Virus eating my bandwidth!!

If it is the Morto worm you have got a lot of work ahead of you - you have to check and clean every pc in your network!
See the Symantec post on Morto:
http://www.symantec.com/security_response/writeup.jsp?docid=2011-082908-4116-99&tabid=2

Make sure all passwords on server and workstations are changed and made secure!
Do not underestimate the severity of the situation you are in. Personally, I would shut down the network now and run scans on all machines. Only reconnect a machine if you are sure it is clean.

Right now a standalone firewall would help as you could block:
.jifr.net
.jifr.co.be
.jifr.co.cc
210.3.38.82

Most important - install an up to date antivirus program, use Microsoft Security essentials on workstations if you do not have one. Buy one for the server - Symantec,Kaspersky, McAfee, Nod32...
 
Last edited:
Get a dedicated firewall, such as Smoothwall.

You can then selectively block ports, incoming as well as outgoing.
I have actually tried to download smoothwall, but I can only "request a trial", looks like a process, will try again if it's worth it?

Only thing is, in my experience, requesting a trial means it's bloody expensive.
 
If it is the Morto worm you have got a lot of work ahead of you - you have to check and clean every pc in your network!
See the Symantec post on Morto:
http://www.symantec.com/security_response/writeup.jsp?docid=2011-082908-4116-99&tabid=2

Make sure all passwords on server and workstations are changed and made secure!
Do not underestimate the severity of the situation you are in. Personally, I would shut down the network now and run scans on all machines. Only reconnect a machine if you are sure it is clean.

Right now a standalone firewall would help as you could block:
.jifr.net
.jifr.co.be
.jifr.co.cc
210.3.38.82

Most important - install an up to date antivirus program, use Microsoft Security essentials on workstations if you do not have one. Buy one for the server - Symantec,Kaspersky, McAfee, Nod32...

I don't think it's morto after all - there is no reference to svchost.exe and the files to look for to identify morto, simply is not on my server. Nod32 did not pick it up. Symantic I havent tried, to be honest. McAfee - I could not find a 2003 compatible version. My passwords are all changed, accounts blocked and no-one has RDP permissions. Still virus runs happily.
 
Tayqon, I strongly suggest running the Kaspersky Virus removal tool.
Format and reload is best, however if you don't want to do that use the Kaspersky tool.
I use it often at customers, it does run on sever 2003, 2008, 32 or 64 bit.
I find it to be the best of the virus detection and removal tools out there.

When your server is clean, run it again, and run Malwarebytes and Spybot to make sure.
A standalone firewall would have stopped this virus from getting out of your network (assuming you only allow valid ports out of your network)and possibly even from getting on to yuor server in the first place. Just because you haven't had one, don't assume it is not a basic security requirement for a business network!

edit: (Sorry I see you posted while I was typing the above...)

Thanks, still downloading, Spybot & Malware Bytes only picked up 1 cookie. I'm not assuming anything - I'm just saying I've spent many ours more fixing issues caused by firewalls than what I've spent cleaning up the odd silly virus. Everyone disagrees with me, even my peers, but they are wrong :P Of course firewalls help to govern employees' access to the web. It's got it's uses but not for me, maybe not even for this case, because RDP port is open, otherwise, what's the use of having RDP.
 
Last edited:
I'm not assuming anything - I'm just saying I've spent many ours more fixing issues caused by firewalls than what I've spent cleaning up the odd silly virus. Everyone disagrees with me, even my peers, but they are wrong :P
You are probably right about your history so far. But what is important is also the future. If a virus (or malicious user) completely trashes your server, can you live with it? Is it worth the insurance money (a firewall and the time it takes to keep it running)?

For applications that are regularly backed up, and have low uptime requirements, I tend to agree with you that security often comes at a price (in terms of time) that is not worth it.
 
I've been reading posts, and not to show my ignorance, but is the file svchost.exe where it will be? i sometimes shutdown my PC and it says "waiting for svchost.exe to close"??? Have i got this thing too? I'm on uncapped, so not sure if i might have it!
 
