Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

"Sygate.exe" - Virus / Backdoor Trojan?

Status
Not open for further replies.

bpinning

IS-IT--Management
Feb 16, 2004
194
0
0
AU
Hi all,

Lets see what you think.
We were hit by a virus, we cleaned it, updated the machine to the latest definitions and updates from windows. But, Sygate.exe still appears and runs.

This is basically what we think it is and what it does:

- W32/Rbot-II is a worm which attempts to spread to remote network shares. It also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background as a service process.
- W32/Rbot-II spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
- W32/Rbot-II copies itself to the Windows system folder as SYGATE.EXE and creates entries at the following locations in the registry with the value Sygate Personal Firewall so as to run itself on system startup, resetting them every minute:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- W32/Rbot-II sets the following registry entries every 2 minutes:
HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"
- W32/Rbot-II attempts to delete network shares on the host computer every 2 minutes.

Our most common problem is the fact that it is sending out a DNS lookup to some king.tah"something".net then a IRC chat request to Name.service.net. It does this about every 5-6 seconds.

And the mor interesting thing is that nothing can find it. Norton, Panda, AVG all seem to fail, also adware programs cant find it either. Worm removal tools also fail.

Im out of ideas......

And help would be greatly appreciated, we have over 200 machines doing it, re-buils are out of the question, and port blocking on 888 is only a temporary measure.

Thanks heaps in advance,

Brett
 
Have you ran Spybot S&D, Adaware, sypware sweaper yet ?
Also sometime I find if I install a firewall, "I use a old Tiny fire wall" the fire wall will tell you the file name and location of the file when it trys to access the internet.
 
Hi,

Fixed...

This sygate.exe, as far as we know it is causing a DNS lookup of "king.ChiriRoza.Net" and follows with an attempt to connect to an IRC chat session on port 888, to "name.services.net".
I have virus scanned the machine with 29/10 def. and used spybot s&d, ad-aware and none of them have found the file. It sits in the windows/system32/ folder, we think it came through with sq.exe, or W32/Spybot.worm, which we got on the same day.

I sent the infected file to Symantec to be analysed, waiting for the reply....

But with an update to 31/10 Def. It findes the file, and quarantines it. All you have to do now is remove the Sygate.exe refrences in the registry and bobs your uncle its all fine, net traffic dropped to 5-8% a lot better than the 80-100% of before.

Thanks all,

Cya.
 
sygate.exe could also be Sygate Personal Firewall although I doubt it would do what you say.. However when searching I came across a more dubious site that had a home page that looked very amateurish, needless to say thats where I stopped going any further on that page.

Stu..

Only the truly stupid believe they know everything.
Stu.. 2004
 
Use Kaspersky Labs KasperSky AntiVirus, Just Kasper Can fulfill ur demands .... Tested & Working

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top