ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    virus cleanup-advise needed

    IT Discussion
    virus malware
    3
    12
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AmbarishrhA
      Ambarishrh
      last edited by

      Hi all

      Need some help on cleaning up a server, just got access and told to check.

      Rackspace is managing this server and their report:

      https://www.virustotal.com/en/file/8c2a8af66ca0d1cd1c80fba6fb38f2bd86b148ee08de926b815416709d452835/analysis/
      
      This is the report
      
      Process Monitor identified that the "C:\Program Files\Java\jre6\java.exe" process was malicious.
      The java.exe processes was installed as a service, and it had created dependencies on itself for multiple system services.  I cleared out these dependencies with the following commands:
      sc config RpcSs depend= /
      sc config Dhcp depend= /
      sc config Dnscache depend= /
      sc config gpsvc depend= /
      sc config PolicyAgent depend= /
      sc config Netman depend= /
      sc config Spooler depend= /
      sc config SamSs depend= /
      sc config SENS depend= /
      
      I then stopped and disabled the java service followed by a restart of IIS.  Once complete your site started responding again.
      
      

      Now I am trying to find the right tools to clean this server, any suggestions please. Its a very long time i havent worked on malware cleanup! 🙂

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        RS isn't managing very well if they are expecting you to manage it for them!

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          I never cleanup malware, I always rebuild. So much safer.

          1 Reply Last reply Reply Quote 2
          • AmbarishrhA
            Ambarishrh
            last edited by

            This is for one of our close contact with the company who asked us to help them, option for a rebuild was suggested but looks like they dont have a healthy backup to start with. So i have to clean this up, get the iis site back up and running and then see what we could do to make it better and avoid issues

            I am checking bleepingcomputer one of my fav old time site for malware removal.

            1 Reply Last reply Reply Quote 1
            • travisdh1T
              travisdh1
              last edited by

              Looks like someone clicked a link while working on the server if that java.exe is actually malicious.

              1 Reply Last reply Reply Quote 0
              • AmbarishrhA
                Ambarishrh
                last edited by

                Just did an online eset scan, its not just java!

                C:\Program Files\Jenkins.zip	multiple threats,a variant of MSIL/Spy.Agent.AES trojan,a variant of Win32/ServU-Daemon.AB potentially unsafe application	
                C:\Program Files\Java\jre6\java.exe	a variant of Win32/ServU-Daemon.AB potentially unsafe application	
                C:\Program Files\Jenkins\java.exe1	a variant of Win32/ServU-Daemon.AB potentially unsafe application	
                C:\Program Files\Jenkins - Copy\java.exe	a variant of Win32/ServU-Daemon.AB potentially unsafe application	
                C:\tmp\1.1	Linux/Setag.B.Gen trojan	
                C:\tmp\20AS	a variant of Linux/ChinaZ.F trojan	
                C:\tmp\20AS.1	a variant of Linux/ChinaZ.F trojan	
                C:\tmp\30AS	a variant of Linux/ChinaZ.F trojan	
                

                And more of this kind!

                travisdh1T 1 Reply Last reply Reply Quote 0
                • travisdh1T
                  travisdh1 @Ambarishrh
                  last edited by

                  @Ambarishrh Yuck, that thing will probably never be completely clean.

                  1 Reply Last reply Reply Quote 1
                  • AmbarishrhA
                    Ambarishrh
                    last edited by

                    I have the same feeling. Informed them to do the rebuild and just take the iis file. Will scan that seperately

                    scottalanmillerS 1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @Ambarishrh
                      last edited by

                      @Ambarishrh said in virus cleanup-advise needed:

                      I have the same feeling. Informed them to do the rebuild and just take the iis file. Will scan that seperately

                      Scanning an IIS file is easy, scanning a whole server is essentially impossible.

                      1 Reply Last reply Reply Quote 2
                      • AmbarishrhA
                        Ambarishrh
                        last edited by

                        Can webroot help me here, thinking of using webroot and see if it can clean

                        travisdh1T scottalanmillerS 2 Replies Last reply Reply Quote 0
                        • travisdh1T
                          travisdh1 @Ambarishrh
                          last edited by

                          @Ambarishrh said in virus cleanup-advise needed:

                          Can webroot help me here, thinking of using webroot and see if it can clean

                          Possibly, but you're dealing only with possibilities. Would be much better if you can rebuild and move/scan the IIS files.... that assumes IIS was the only thing running on the box.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Ambarishrh
                            last edited by

                            @Ambarishrh said in virus cleanup-advise needed:

                            Can webroot help me here, thinking of using webroot and see if it can clean

                            Maybe. Anything "might" work. But you'll never know.

                            1 Reply Last reply Reply Quote 0
                            • 1 / 1
                            • First post
                              Last post