Virus eating my bandwidth!!

Here's the thing: server's crash. Machines break. This might be a very good time to prepare an alternate machine. This forces you to do a proper disaster recovery plan, and at least you still have the original server to document.

So this is what I would suggest: Buy / borrow some hardware. Install new server, start installing all the software and document it for the next poor guy. When you are happy, swap the 2 and reinstall the first server.

You have a virus on your server. This is bad news. The only guaranteed way to get rid of it is a full reinstall. Sorry.
 
Its time to reconsider your stance on re-installing...

Whats going to get the problem sort out fastest.

1. Trying to find the problem
Originally this would be, but this far down the thread it seems your wasting a lot of valuable time spent somewhere else.

2. Clean Install
Usually not the 1st resort, but after a while not figuring out the problem...

3. New server keeping old one around.
Probably the best option if you have the hardware or funds around for this.
 
Its time to reconsider your stance on re-installing...

Whats going to get the problem sort out fastest.

1. Trying to find the problem
Originally this would be, but this far down the thread it seems your wasting a lot of valuable time spent somewhere else.

2. Clean Install
Usually not the 1st resort, but after a while not figuring out the problem...

3. New server keeping old one around.
Probably the best option if you have the hardware or funds around for this.

Fair points but I can't believe that not a single A/V kit can remove this s.o.b. I can setup another server, but what if it gets infected the moment it goes online? Or a week down the line? I always try to understand what's happening.

Currently I've got the rogue svchost.exe suspended but it's still causing some traffic on my server, who knows what it's up to..

Contrary to your .sig, I'm pretty impressed by this bug.
 
Fair points but I can't believe that not a single A/V kit can remove this s.o.b. I can setup another server, but what if it gets infected the moment it goes online? Or a week down the line? I always try to understand what's happening.

Currently I've got the rogue svchost.exe suspended but it's still causing some traffic on my server, who knows what it's up to..

Contrary to your .sig, I'm pretty impressed by this bug.

Open up msconfig ( start --> Run --> msconfig ) , and go to the startup items and services, disable EVERYTHING that you do not recognise.

Reboot and see if there's still bandwidth being used.

99% of the time this'll solve more problems than you know about.
 
Hehe Well this is funny. I wrote an app that just sends keys into the KB buffer and while that's going, the virus stays dormant.

So I'm going to run this app until one of the A/V makers comes up with a fix...
 
Umm wow, so this is your server, you know it is infected, and you are just going to use a hack to keep it running.
You have no idea of what the virus is sending out, what it is corrupting on the machine itself.

Do you not value the data that you have on that machine ?
 
Tayqon, download the Kaspersky virus removal tool.
It runs on servers both 32 bit and 64 bit. I dowload it from the link below - just look for the newest exe:
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/avptool11/

(The virus removal tool will run TDSSkiller if required, then you have to reboot to continue scanning).

When you run the virus removal tool, first go to settings and configure it to automatically remove any virus found, as by default it will flag the viruses and you have to manually select to remove.
Once complete it will require a reboot - then run the tool again to make sure it is clean. Also note that the Virus removal tool does not pick up all spyware, so when you have a clean scan from Kaspersky, run Malwarebytes and Spybot Search and Destroy to make sure.

This is a long process, but since you do not want to reload, this is the best option.
 
Get a dedicated firewall, such as Smoothwall.

You can then selectively block ports, incoming as well as outgoing.
 
Umm wow, so this is your server, you know it is infected, and you are just going to use a hack to keep it running.
You have no idea of what the virus is sending out, what it is corrupting on the machine itself.

Do you not value the data that you have on that machine ?

This.

I agree with him.

Better bite the bullet, backup all data, reinstall, install updated AV, restore, scan and away you go.

Maybe you can get away with a server upgrade at the same time? Get a new server (new hardware etc), install new server etc, get updated AV installed, copy data across etc etc.
 
Get a dedicated firewall, such as Smoothwall.

