Question

W32/Sality.gen.c running rampant on network...

Asked by: CecilAdmin

Has anyone seen this virus recently?  Somehow this virus has entered our network and is dropping other trojans and rootkits such as the following:

+ NTRootKit-AB (Trojan)
+ RemAdm-ProcLaunch!171 (Remote Admin Tool)
+ Spam-Mailbot (Trojan)

The virus seemed to spread quickly today.  We have various versions of McAfee Enterprise installed on the network.  Some clients have 8.0, 8.5i, and 8.7i.  The servers all have th latest 8.7i and the 04/13/09 McAfee DAT.  Despite being protected with On-Access, Access Protection, and overflow protection, this virus seems to disable the client version and redistribute the virus to servers via mapped network drives and/or vise versa.  Quite common is the autorun.inf which seems to initiate the virus from either the server or the client which kicks off various .pif files, infectious exes, other autorun.infs, and/or trojans.  We have flirted with disabling Autorun (on all drives) via GPO with no success.

Has anyone seen this or have any recommendations?   Various online resources and contact seems to yield minimal results.  Any information would be greatly appreciated.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-04-14 at 00:33:13ID24319594
Tags

W32/Sality.gen.c

,

McAfee

,

NTRootKit-AB (Trojan)

,

RemAdm-ProcLaunch!171 (Remote Admin Tool)

,

Spam-Mailbot (Trojan)

Topic

Anti-Virus

Participating Experts
3
Points
500
Comments
15

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. About the trojan Dvldr
    Hi everybody! I need your help to d with a trojan called "Dvldr". My Norton Anti-virus had detected a Dvldr trojan in two files in the system32 folder (I am using Win 2000): "Inst.exe", "Dvldr32.exe". It then failed to repair or quarantine the i...
  2. mousebut.exe trojan?
    I have had two instances of people with this virus/trojan in the last week. One on Win 98 was captured by Norton but left a reference to it in the win.ini on start-up. I removed the win.ini reference and all is OK The other, today on Win 2000 Pro was captured by Norton, but...
  3. What is the reasons of spreading viruses in LAN ?
    Hi all of security experts ! I work now in microsoft netowrk that conatins about 800 PCs win2000 and XP and controlled by DC . I need to know 1.generally what is the reasons of spreading viruses in LAN ? 2.as technician members we have limited rights in doamin and we a...
  4. Mcafee Outbound Files
    What are the consequences of turning off "Outbound Files" scan on Mcafee Virus Scan 4.5.1..... ? It seems to double to speed of older PCs....

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: bigpadhakooPosted on 2009-04-14 at 02:08:30ID: 24136138

i recommend you to download trojan remover to fix this and all other existing rootkit threats. you can download a trial version of fully functional  30 days copy. follow this link. http://www.simplysup.com

 

by: ryan80Posted on 2009-04-14 at 02:31:48ID: 24136269

this is a nasty virus that can sometime make you have to format.  Try these suggestions:

http://www.bleepingcomputer.com/forums/lofiversion/index.php/t215884.html

I have always liked Combofix, Malwarebytes, and rogueFix which is a batch file and have found needs to be run first before Combofix for nasty bugs.  

Remember, the virus will try to infect any media you connect to it, so consider it tainted and format it. Disable autorun.

AVG makes a Sality remover
http://free.avg.com/virus-removal.ndi-67769

Good luck.

 

by: xtreminatorPosted on 2009-04-14 at 04:43:02ID: 24137041

SpyDLLRemover is effective solution to remove root kits from system.

ryan80 is right avg make sality remover, u need to run it in safe mode.

make weapon of these couple of tools and get rid off it .

 

by: ryan80Posted on 2009-04-14 at 06:50:42ID: 24138143

In case safe mode is corrupted too, you can try Roguefix which is a batch file that will remove a lot of root kits.  I have had to use this first sometimes in safe mode before I could run a standard antivirus.

Also you could use something like BartPE if things are really rediculous. it is a bootable OS that runs in RAM. it has add ons that you can use to do things like virus scans.

