Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,295 members, 7,808,004 topics. Date: Thursday, 25 April 2024 at 02:21 AM

Virus Problems On Windows Systems In Network - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Virus Problems On Windows Systems In Network (4249 Views)

How To Resolve Insufficient Space Problems On Android Device / Solutions To Gaming Problems On Pc / Cost Of Laptops And Other It Systems In Nigeria And Abroad (can We Save Money?) (2) (3) (4)

(1) (Reply) (Go Down)

Virus Problems On Windows Systems In Network by wilkanah(m): 2:09pm On Jul 07, 2006
Virus Wahala

i manage a small linux network with a linux server and windows / linux clients.

i'm having virus trouble but while all the window's systems are down the linux systems are not infected.

i have a shared folder on the server where everyone keeps files in transit. i suspect the virus is in this folder but the cost of deleting it is pretty high (there's quite a lot in this folder).

i've backed up 3 windows systems and reinstalled at various times but it only takes a while before they go down a again.

since the virus doesn't take effect on linux, i can't tell where exactly it is or what it is.

effect --- it reboots the windows system when a user tries to use the command line, takes over the shutdown process once you select shutdown (doesn't give u enough time to use the menu i.e hibernate, restart, shutdown), it reproduces in each folder the foldername.exe and some other data.administrator folder(you see this last effect even on the linux systems).

i've used mcaffe 2006, it doesn't find anything.

since i can't format all my systems and loose all my data. what i have to do i find adequate antivirus protection for my windows systems, or move all my systems to linux which i can't do at the moment because of some programs i need to run.

so guys, what i need from u (precisely someone who has had a similar experience) is info on any antivirus that can protect my windows machines from this virus.

i don't even know the name.

thanks 4 all your brilliant suggestions.
Re: Virus Problems On Windows Systems In Network by kenshin(m): 2:22pm On Jul 07, 2006
Try out Symantec Norton antivirus 2005 or avast from www.avast.com
I use Norton 2005 personally, it protects my windows box despite using flash drives from diverse sources.
Re: Virus Problems On Windows Systems In Network by Seun(m): 2:25pm On Jul 07, 2006
What you are facing is a worm that uses the network to spread. Your Mcafee antivirus is obviously not updated, and you probably don't install the latest Windows Updates on your Windows XP systems. Hmmm.

Here are some steps I'll suggest:
- Download AVG antivirus using a Linux system.
- Make sure you also download the file containing the latest updates.
- Format a FLASH drive or diskette with your Linux system
- Copy the AVG antivirus installer and updates into the drive.
- Disconnect [/b]all infected Windows systems on your network.

For each infected Windows PC:
- Boot it up in [b]Safe Mode
(without networking).
- Uninstall McAfee or any other antivirus.
- Install AVG antivirus software and the latest updates.
- Scan your hard drive(s) using the AVG.
- Scan the shared folder (if it has not yet been scanned).
- Reboot the system if prompted, and then
- Connect it to the network once more.

Using the above procedure, you'll be able to deal with the problem without reformatting any system. I have used it this system to clean a laptop with such a virus, so please make sure you use it. wink
Re: Virus Problems On Windows Systems In Network by wilkanah(m): 2:56pm On Jul 07, 2006
thanks, i'll try it and let u know how far, but how do i get the virus out of the linux systems
4 all i know the virus is in one of them and it'll get back to the windows machines just in time?
Re: Virus Problems On Windows Systems In Network by Seun(m): 3:06pm On Jul 07, 2006
Even if the shared folder on a Linux server has the virus, it won't affect the Linux system. You just need to scan the shared folder with the first Windows system you clean, so other Windows systems won't be affected.

Once you finish with this process, make sure you update the antivirus regularly and the Windows updates too.
Re: Virus Problems On Windows Systems In Network by Svchost(m): 4:36pm On Jul 07, 2006
With the virus already resident, that might prove a little bit tough, and this means you got to be tough.

Firstly, check your event viewer from your administrative tool for any information registed regarding the recent activities on your windows system. And with the system event ID and source, you could search for the information thru the net, which could lead to a result that could identify the exact virus possibly, and then a solution. With that you can deal with that problem.