You can then selectively block ports, incoming as well as outgoing.

Agree - you can also look at Endian or Untangle that run on top of Linux and provide great firewalls/proxy etc for small businesses.
 
Umm wow, so this is your server, you know it is infected, and you are just going to use a hack to keep it running.
You have no idea of what the virus is sending out, what it is corrupting on the machine itself.

Do you not value the data that you have on that machine ?

I'm pretty sure it (was) sending out spam. I'm sure whatever was going to be corrupted is already corrupted.

I don't value the data, I'll wipe it without thinking about it, got backups, I'm value it's service. I don't want it to go down.

Either way, I'm not burning 2 days getting a new server up just to have it infected again. I need a permanent solution, not a quick fix.
 
Ye but did you try it or just read it off their website? According to google it can even run on the windows 2003 server
I downloaded it twice tried installing it. I spoke to their rep over live chat and he confirmed 2003 is no go, although he's "happy to assist me in this issue".
 
Agree - you can also look at Endian or Untangle that run on top of Linux and provide great firewalls/proxy etc for small businesses.
This is something I have to get in place. Then I can isolate the problems.

Funny thing is, I've been running many servers and desktops without any firewalls for 15 years+. It always caused more production issues that it solved. But this bug, sheesh. Although I'm still far in credit in time saved opening ports 24/7 and trying to figure out why the firewall server is not booting up by staring at a linux driver debug screen !
 
This.

I agree with him.

Better bite the bullet, backup all data, reinstall, install updated AV, restore, scan and away you go.

Maybe you can get away with a server upgrade at the same time? Get a new server (new hardware etc), install new server etc, get updated AV installed, copy data across etc etc.
Again, although it might not seem so, this is the quick fix that might (will?) bite me in the end. If I don't find a fix my brand new machine might get affected because it's on the same network running the same apps.
 
Tayqon, download the Kaspersky virus removal tool.
It runs on servers both 32 bit and 64 bit. I dowload it from the link below - just look for the newest exe:
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/avptool11/

(The virus removal tool will run TDSSkiller if required, then you have to reboot to continue scanning).

When you run the virus removal tool, first go to settings and configure it to automatically remove any virus found, as by default it will flag the viruses and you have to manually select to remove.
Once complete it will require a reboot - then run the tool again to make sure it is clean. Also note that the Virus removal tool does not pick up all spyware, so when you have a clean scan from Kaspersky, run Malwarebytes and Spybot Search and Destroy to make sure.

This is a long process, but since you do not want to reload, this is the best option.
Shot, going to try it now...
 
This is something I have to get in place. Then I can isolate the problems.

Funny thing is, I've been running many servers and desktops without any firewalls for 15 years+. It always caused more production issues that it solved. But this bug, sheesh. Although I'm still far in credit in time saved opening ports 24/7 and trying to figure out why the firewall server is not booting up by staring at a linux driver debug screen !

Try this
http://en.utilidades-utiles.com/download-comodo-firewall-windows-2003.php
http://www.filehorse.com/download-comodo/

Latest version: Comodo Internet Security 5.5.195786
Requirements: Windows XP / 2003 / Vista / Windows 7

You probably were downloading windows vista/windows 7 only one

Also not a big fan of Kapersky
 
Last edited:
Tayqon, I strongly suggest running the Kaspersky Virus removal tool.
Format and reload is best, however if you don't want to do that use the Kaspersky tool.
I use it often at customers, it does run on sever 2003, 2008, 32 or 64 bit.
I find it to be the best of the virus detection and removal tools out there.

When your server is clean, run it again, and run Malwarebytes and Spybot to make sure.
A standalone firewall would have stopped this virus from getting out of your network (assuming you only allow valid ports out of your network)and possibly even from getting on to yuor server in the first place. Just because you haven't had one, don't assume it is not a basic security requirement for a business network!

edit: (Sorry I see you posted while I was typing the above...)
 
Top
Sign up to the MyBroadband newsletter
X