I've been reading posts, and not to show my ignorance, but is the file svchost.exe where it will be? i sometimes shutdown my PC and it says "waiting for svchost.exe to close"??? Have i got this thing too? I'm on uncapped, so not sure if i might have it!

Don't worry about it, unless your anti-virus is a bit, well, dated.

svchost is on all Windows machines: This is, afaik, just a wrapper around a 32bit process, i.e. this program runs other programs. You can't remove svchost, and you can't stop all svchost processes.

Of course, svchost can be used to run malicious software, as in this thread, but your problem is not in the host dll / svchost.
 
Don't worry about it, unless your anti-virus is a bit, well, dated.

svchost is on all Windows machines: This is, afaik, just a wrapper around a 32bit process, i.e. this program runs other programs. You can't remove svchost, and you can't stop all svchost processes.

Of course, svchost can be used to run malicious software, as in this thread, but your problem is not in the host dll / svchost.
Ah, many thanks Bin. You may have confirmed my fears, as i don't have an anti-virus at all ! HECTIC. Will get Kaspersky this afternoon and see.
 
I have actually tried to download smoothwall, but I can only "request a trial", looks like a process, will try again if it's worth it?

Only thing is, in my experience, requesting a trial means it's bloody expensive.

That's the commercial version.

Look at the Express version, it's the free version ---> http://www.smoothwall.org/


The difference between the corporate (commercial) and the express version is that with the corporate version you get paid-for support 24x7. With the express version you can ask on the forum for help, there will be volunteers.





Also, I've been running Smoothwall as firewall with Win2k3 server for a long, long time now, and haven't picked up any nasty worms/trojans/viruses. Or any bootup problems.
 
Last edited:
That's the commercial version.

Look at the Express version, it's the free version ---> http://www.smoothwall.org/


The difference between the corporate (commercial) and the express version is that with the corporate version you get paid-for support 24x7. With the express version you can ask on the forum for help, there will be volunteers.





Also, I've been running Smoothwall as firewall with Win2k3 server for a long, long time now, and haven't picked up any nasty worms/trojans/viruses. Or any bootup problems.

Brilliant, trying it now.
 
the real fun starts when you find more than one virus ;)
the way i see it AV's are only effective when installed on a clean setup from the start, else they can't really keep the system inoculated

i guess you could go through the registry trying to remove all the offending things in startup, but ja time and effort. then only to have it come back a few reboots later

what joy i had with virtuamonde and generic.trojan.downloader some years ago
 
Also, I've been running Smoothwall as firewall with Win2k3 server for a long, long time now, and haven't picked up any nasty worms/trojans/viruses. Or any bootup problems.

When you say *with* you mean your win2k3 is on a separate computer to the smoothwall server? Looks like one need a dedicated machine?
 
When you say *with* you mean your win2k3 is on a separate computer to the smoothwall server? Looks like one need a dedicated machine?

Yes.

Smoothwall is a "dedicated" firewall. This means that nothing can get past it once you set it to block certain ports.

A "software" firewall, such as Zonealarm etc, can be bypassed with a rootkit. But not a dedicated firewall.

Plus, you can have all sorts of modifications and add-ons to your Smoothwall, such as tracking bandwidth usage, web content filtering and so on.

Said dedicated machine can be as low as a Pentium2 with 128Mb RAM and a 4Gb HDD.
 
Yes.

Smoothwall is a "dedicated" firewall. This means that nothing can get past it once you set it to block certain ports.

A "software" firewall, such as Zonealarm etc, can be bypassed with a rootkit. But not a dedicated firewall.

Plus, you can have all sorts of modifications and add-ons to your Smoothwall, such as tracking bandwidth usage, web content filtering and so on.

Said dedicated machine can be as low as a Pentium2 with 128Mb RAM and a 4Gb HDD.
Fair enough, but I'm running out of space in my study...

Maybe I should just get a proper managed router. Can anybody suggest one with a proper firewall?
 
Top
Sign up to the MyBroadband newsletter
X