Secondly,
1. If the above does not workout, I suggest, you will need move out the entire documents from the shared folder to an external device, both on the Linux unit, but Remember, to disconnect the system from network.
2. After that above, uninstall all antivirus (both sperm detector/ blocker, if any) from the windows system, and make sure you manually delete their program folder paths in the system and possibly inside the system registry –REGEDIT- (be careful) – if possible a manual delete of the uninstalled program folder and the registry entries will be best done in safe mode.
3. Make a new antiviral software installation to the latest version (AVG Ok) and update your windows to latest patch files, before bringing back your files.
4. Let me know, if any progress
Re: Virus Problems On Windows Systems In Network by Chxta(m): 5:14pm On Jul 07, 2006
Download and install Zone Alarm. As for the Linux system, what distro are you using? Install AntiVir for Linux and scan it. It would detect any Windoze virus lurking around. . .
Re: Virus Problems On Windows Systems In Network by wilkanah(m): 5:25pm On Jul 07, 2006
SuSE 9 on d linux clients, SuSE 10 on the server, fedora here, red hat there

thanks 4 all d info, i'm already working on getting all d antivirus software and shld be testing all this later 2day.
Re: Virus Problems On Windows Systems In Network by Chxta(m): 7:12pm On Jul 07, 2006
SUSE's package manager is RPM based. Download this and untar it. Good luck man. . .
Re: Virus Problems On Windows Systems In Network by wilkanah(m): 3:52pm On Jul 08, 2006
thanks a lot guys,
got avg for windows and avg for linux and i was able to install on my windows boxes, of course after uninstalling mcaffe (just like u said). It discovered and healed all infected files. had to loose stuff here there cos now some programs don't start, but the virus is no longer in effect and i believe the systems r ok now.
had some problems installing on my linux boxes but lemme battle with that on monday, the doc attached says i gotta get some phyton blah blah,
i'll take care of it.
thanks a lot for all d info.
u were right. twas a worm.
I-WORM/VB.GB and i think it spread itself thru a file BRENGKOLANG.EXE, which i found in the c: drive of all the windows systems.
ese gon!
Re: Virus Problems On Windows Systems In Network by sbucareer(f): 9:52am On Jul 10, 2006

In future as a network administrator, buy or tell your organization to buy a backup media. Backup your files everyday, toward the end of business activity.

Make sure you have 7 media tapes, give each one seven days rotation. If there is money buy more than 7. To really solve this problem you NEED to know the virus name. I am suprise people are giving you prognosis without the virus name.

Anyway, like one member said, read your Event Viewer and Identify the date and id of any process irregularity and take it from there.

Anti virus does not protect your PC if you can not update your definition file from the antivirus company. Futhermore, your antivirus is useless if it does not know or heard about the virus before.

It is like our immune system, everything is a disease to it, unless he knows that, by having it on its database. That is why some people suffer for diabetes, because the immune system sees that sugary food as disease and he must attack it. They have no way of registering sugar to their immune system database.

Even your email or any other things that enter your network card is a virus, unless the antivirus is told, what is a virus and what is not. 

So, find the virus name and search the internet on how to clean that virus from your system.

If you are really the genuine license holder of the antivirus software, send them email with your license key number and tell them exactly what you have told us, you would get  more positive answer, since you work for a cooperate organization, I wouldn't see that as a problem, would I?
Re: Virus Problems On Windows Systems In Network by Nobody: 7:41am On Jul 29, 2006
Great technical support!

[off-topic] i notice that sbucareer's posts are always in the courier monospaced typeface,
Re: Virus Problems On Windows Systems In Network by cipancute: 7:44am On Jul 29, 2006
first u need to get the hidden file filename. i just cleared a few computers on a network from a worm called Brontok (indonesian made) and your symptom matched all of the worm characterisation.

it reboots your pc because it looks for certain words that run on your taskmanager (by the way, this virus load everytime you starts your explorer, )

it also disables registry editing, so the best way, first identify which kind of sub-worm that infect your system because cleaning is slightly different for each sub worm for example brontok.A

then look for how to clean it on sophos website. smiley sorry, im not in any way affiliated with sophos but i've found the manual solution there, good luck ,

(1) (Reply)

Clean Hp Compaq 6710b Laptops @ 25k / Help! My Gmail Account As Been Disable. / Ccna, Ccnp, Oracle, Comptia, Microsoft Certification Exam Center In Nigeria

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 33
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.