Solved

Virus doing spam port scan on 1433

Posted on 2004-09-10
9
739 Views
Last Modified: 2013-12-04
Several computers with SQL 2000 service pack 3a installed are doing this occasionally. And I discovered it's a executable which show up as "sysdevice.exe" under task manager that's doing it.

I have no idea how it got there or what triggered it to run at random times. I can't find this exe anywhere on my computer to get rid of it. Right now to prevent ISP police shutting down our internet we are having the firewall block all outgoing packet to port 1433 except our remote SQL server's IP.

Anyidea what this virus is and/or how to get rid of it?
0
Comment
Question by:gotdough
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 7

Expert Comment

by:msice
ID: 12031681
Are the systems running hp OpenVMS there are varns in that and you could be getting some issues from them.
http://ftp.support.compaq.com.au/pub/ecoinfo/ecoinfo/420.htm
0
 

Author Comment

by:gotdough
ID: 12031695
No, I'm not running any of those. I think this might be a new virus
0
 
LVL 7

Expert Comment

by:msice
ID: 12031703
0
 

Author Comment

by:gotdough
ID: 12031715
I did complete check with Norton Spybot and Adaware all with latest updates under safe mode. Nothing came up.
0
Scale it in WD Gold

With up to ten times the workload capacity of desktop drives, WD Gold hard drives employ advanced technology to deliver among the best in reliability, capacity, power efficiency and performance.

 
LVL 7

Expert Comment

by:LimeSMJ
ID: 12032531
http://grc.com/port_1433.htm

Gives more info on SQL's port 1433 usage.
0
 
LVL 5

Expert Comment

by:burningmace
ID: 12033882
If you are part of a company, then any employee could have downloaded it from the web. There's some really nasty network-spreading viruses around, a lot of which hijack connections to send out messages or weaken the system. I recently got a virus which started off on a Windows XP system and managed to jump it's way through our wireless network untill all of the computers (asbout 20 or so) were infected. I had to totally disconnect us from the internet to stop hackers using the open ports the virus created to destroy our network. It took me weeks to fix, because it bound itself to other files. In the end I had to back up any documents we needed and re-format everything.

If the virus is running as "sysdevice.exe" try doing the following:
1) Start -> Run, type "regedit" (no quotes)
2) Navigate to "HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run"
3) Look for any values which contain "sysdevice.exe" in their data.
4) If you find any, go to step 5, otherwise, check "HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run". If you still get nothing, skip the rest of this and read about MSConfig at the bottom of this answer.
5) Use Ctrl-Alt-Del to close the process, if it refuses to close, go to Start -> Run and type in "cmd", then type "taskkill /IM sysdevice.exe /F" (no quotes)
6) Find and delete the EXE file in explorer, the directory shown in the registry key you found. If it's not there, it may be hidden and you might not be showing hidden files. To show hidden files, click Tools -> Folder Options, go to the "View" tab, and make sure that "Show hidden files and folders" is selected.
7) Delete the registry value that attempts to run the virus at login by highlighting it (left-click) and pressing the "Delete" or "Del" key. You can also right click it and select "Delete".
8) Restart the computer. The virus should be gone.

If you couldn't find any bootup values, use MSConfig. To do this, click Start -> Run, and type "msconfig" (no quotes). Check for anything called sysdevice in the services tab and disable it. Also, look in the startup tab for any bootup values.

Hope it's useful!
0
 
LVL 5

Expert Comment

by:burningmace
ID: 12033930
Oh yeah, I forgot to say this...

MSConfig will only delete the registry value, the file will still be there. You need to delete the file as well. I would suggest closing the virus process before you use MSConfig.

Another good idea is to Google the process name.
I just did it and it appears not to be a virus in the first place. It's a driver controller for OpenVMS that handles things like mailboxes and null drivers.

It goes to show that Google really is useful, and it should be the first place to check.

Oh well, what I said above is perfectly useful for removing viruses, if you want to stop the program, follow the anwer above but don't delete the file.
0
 
LVL 5

Accepted Solution

by:
burningmace earned 125 total points
ID: 12033943
The program is probably triggered by somebody checking their mail, or a driver being loaded. I would leave it well alone to be honest. The "spam" is probably mail and some network communication. If the program is infected by a virus (which I very much doubt), Kaspersky Anti-Virus will find it. I'm not joking, it'll find Jesus in your RAM if you ask it to, hehe.
But seriously, this process is nothing to worry about.
0
 

Author Comment

by:gotdough
ID: 12035660
Yeah I did go thru registry not only just under the Run folder but also did a complete search. Google doesn't show anything on sysdevice.exe either. I think this is just a brand new virus somehow.

The spam is what I have captured on packet sniffer, it port scans about 20 ip addresses every second. And it stopped once I terminates the exe
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
This video discusses moving either the default database or any database to a new volume.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now