 

by: CecilAdminPosted on 2009-04-14 at 10:57:06ID: 24140818

Awesome feedback.  We are proceeding with many examples including the ones mentioned here.  A lot of the infected clients will not boot into Safe Mode at all in which case we are trying to run a couple mods/scripts to try to re-enable its functionality.

 

by: ryan80Posted on 2009-04-14 at 11:02:41ID: 24140874

Roguefix is a text file that runs as a batch file.  I have not found a single virus yet that prevented it from running.  It usually allows you to be able to run Combofix afterwards.

 

by: CecilAdminPosted on 2009-04-14 at 12:49:27ID: 24141834

The Roguefix does not restore the Safe Mode functionality though.... the virus corrupts the computer and force it to load Windows normal mode to load itself in memory (Safe Mode, Safe Mode with Networking, and Safe Mode with Command Prompt all Blue Screen) then the virus will actually kill the AVG removal tool.

 

by: ryan80Posted on 2009-04-14 at 13:03:28ID: 24141971

yeah, Roguefix doesnt restore safe mode, but it can make it usable.

 

by: ryan80Posted on 2009-04-14 at 13:04:22ID: 24141980

It can kill the virus that stops safe mode and the virus removal tool.  At least ive seen it do it with other viruses

 

by: CecilAdminPosted on 2009-04-14 at 13:57:23ID: 24142494

How can we get safe mode restored -- that should be one of the first steps to be able to run a successful scan without the virus running in memory, for example.  We've pondered BartPE.  I am willing to open another expert question too.

 

by: CecilAdminPosted on 2009-04-14 at 14:46:59ID: 24142990

http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/
^We found this site which works great for XP clients; however, I am thinking the keys are probably different on Windows Server 2003 SP1 and SP2?

 

by: CecilAdminPosted on 2009-04-14 at 19:30:20ID: 24144364

^We were able to export the keys from another Win2k SP2 Ent server and import them into the suspect servers to regain access to safe mode with command prompt for virus scans.

 

by: ryan80Posted on 2009-04-15 at 06:11:08ID: 24147529

nice find. that can really come in handy

 

by: CecilAdminPosted on 2009-04-18 at 20:01:15ID: 24177771

McAfee 8.7i w/ AntiSpyware Module 8.7 with the latest DAT up until Friday 04/17 still would not clean the virus.  It would detect but not clean.  McAfee argued that it was running in memory, but we could replicate the issue on a clean image every time on multiple computers.  If an infected USB drive was plugged into a clean machine or an infected drive mapped, the virus would jump immediately (or vise versa).  McAfee would detect it, but fail to clean it as you could see the virus begin to spread across the machines.

We finally got our ticket escalated up to level 4 with McAfee after submitting the variant to AVERT w/ relative logs in which case early Friday morning they released a 04/17 beta Super DAT.  We replicated the exact same scenario as before, however, with the newly applied new DAT McAfee 8.7i was able to not only detect the virus, but also clean it essentially stopping it from spreading which previous DATs were unable to do.  They have a process of including the DATs in the next DAT interval, so hopefully if anyone runs across this virus it can actually be stopped with the latest McAfee DATs.  In the meantime, I believe the beta Super DAT (at least on Friday) on their page will suffice in case they have no bundled it yet with the latest DAT release...

http://vil.nai.com/vil/virus-4d.aspx
^avvwin_xdatbeta.exe

 

by: CecilAdminPosted on 2009-05-19 at 11:32:04ID: 24425013

http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-041814-2904-99&tabid=3
http://www.symantec.com/security_response/writeup.jsp?docid=2008-042106-1847-99&tabid=3

^We ended up imaging the client machines.  Any essential clients or servers that could not be duplicated, we followed Symantec's removal guide that also included specific registry keys to remove and/or fix.

We found that despite the machines being clean and up to date, registry key values detailed in the above Symantec links were added by the virus and/or related drops making the machine vulnerable to connect to the Internet and reinfect itself.  While the McAfee software would now detect and clean On Access, the process would continue due to the vulnerability.  Plus, if any new variants popped-up, we would be extremely susceptible to new infections.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...