Hunting down a virus in an office

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • mon2
    Badcaps Legend
    • Dec 2019
    • 13846
    • Canada

    #1

    Hunting down a virus in an office

    Hi. We have an office client who has been contacted by the local internet provider that one of the office Windows PCs is infected with a virus. The report has been confirmed. Apparently through a remote outside trigger, this virus is performing brute force attacks around the world from this local IP address at varying times. Aside from low level formatting each PC, what is the recommended approach for this case? Running F-prot (suggested by the internet supplier) has come up empty. We are planning to run hijack this. At this time, we do not know which PC is creating this issue. Internet provider is also suggesting to run Wireshark. However, what is the value if the virus is dormant during this log excercise?

    Run online scanner using Windows safe boot with networking?

    Welcome feedback. Thanks.
  • stj
    Great Sage 齊天大聖
    • Dec 2009
    • 30934
    • Albion

    #2
    the isp needs to be more forthcoming, they know the machine i.d.
    i suspect they dont want to reveal just how much they can log for the government.

    get the log from them - see how often it happens like hourly or daily etc.

    now the bad news.
    thanks to microsoft pushing for the UEFI standard, it's possible the shitware is installed in the bios or it's secret partition on the primary drive!!!

    it's also possible but unlikely that it's installed in the router.

    Comment

    • mon2
      Badcaps Legend
      • Dec 2019
      • 13846
      • Canada

      #3
      Thank you! Will review.

      Comment

      • harp
        Badcaps Veteran
        • Jun 2022
        • 586
        • Planet Earth

        #4
        In one my testing of unwanted connection of various os and device, I use some stanalone fully isolated laptop like wifi hotspot with wireshark monitoring........... http://www.youtube.com/watch?v=oi2VOkPITqQ Maybe you can do same, to disconnect tested computer and via usb wificard conect to wireshark hotspot... you give very little information about what number of computer is in network and what information (ip, address...) you collect from isp... the program in case of detection of network connectivity usualy send request to try connect to desired server...

        Comment

        • Zippy Tee
          New Member
          • Jan 2025
          • 2
          • UK

          #5
          Depending who owns the Internet Router,either you or the SP can log onto device and run 'Packet Capture' depending on the router.
          It should be discovered where high utilization is being ran & the type of traffic, which in turn will help you track down the dodgey device.

          Once resolved, maybe worth investing in a Firewall or investigate your loophole in the network after..

          Happy Hunting.

          Comment

          • sam_sam_sam
            Badcaps Legend
            • Jul 2011
            • 6024
            • USA

            #6
            If your router has the capability to show you every device on your network then start looking at that particular device that has a lot of traffic more than other devices on the network beyond that I really do not know what else to suggest or recommend

            Or find a very good anti virus program and run it several times on each machine's hard drive ( preferably on another computer that you know that is not infected with a virus and just run the anti virus software on just the computer's hard drive so all files can be scanned not just some of them just like you flash drives and back in the day with floppy disks ) and you might find which computer it is but if your internet provider has contacted you I would suspect that maybe all of your computers on that network might be compromised and or infected with it virus ( one note not all antivirus software are the same some are better than others )

            One note I have read somewhere that depending on what type of virus or malware it is even formatting the hard drive may not help because it goes deeper than just the hard drive I personally do not how true this is

            I firmly believe that if you do not need to be hooked to internet to complete your tasks at hand do not be hooked to the internet because now days you have to worry about being hacked or malware and being held for ransom money to me it not worth it

            I have battery testing machine that I refuse to hook to a computer that has access to internet because of these issues that I have mentioned above

            If I can not do what I need to do on a tablet I really do not need to do it
            If my tablet gets hacked I will reformat it back to the factory settings like you bought it from the store and if does not work properly after that I will destroy it so it can not do anymore harm to anyone else

            I have a new computer to download software for my battery testing machines on different computers and later on do 3D cad drawing for my 3D printer maybe later on this year I hope to get back into drawing components that I need to make
            Last edited by sam_sam_sam; 01-20-2025, 08:37 PM.

            Comment

            • stj
              Great Sage 齊天大聖
              • Dec 2009
              • 30934
              • Albion

              #7
              pc's are compromised by design,
              you can secure some of them but not all.

              firstly the bios may have malware like "computrace" hidden in it - that can edit both windows AND linux to insert itself into the harddrive at boot!
              then if it's an intel system you have the Management Engine in the chipset itself that runs in standby and has full acess to the drives, ram and networking!!
              MEcleaner can rip it out of some systems but not all.
              the ME cannot be seen by the o.s. because it runs on a seperate microcontroller that is not linked to the cpu!

              AMD?
              who knows - i have no idea what AGESA can do!

              Comment

              • Mattz_GT
                Member
                • Jan 2025
                • 19
                • United Kingdom

                #8
                For a difficult virus, you really need to try one or more bootable "rescue" disks (I'm old, its USBs now) as some viruses can hide while running / intercept the actions of an AV program

                Comment

                Related Topics

                Collapse

                • Document Archive
                  MEDION AKOYA P15645 + MS Office Home&Student 2019 Notebook Specification for Upgrade or Repair
                  by Document Archive
                  This specification for the MEDION AKOYA P15645 + MS Office Home&Student 2019 Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the P15645 + MS Office Home&Student 2019 boardview and P15645 + MS Office Home&Student 2019 schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please...
                  09-06-2024, 05:00 PM
                • Document Archive
                  ASUS VivoBook S330UA-EY033T + MS Office Home & Student 2019 Notebook S13 Specification for Upgrade or Repair
                  by Document Archive
                  This specification for the ASUS VivoBook S330UA-EY033T + MS Office Home & Student 2019 Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the S330UA-EY033T + MS Office Home & Student 2019 boardview and S330UA-EY033T + MS Office Home & Student 2019 schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the...
                  09-06-2024, 03:21 PM
                • Document Archive
                  ASUS ZenBook UX3410UF-GV180T + MS Office Home & Student 2019 Notebook Specification for Upgrade or Repair
                  by Document Archive
                  This specification for the ASUS ZenBook UX3410UF-GV180T + MS Office Home & Student 2019 Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the UX3410UF-GV180T + MS Office Home & Student 2019 boardview and UX3410UF-GV180T + MS Office Home & Student 2019 schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly...
                  09-06-2024, 03:21 PM
                • Document Archive
                  ASUS VivoBook S406UA-BM013T + MS Office Home & Student 2019 Notebook S14 Specification for Upgrade or Repair
                  by Document Archive
                  This specification for the ASUS VivoBook S406UA-BM013T + MS Office Home & Student 2019 Notebook can be useful for upgrading or repairing a laptop that is not working. As a community we are working through our specifications to add valuable data like the S406UA-BM013T + MS Office Home & Student 2019 boardview and S406UA-BM013T + MS Office Home & Student 2019 schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the...
                  09-06-2024, 03:21 PM
                • Document Archive
                  SHUTTLE XPC slim Office DL1000XA XPC slim J4005 Specification for Upgrade or Repair
                  by Document Archive
                  This specification for the SHUTTLE XPC slim Office DL1000XA can be useful for upgrading or repairing a desktop PC that is not working. As a community we are working through our specifications to add valuable data like the XPC slim Office DL1000XA boardview and XPC slim Office DL1000XA schematic. Our users have donated over 1 million documents which are being added to the site. This page will be updated soon with additional information. Alternatively you can request additional help from our users directly on the relevant badcaps forum. Please note that we offer no warranties that any specification,...
                  09-12-2024, 03:28 PM
                • Loading...
                • No more items.
                Working...