^`d}qZxu and ~`d}qzxu3zYF Help me to find this

This is for non-Subaru related topics. Keep it realistic please.

Moderator: Moderators

Post Reply
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

^`d}qZxu and ~`d}qzxu3zYF Help me to find this

Post by ciper »

Look in your registry for these. Post a reply if you see either


^`d}qZxu
~`d}qzxu3zYF
Specifically look under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

Also look under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

If affected use TCPVIEW from Sysinternals to see which applications are listening on the ports.

%systemroot%\system32\soundman.exe is probably what you will see.
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

If the virus is running soundman.exe is hidden.

If you create a text file in your temp folder and rename it soundman.exe it will disapear!
eastbaysubaru
Knowledgeable
Knowledgeable
Posts: 1312
Joined: Wed Oct 16, 2002 10:44 pm
Location: Northern Sonoma County
Contact:

Post by eastbaysubaru »

How is it spread?

-Brian
'04 PSM FXT
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

Nobody really knows yet. The AV vendors aren't as smart as you think, they know its a varient of another older virus so they assume it uses the same infection method.

I have more details about it if anyone is interested.
JasonGrahn
Knowledgeable
Knowledgeable
Posts: 1333
Joined: Tue Oct 15, 2002 4:55 pm
Location: Seattle, WA
Contact:

Post by JasonGrahn »

feel free to post details online of your virus. oh wait.. your computer virus.
-Jason Grahn
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

Booting safe mode and running stiner 2.1.5 will get rid of most the files.

Check your host file for redirection of many web sites to 127.0.0.1

The two registry entry I mentioned should be manually deleted

One way I thought of preventing infection was to create a file named soundman.exe in the system32 folder and removing all permissions from it (click advanced and then uncheck inherity permissions and choose remove).

Also changing the host file back to original and giving everyone including administrators and the system account read only access will prevent redirection.

So far this virus seems to spread through an unpatched hole. We have had machines without email applications get infected.
Machines that did not have a c$ administrative share where infected
Machines that DIDNT have a blank local password got it
Machines that werent part of the domain got it
Plus we use SUS on some machines and they got infected.
Legacy777
Site Admin
Site Admin
Posts: 27884
Joined: Tue Oct 15, 2002 11:37 am
Location: Houston, Tx
Contact:

Post by Legacy777 »

did the machines still have the admin$ share there....that gets shared out too

Other then that....I don't really see how it'd get through......
Josh

surrealmirage.com/subaru
1990 Legacy (AWD, 6MT, & EJ22T Swap)
2020 Outback Limted XT

If you need to get a hold of me please email me rather then pm
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

Ill double check that one, didnt notice.

I almost think its another RPC hole or something.
Legacy777
Site Admin
Site Admin
Posts: 27884
Joined: Tue Oct 15, 2002 11:37 am
Location: Houston, Tx
Contact:

Post by Legacy777 »

wonderful....that means I get the fun job of patching all our stupid old nt4 automation machines........at least the 2k machines will get it through policies....and will just need reboots.
Josh

surrealmirage.com/subaru
1990 Legacy (AWD, 6MT, & EJ22T Swap)
2020 Outback Limted XT

If you need to get a hold of me please email me rather then pm
ciper
Knowledgeable
Knowledgeable
Posts: 4388
Joined: Tue Oct 15, 2002 8:16 pm
Location: SFCA

Post by ciper »

You should try SUS for the 2K/XP machines. It works well and reduces internet traffic significantly. Plus you control exactly what patches they do/dont get.
Legacy777
Site Admin
Site Admin
Posts: 27884
Joined: Tue Oct 15, 2002 11:37 am
Location: Houston, Tx
Contact:

Post by Legacy777 »

Yeah I had it setup on one of our servers and was going to use it, but it changed permissions. So I need to set it up on another server and change the group policies to point to it.

Right now it's just going to WU site to get the stuff.

This network of automation machines was put together so hap-hazardly....it's pityful....and thing that gets me is these are mission critcal machines and some of them are running old dell desktop machines 400 mhz 128mb ram
Josh

surrealmirage.com/subaru
1990 Legacy (AWD, 6MT, & EJ22T Swap)
2020 Outback Limted XT

If you need to get a hold of me please email me rather then pm
Post Reply