Weird things happening to Windows 2008 Standard file server

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by heatgun, Jun 11, 2014.

  1. heatgun

    heatgun Private E-2

    i all,

    We have Windows 2008 installed on our Dell server and we are using as file server with SQL database, recently I found out someone gets in our server and keeps installing toolbars, that may be auto robot installing, I have no idea, when I check history of firefox I see facebook.com, google.com some paid survey websites, links to download toolbars, I mean bunch of stuffs, I uninstalled all kind of toolbars and everything I see suspicious, changed username and passwords, changed RDP port numbers, I mean everything I can think of..
    I though I was good then today I found out more toolbars installed after business hours when no-body, literary no one had access to our office, no history from firefox though but 4 toolbars installed today at 8pm (everybody leaves at 5PM)


    Scanned server using Super antispywarebytes + malwarebytes, both scanners find following as trojan;

    "Operating System Information
    Windows Server 2008 R2 Standard 64-bit (Build 6.01.7600)
    UAC Off - Administrator

    Memory items scanned : 574
    Memory threats detected : 0
    Registry items scanned : 65709
    Registry threats detected : 2
    File items scanned : 89004
    File threats detected : 3

    Trojan.Agent/Gen-Nullo[Short]
    (x86) HKLM\System\ControlSet001\Services\WAUYKLVM
    C:\WINDOWS\SYSTEM32\DRIVERS\JUPDDA.SYS
    (x86) HKLM\System\ControlSet001\Enum\Root\LEGACY_WAUYKLVM
    C:\WINDOWS\SYSWOW64\ATTRIB.EXE
    C:\WINDOWS\SYSWOW64\SECEDIT.EXE
    "

    Server becomes unbootable If I remove files shown above, specially JUPDDDA.SYS
    Windows 2008 just wont boot without it, luckily I had back up from a night before and I was able to restore system but still have this issue, what should I do? how can I get rid of this trojan without affecting boot files.

    Thank you
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I suggest that you work thru the below but when running all the scans DO NOT FIX anything. Just run the scans and attach the logs. Ignore fixing things as requested with Malwarebytes and TDSSKiller.


    READ & RUN ME FIRST. Malware Removal Guide
     
  3. heatgun

    heatgun Private E-2

    Please see attached logs, note malwarebytes wont show anything for some reason but SuperAntiSpyware does find

    thank you
     

    Attached Files:

    Last edited: Jun 14, 2014
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the logs that were requested. That is not a TDSSKiller log and we did not request a log from SUPERAnti-Spyware. Please complete the instructions requested and attach the logs from the below scans
    • RogueKiller
    • Hitman Pro
    • Malwarebytes
    • TDSSKiller
    • MGtools
     
  5. heatgun

    heatgun Private E-2

    My bad, I have scanned all again and attached here, (MGTools wont start for some reason) hitman report was too big and I couldnt attached here so link from dropbox: https://www.dropbox.com/s/2pvqoavq1wino4m/HitmanPro_20140615_0129.log
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are infected with a vrius that can affect all executable programs on the computer. Infections like this are typically best resolved by a total clean reinstall without using any backups from the PC that were created after the point of infection.

    See the below

    http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Virus:Win32/Expiro.gen!F

    What protection software are you running? There may be a chance that Microsoft Security Essentials (MSE) can fix this as implied by the above link but you cannot have any other protection software running. Also you may have to scan this hard disk via another computer to avoid infecting MSE as it is download and installed.

    You could also check to see if th below is of any help:

    http://free.avg.com/us-en/remove-win32-expiro
     
  7. heatgun

    heatgun Private E-2


    There is no protection software installed on Windows 2008 server and MSE is NOT compatible with servers
    I guess we will go ahead and re-install Win 2008 as you advised but all our backups been removed by virus as well, so no back up prior virus infection.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You store your backups on the same computer????

    What about the AVG tool?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds