Endpoint Protection

 View Only
  • 1.  virus not detected

    Posted Jul 01, 2009 09:50 AM
    A user got his home computer infected with a virus that isn’t detected by SAV. When the system is connected to the internet it first makes a connection to an IP on port 6666, I’m assuming this is to download info for the virus or to open a back door since they do not use IRC. After that connection is made the system opens up hundreds of connections to random or incremental IP blocks on port 25 and tries to send out emails.

    I got email scanning on in SAV but it doesn’t pick up a virus instead I get a bunch of messages from Symentec email proxy saying my message couldn’t be delivered, too may connections from one client and other 5XX email errors but none of them have contained the name of the virus, most of them were 5XX by the receiving email server for too many connections, spam, phishing, etc.. The emails have subjects like “our official blog”, “Please save her”, “his profile” and about 15 other subjects that it seems to rotate though.

    I disabled the email filtering to try and get PID for the process opening all of the SMTP connections using netstat –a –n –b and the PID comes back to services.exe.

    Here is the SAV info on the system.

    Windows XP Pro SP 3
    Symantec Anti-Virus 10.1.6.6010
    Scan Engine 81.3.0.13
    Virus Defs 6/30/2009 Rev 2

    I tried to run a full scan SAV, and every time I do I get “Could not start scan. Scan engine returned error 0x20000058”. I searched around for this error but couldn’t find anything on Symantec or any other site relating this error to a Virus of any type. I ran a full scan with the most up to date Spybot SnD and nothing was found.

    So, I rebooted into safe mode and was able to run a full scan with SAV in safe mode and not get the 0x20000058 error, however the scan turned up nothing, I also ran another scan with Spybot SnD and nothing was found there either.

    I didn’t really get to look at it any more then that, it was about 3am after the last scan and I decided to call it a night. If anyone had any thoughts on what it could be, or next steps please let me know.

    Thanks!



  • 2.  RE: virus not detected

    Posted Jul 01, 2009 11:05 AM
    Hi,

    What is the process behind the port 6666? This is your virus.
    Open a case with our Support to isolate and submit this process to our Security Response and we will create the proper definitions to detect and clean it.

    Cheers,





  • 3.  RE: virus not detected

    Posted Jul 01, 2009 12:30 PM
    It points back to services.exe as well.  I'm guessing whatever it is modified that exe or the process is hidden.  I didnt' have time last night to run GMER or highjack this to see if it would pick up the problem or hidden process.


  • 4.  RE: virus not detected

    Posted Jul 01, 2009 02:31 PM
    Procesexp or Autoruns can also give you details if anything is hooked into services.exe 


  • 5.  RE: virus not detected

    Posted Jul 01, 2009 02:54 PM
    some malwares run as a service, with the proper tools you can go behind the services.exe and found a .dll or an .exe or something else.


  • 6.  RE: virus not detected

    Posted Jul 08, 2009 12:32 PM
    Hi, I thought I was infected by a virus or a malware.
    At first, I had a RNCsys32.exe running at my startup. So immediately, I thought I was infected by a virus or Malware.
    I have got this issue too. What happen is that I uninstall the anti-virus and reinstall with the updated 10.1.8.8000
    All is well now.