Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Virus/Spyware activity but nothing found

Status
Not open for further replies.

stussy

MIS
May 22, 2003
269
GB
Hi

We have a network of 40 ish XP/2000 machines. One of our suppliers brought his laptop (win2k) in today, and needed to get a internet connection to run terminal services over to his server. As SOON as he was on the network and using our router, I noticed everything was crawling. A look at the router (with built in firewall) showed that we had maxed out on outgoing connections (2048), and that 1500 were from his laptop, and the remaining 500 odd were from 4 of our tills, which have no need to access the outside world.

I turned the router off, and went around removing the gateway from the other win2k machines.

Everything has calmed down for the moment. It HAD to be some self-replicating thing, as while watching the router and clearing down each PC, I could see other PC's trying to get a connection. In 2 years they have never even been on the internet.

AVG and Norton have come back clean on a full scan of all the machines. I'm just running all spyware tools etc to see what I can find, but does anyone have ANY ideas what may have happened? Since removing the gateway I've had no extraneous connections, but a couple of pc's have had network issues.

Cheers

Mike
 
I suspect this may hit a few more people before the day is out.

Msnsched.exe is the offending file, a detailed report is here:


Patched and up-to-date systems are OK, which is why it only did the laptop (w2k sp1), the tills on my network (w2k sp1) and left alone everything else (w2k sp4 or XP sp2) alone.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top