Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

backdoor windows.exe virus? (c.bat / .pif) 2

Status
Not open for further replies.

Bremer

IS-IT--Management
Sep 20, 2002
5
US
Anyone seen this?

Windows.exe process monopolizing CPU on infected machines

Infected machines flood network with ARP requests for random IP addresses apparently based on subnet (i.e. 10.10.*.*).

On a hit, the ARP response to the infected host will kick off an (?)RPC(?) sequence to copy .pif, then c.bat, and finally windows.exe.

In addition to propagating itself, it appears to try to connect to 213.35.161.4

Affecting Win2K server and professional

Thanks...

 
Had this, the way we handled it was to disconnect all pc's from network and clean each one by removing the exe and all occurrances of .pif, the exe, and c.bat from the registry.
There can be a couple of exe's that are on it. One is similar to MS Messenger, and one is similar to windows update. If I remember correctly, msmsng.exe and wnupdate or something similar. After all pc's are clean you may then connect them to the network. BUT NOT UNTIL ALL of them are clean, If even one pc is missed, you will re-infect them all again.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top