entries on her PC, I went in and cleaned up as much as I could, but here is the twist, SEP is ALSO finding suspicious activity from her account on PC's she's never been on, and sites she's never been to. It has found malicious attached to a machine in New York and it has found suspicious entries attached to her name in a PC in Toronto. When I checked these PC's NEITHER of them had her listed under the user profile her machine was infected and cleaned, but her profile sporadically appears on differnt PC's that she's never been on.

    Any idea on this?



  • 2.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:14 PM

    It finds Trojan. ZBot and Trojan.Fake AV



  • 3.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:16 PM

    Is SEP cleaning them up?



  • 4.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:18 PM

    Yes, it shows in "Cleaned/Blocked"



  • 5.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:21 PM

    I would change her password immediately, does she have any type of admin rights at all?



  • 6.  RE: Very unusual pattern
    Best Answer

    Posted Feb 24, 2014 03:28 PM

    She had admin rights which I took away. I also have asked her to change her password.

    Thank you.



  • 7.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:30 PM

    This was key...see how it plays out now..



  • 8.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:34 PM

    Going to do this on a larger scale now.

    THX again!!!



  • 9.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:39 PM

    enjoy!



  • 10.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:48 PM

    Now she gets something about prenb.dll.

    Hmmmmm, I think that is the garbage file...



  • 11.  RE: Very unusual pattern

    Posted Feb 24, 2014 03:53 PM

    You can submit it or scan it at https://www.virustotal.com



  • 12.  RE: Very unusual pattern

    Posted Feb 25, 2014 07:58 AM

    I deleted the entry from the registry and there was another suspicuous entry, mapv.dll or something like it. Can't remember exactly



  • 13.  RE: Very unusual pattern

    Posted Feb 25, 2014 09:15 AM

    looks like it left some easter eggs behind for you to clean.



  • 14.  RE: Very unusual pattern

    Posted Feb 25, 2014 09:17 AM

    of course it would. Had to keep me busy :-)



  • 15.  RE: Very unusual pattern

    Posted Feb 25, 2014 09:21 AM

    because you have nothing else to do right crying