Persistent Worm, Server 2003 R2

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bowlersaid, Oct 27, 2010.

  1. Bowlersaid

    Bowlersaid Private E-2

    What do you suggest I scan the passport drive with?

    I will get these registers clean and the system

    either that or call for an EMP and kill them all :major

    This damn thing is a huge pia -
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Scan with your AV and the other conficker tools. Also just see what happens when it is plugged in with AutoRun Eater enabled.
     
  3. Bowlersaid

    Bowlersaid Private E-2

    Plan B

    I am going to take the passport to my personal sys.
    reformat the drive, be done with it ...

    Then just reestablish the subs, not difficult
    It is just the third (so to speak) back-up

    The server has a second physical drive mirror in real time

    The passport was the fallback 3rd, it will just start over

    To be continued.........:major
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just remember one important fact, any drive that has had connectivity in any form with these infected systems on the network, may ( or may not ) be carrying the infection too.
     
  5. Bowlersaid

    Bowlersaid Private E-2

    Update---

    Ok, coming back clean , the register systems, the Mirror, The Passbook, the server... :major

    In the end, started at the farthest reach (the registers) and one at a time dropped it from the net, scrubbed it clean, and keep going until all registers were off line and scrubbed. Then scrubbed the server, the mirror and took the passport to be nuked clean. When all was clean, put the net back on line and currently running with no flags - and all scans coming back clean... Going to give it a day and a reboot or two to make sure...

    But optimism is on the horizon:wave
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great news. These infections that spread on networks can be problematic until all the infected machines get fixed. Any single machine can cause reinfection of others on the network.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds