Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 778
  • Last Modified:

Virus doing spam port scan on 1433

Several computers with SQL 2000 service pack 3a installed are doing this occasionally. And I discovered it's a executable which show up as "sysdevice.exe" under task manager that's doing it.

I have no idea how it got there or what triggered it to run at random times. I can't find this exe anywhere on my computer to get rid of it. Right now to prevent ISP police shutting down our internet we are having the firewall block all outgoing packet to port 1433 except our remote SQL server's IP.

Anyidea what this virus is and/or how to get rid of it?
0
gotdough
Asked:
gotdough
  • 3
  • 3
  • 2
  • +1
1 Solution
 
msiceCommented:
Are the systems running hp OpenVMS there are varns in that and you could be getting some issues from them.
http://ftp.support.compaq.com.au/pub/ecoinfo/ecoinfo/420.htm
0
 
gotdoughAuthor Commented:
No, I'm not running any of those. I think this might be a new virus
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 
gotdoughAuthor Commented:
I did complete check with Norton Spybot and Adaware all with latest updates under safe mode. Nothing came up.
0
 
LimeSMJCommented:
http://grc.com/port_1433.htm

Gives more info on SQL's port 1433 usage.
0
 
burningmaceCommented:
If you are part of a company, then any employee could have downloaded it from the web. There's some really nasty network-spreading viruses around, a lot of which hijack connections to send out messages or weaken the system. I recently got a virus which started off on a Windows XP system and managed to jump it's way through our wireless network untill all of the computers (asbout 20 or so) were infected. I had to totally disconnect us from the internet to stop hackers using the open ports the virus created to destroy our network. It took me weeks to fix, because it bound itself to other files. In the end I had to back up any documents we needed and re-format everything.

If the virus is running as "sysdevice.exe" try doing the following:
1) Start -> Run, type "regedit" (no quotes)
2) Navigate to "HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run"
3) Look for any values which contain "sysdevice.exe" in their data.
4) If you find any, go to step 5, otherwise, check "HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run". If you still get nothing, skip the rest of this and read about MSConfig at the bottom of this answer.
5) Use Ctrl-Alt-Del to close the process, if it refuses to close, go to Start -> Run and type in "cmd", then type "taskkill /IM sysdevice.exe /F" (no quotes)
6) Find and delete the EXE file in explorer, the directory shown in the registry key you found. If it's not there, it may be hidden and you might not be showing hidden files. To show hidden files, click Tools -> Folder Options, go to the "View" tab, and make sure that "Show hidden files and folders" is selected.
7) Delete the registry value that attempts to run the virus at login by highlighting it (left-click) and pressing the "Delete" or "Del" key. You can also right click it and select "Delete".
8) Restart the computer. The virus should be gone.

If you couldn't find any bootup values, use MSConfig. To do this, click Start -> Run, and type "msconfig" (no quotes). Check for anything called sysdevice in the services tab and disable it. Also, look in the startup tab for any bootup values.

Hope it's useful!
0
 
burningmaceCommented:
Oh yeah, I forgot to say this...

MSConfig will only delete the registry value, the file will still be there. You need to delete the file as well. I would suggest closing the virus process before you use MSConfig.

Another good idea is to Google the process name.
I just did it and it appears not to be a virus in the first place. It's a driver controller for OpenVMS that handles things like mailboxes and null drivers.

It goes to show that Google really is useful, and it should be the first place to check.

Oh well, what I said above is perfectly useful for removing viruses, if you want to stop the program, follow the anwer above but don't delete the file.
0
 
burningmaceCommented:
The program is probably triggered by somebody checking their mail, or a driver being loaded. I would leave it well alone to be honest. The "spam" is probably mail and some network communication. If the program is infected by a virus (which I very much doubt), Kaspersky Anti-Virus will find it. I'm not joking, it'll find Jesus in your RAM if you ask it to, hehe.
But seriously, this process is nothing to worry about.
0
 
gotdoughAuthor Commented:
Yeah I did go thru registry not only just under the Run folder but also did a complete search. Google doesn't show anything on sysdevice.exe either. I think this is just a brand new virus somehow.

The spam is what I have captured on packet sniffer, it port scans about 20 ip addresses every second. And it stopped once I terminates the exe
0

Featured Post

New feature and membership benefit!

New feature! Upgrade and increase expert visibility of your issues with Priority Questions.

  • 3
  • 3
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now