Author |
Message |
cloaked_wolf
What's a life?
Joined: Thu Apr 23, 2009 8:46 pm Posts: 10022
|

All of the computers in the workplace are suppled by the primary care trust. They've provided AV software through Sophos. The problem is that one computer was being worked on and had a warning come up about a virus on the system and how it needs to scan the computer. The manager was savvy enough to contact me rather than press anything and I immediately knew a trojan had gotten in and was trying to pass off as security software. My first action was to yank the LAN cable to stop potential spread; I then forced the computer off and ripped out the hard drive. Plan is to run it through my own anti virus and antitrojan software. Important files are always backed up.
Things I need to know:
- how can I detect the route it came through? The manager had been looking at bank accounts at the time before using Sage software. She denies any other usage at the time and I trust her word implicitly.
- how can I detect the spread? Given that Sophos never picked it up or did anything, it is quite conceivable that it may have spread undetected elsewhere. I honestly feel like ripping out all of the hdd and scanning them manually as an external drive.
- how can I check to ensure the backed up files on the servers, and the servers themselves, aren't affected?
_________________ He fights for the users.
|
Sat Dec 01, 2012 3:24 pm |
|
 |
MrStevenRogers
Spends far too much time on here
Joined: Fri Apr 24, 2009 9:44 pm Posts: 4860
|
find out which trojan it is first and then work from there
chances are (if nothing was executed) that it is on the one system only ...
_________________ Hope this helps . . . Steve ...
Nothing known travels faster than light, except bad news ... HP Pavilion 24" AiO. Ryzen7u. 32GB/1TB M2. Windows 11 Home ...
|
Sat Dec 01, 2012 11:00 pm |
|
 |
saspro
Site Admin
Joined: Thu Apr 23, 2009 5:53 pm Posts: 8603 Location: location, location
|
Sounds more like scareware than a trojan. Which would explain why Sophos didn't find it. Malwarebytes should clear it & will tell you where it was, from there you can work out from their history which site caused it.
|
Sun Dec 02, 2012 10:35 am |
|
 |
JJW009
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 6:58 pm Posts: 8767 Location: behind the sofa
|
It would be safest to erase the disk and re-image the machine, after saving any important data. If it really does have something nasty in it, they often have registry keys which reload the malware as soon as there's an internet connection. This will happen even though every file on the disk is "clean".
I think some software can scan off-line registry files, but I can't recommend any.
As to "where did it come from", unless something obvious shows up in Internet Explorer's browse history then that kind of detective work is certainly beyond my skills and may actually be impossible.
_________________jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly." When you're feeling too silly for x404, youRwired.net
|
Sun Dec 02, 2012 11:43 am |
|
 |
cloaked_wolf
What's a life?
Joined: Thu Apr 23, 2009 8:46 pm Posts: 10022
|
Unfortunately, we don't have the images - the PCT has them, which would mean reporting this. I've ran both Sophos and Malwarebytes on the HDD. They picked up infected files in the Temporary Internet Files, Application Data and System Volume Information folders. This is with the HDD as an external USB drive. Plan now is to see if the computer will boot up and see what happens.
_________________ He fights for the users.
|
Mon Dec 03, 2012 9:02 am |
|
 |
JJW009
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 6:58 pm Posts: 8767 Location: behind the sofa
|
Boot it up with no network connection.
Then plug the network in and run a netstat to see if it connects to anything. There's a chance it'll just re-download the files.
_________________jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly." When you're feeling too silly for x404, youRwired.net
|
Mon Dec 03, 2012 10:40 am |
|
 |
MrStevenRogers
Spends far too much time on here
Joined: Fri Apr 24, 2009 9:44 pm Posts: 4860
|
disable system restore before doing this !!! ...
_________________ Hope this helps . . . Steve ...
Nothing known travels faster than light, except bad news ... HP Pavilion 24" AiO. Ryzen7u. 32GB/1TB M2. Windows 11 Home ...
|
Mon Dec 03, 2012 12:14 pm |
|
 |
cloaked_wolf
What's a life?
Joined: Thu Apr 23, 2009 8:46 pm Posts: 10022
|
Deleted system restore points. Netstat didn't show anything abnormal. Computer has been running fine all day.
_________________ He fights for the users.
|
Mon Dec 03, 2012 7:27 pm |
|
|