Link to home
Start Free TrialLog in
Avatar of DarcyAdams
DarcyAdams

asked on

Possible virus on the network

Our hardware firewall is reporting every few minutes that it has exceeded 6000 connections and will have to dump some of those connections in order to operate.  We've ran a port sniffer on some of our computers and have found that they are created large numbers of connections to port 135 on the firewall but we've ran a virus scan on each computer and nothing is coming up.  Any ideas?
Avatar of Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer
Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer
Flag of United States of America image

You probably have Spyware that is creating the attacks.  Download Spybot  http://www.safer-networking.org/en/index.html or Ad-aware http://www.lavasoftusa.com/software/adaware/ and check on those machines for spyware.  I'll bet you will find that you have a trojan or similiar causing your problems.
Avatar of DarcyAdams
DarcyAdams

ASKER

I've ran spyware and antivirus, nothing.
I used ad-aware 6.0.  After looking at the computers closer this may be the blaster all over again.  The computers weren't up to date on their windows update.  I'll update them and see if that solves any of the problems.
Avatar of bbao
you didnt mention the taffic direction, it is incoming traffic or outgoing traffic on your firewall?
Its outbound.
SOLUTION
Avatar of Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer
Steve McCarthy, MCSE, MCSA, MCP x8, Network+, i-Net+, A+, CIWA, CCNA, FDLE FCIC, HIPAA Security Officer
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
can you determine who (on your LAN) were sending the destructive packages by analysing the firewall log?
I'll try with spybot and see if it finds anything and yes we do know which computers are having issues.  We used a sniffer and had it watch a specific ip address to see what its doing.  The moment they're turned on they start sending garbage outbound to rdp 135.  The only attacks I can find on the net are the blaster that worked that way so we're running windows updates right now to see if that will prevent it from spreading too much.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial