Author Topic: computers hijacked by rogue anti-spyware  (Read 3389 times)

0 Members and 1 Guest are viewing this topic.

Offline Geowil

  • Jr. Member
  • **
  • Posts: 64
computers hijacked by rogue anti-spyware
« on: June 05, 2008, 11:24:48 PM »
Recently, some computers where I work were hijacked by something called Anti-Spy Spider.  It seems more like a Root kit because its compromised almost all of the security on the computers and our enterprise version of Sophos cant even detect it.  Its changed the desktop background and screen saver and als9o has a web page that it pulls from C:\WINDOWS whenever we try to open IE with the icon.

It brings up fake Security center pages as well claiming that the computer has become infected.

It might also have infected our network, Google has been throwing out "You network could be infected" messaged when attempting to search with it.

We are probably just going to re-image them, but I was wondering, that if it had somehow infected the network somehow, how we could go about exterminating it.  :sos:

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: computers hijacked by rouge anti-spyware
« Reply #1 on: June 06, 2008, 01:12:12 AM »
Hi, Geowil.  antispyspider is on the Malwarebytes detection list:  http://www.malwarebytes.org/malwarenet.php

The problem is that each machine would have to be taken off the network and cleaned independently.  Still no guarantee that is the only problem. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline techie

  • Full Member
  • ***
  • Posts: 100
Re: computers hijacked by rouge anti-spyware
« Reply #2 on: June 06, 2008, 04:44:20 PM »
We are probably just going to re-image them, but I was wondering, that if it had somehow infected the network somehow, how we could go about exterminating it.  :sos:

If the server is infected, re-image may only be a temporary fix, it could possibly become reinfected if you have Workstations infected as well.

Time to re-image will require a server shutdown. As well the workstations need to be checked to insure that there clean. I would think about shutting down the routing services to the workstations, check that the server is clean. Then check each workstation, even on re-image of the server, each workstation would still need to be checked, to be sure of no reinfection of the servers. It may be possible to push the cleanup from the server to the workstations.

Either way it will require some time. It is also Dependant of distance of the servers, from the workstations. 

Have you checked with Sophos, to see if they have a fix?



Offline Geowil

  • Jr. Member
  • **
  • Posts: 64
Re: computers hijacked by rouge anti-spyware
« Reply #3 on: June 09, 2008, 05:53:54 PM »
thanks for the replies.  was gone for the weekend, I will have to check with the network specialist and see if he was able to remove it from the infected computers or if he left it alone.

ill also forward him the link to this topic.

thanks again, ill let you know th end result.


Offline Geowil

  • Jr. Member
  • **
  • Posts: 64
Re: computers hijacked by rouge anti-spyware
« Reply #4 on: June 10, 2008, 11:15:24 PM »
he took the computers off the network and scanned all 8 of the servers on that site with malewarebytes, didnt find anything on them and they werent displaying any weirdness on their windows installs. :o

We are going to just re-image them later on this month along with that site's computers.  :smash:

Offline Geowil

  • Jr. Member
  • **
  • Posts: 64
Re: computers hijacked by rouge anti-spyware
« Reply #5 on: June 13, 2008, 11:13:34 PM »
well, we reimaged the computers yesterday and so far we havent seen it pop up anywhere else, so i'd say it hadn't gotten into a server yet.


thanks for the info and help though! :goodie: