Advertisement

06.05.2008 at 12:09PM PDT, ID: 23461541 | Points: 500
[x]
Attachment Details

Mysterious New Rootkit Infection?

Asked by grayhat08 in HijackThis Software, Intrusion Detection Systems (IDS), Operating Systems Network Security

Tags:

Over the period of about a month, all our VPN laptops seem to be getting infected with what must be a rootkit of unknown origin. McAfee, SpyBot and SpySweeper can't seem to find any bugs, but our IDS has been alerting me to these symptoms: ICMP Ping, L3 Retriever Ping, NETBIOS SMB IPC$ share access. At first the suspect computer will start generating ICMP pings, then L3retriever pings and finally it will try to SMB to our fileserver. It's like a virus is spreading from laptop to laptop. I asked some CISSP guys and they suspected a rootkit of unknown origin.

Attached is a HijackThis log from one of the laptops.Start Free Trial
Attachments:
 
HijackThis log file
 
[+][-]06.05.2008 at 06:33PM PDT, ID: 21725558

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.05.2008 at 11:48PM PDT, ID: 21726743

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.07.2008 at 08:16AM PDT, ID: 21735821

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.12.2008 at 06:17PM PDT, ID: 21775039

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.17.2008 at 11:16PM PDT, ID: 21810524

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.19.2008 at 12:19AM PDT, ID: 21819909

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.19.2008 at 05:49AM PDT, ID: 21821608

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.25.2008 at 12:52PM PDT, ID: 21869245

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20081112-EE-VQP-42 / EE_QW_2_20070628