Solved

2003 Server Party Poker and Mozilla Icons????

Posted on 2011-03-09
5
280 Views
Last Modified: 2012-05-11
We didn't think this was a concern at first.  I can now say I have seen this happen at 4 different sites all 2003 servers!!

PartyPoker icons will show up out of the blue on the desktop.  And Mozilla browser will install.
I have confirmed that staff had not done this - these are all dedicated servers without monitors attached!

Has anyone seen this?
0
Comment
Question by:j-teksolutions
  • 2
  • 2
5 Comments
 
LVL 38

Expert Comment

by:younghv
ID: 35093957
There will be installation files/folders that will show the actual installation date/time.
Compare those to the logon records in Event Viewer. Find out who was logged in at that time. Look for who the "Owner" of the files/folders is.

Any of that can be installed remotely, so the presence of monitors does not matter.
If they can be accessed remotely - or have access to the Internet - they are vulnerable.

Are the servers behind a hardware firewall and what security applications are you running?
0
 

Author Comment

by:j-teksolutions
ID: 35222762
We may have found a trojan i bet that this is allowing a comprimise?
0
 
LVL 38

Accepted Solution

by:
younghv earned 500 total points
ID: 35222784
Malware is always a concern in unusual situations.

You might want to start with TDSSKILLER found here:
http://support.kaspersky.com/downloads/utils/tdsskiller.zip

* Download the file TDSSKiller.zip and extract it into a folder on the infected (or potentially infected) PC.
* Execute the file TDSSKiller.exe.
* Wait for the scan and disinfection process to be over. You do not have to reboot the PC after the disinfection is over.

If the tool finds a hidden service it will prompt you to type "delete",  you can also just hit "Enter" without typing in and the scan will continue...
Then post the log to be analyzed.

Malwarebytes is pretty solid:
http://www.experts-exchange.com/A_1940.html (Basic Malware Troubleshooting)

There are a couple of other handy tools - like Hitman Pro - but I don't think we need it yet.
0
 

Author Closing Comment

by:j-teksolutions
ID: 35304750
thanks we were able to clean
0
 
LVL 3

Expert Comment

by:southwestsixteen
ID: 35304846
Hi,

I had a similar thing happen to a couple of sites a few months ago. Mozilla history showed a string of gambling and dating sites most in Russian or Czech. Check your Local Users and AD to make sure no fake user accounts have been created and given admin privileges. We also changed the domain admin password which finally resolved the issue as it seems the buggers kept getting back in even after Malware scans.

Btw, can also vouch for Malwarebytes. Run full scan though.
0

Featured Post

Resolve Critical IT Incidents Fast

If your data, services or processes become compromised, your organization can suffer damage in just minutes and how fast you communicate during a major IT incident is everything. Learn how to immediately identify incidents & best practices to resolve them quickly and effectively.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
Read about achieving the basic levels of HRIS security in the workplace.
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question