Weird Virus! Formatting the computer doesnt get rid of it.

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Sends 30 billion (according to the network card) packets per second on port 445, to the University of Wisconsin IP range.


Formatting the computer and removing all the files, reinstalled windows XP, and its back. Without plugging it into anything, or sticking in any contaminated disks... fresh install of windows XP



Any ideas? Bios infected on the network card? I have no clue.
 

Viper22

Golden Member
Oct 9, 1999
1,607
0
76
Bootsector virus possibly...you would need to do a low level format on the HDD to get rid of it.
 

Maybe your network card is bad. 3 GB/sec. is impossible from a 10/100 Mbps card.
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Im not saying its actually sending that much, but the number is 300000000000000000 with tons of zeros after it
 

EyeMWing

Banned
Jun 13, 2003
15,670
1
0
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
Originally posted by: EyeMWing
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?

I'm sorry but port 445 to a specified range.. sounds viral to me
 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Originally posted by: EyeMWing
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?

3 other computers on campus has it...... same things, thats what gave me the idea.
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
Originally posted by: dxkj
Originally posted by: EyeMWing
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?

3 other computers on campus has it...... same things, thats what gave me the idea.

You didn't answer my 2 questions.. I work in the security/virus field..
 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the network admins noticed the extreme influx from the computer
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445
 

EyeMWing

Banned
Jun 13, 2003
15,670
1
0
Originally posted by: dxkj
Originally posted by: EyeMWing
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?

3 other computers on campus has it...... same things, thats what gave me the idea.

Okay, now it sounds like some dickhead in EE/CS trying to be cool.

Edit: Do all three machines have the same/similar NICs?
Edit: And furthermore, since I assume you're using some reporting software to pull these numbers, does the machine exhibit the same symptoms from outside the OS (i.e. during boot) (watch the NIC or hub LEDs)
 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445



ok, what am I looking for? Sending someone over to run the program right now.

green or red? :)
 

OutHouse

Lifer
Jun 5, 2000
36,410
616
126
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445

Cool program. Thanks.

 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: dxkj
Originally posted by: EyeMWing
Faulty network card - that's freaking impossible. What ever gave you the idea it was a virus?

3 other computers on campus has it...... same things, thats what gave me the idea.

Sounds like some kind of nimda or blaster variant if it is trying to use port 445 (microsoft active directory)

Make sure you do not plug into any network, patch the machine entirely through CD. Otherwise you'll just pick up the worm as soon as you boot.
 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Process: svchost.exe:736

Protocol: UDP

Local Adress: ComputerName:bootpc

Remoted Address: *.*

State: blank
 

hevnsnt

Lifer
Mar 18, 2000
10,868
1
0
Originally posted by: dxkj
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445



ok, what am I looking for? Sending someone over to run the program right now.

green or red? :)

Either on port 445.. It will show you what program is sending/receiving on that port. Remember though, that this port is a Microsoft admin port, so windows components might be using it as well.. Look for weird things like svch0st (that is a zero) or other weird things.
 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445



Ok, I just found out that it is sending TO port 445 not, sending out on port 445....



ok, what am I looking for? Sending someone over to run the program right now.

green or red? :)

Either on port 445.. It will show you what program is sending/receiving on that port. Remember though, that this port is a Microsoft admin port, so windows components might be using it as well.. Look for weird things like svch0st (that is a zero) or other weird things.

 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
Originally posted by: dxkj
Originally posted by: hevnsnt
also, when you reinstalled XP was it on the network? It might have got re-infected as soon as it came back on..

tried scanning, nothing comes up



Disconnected from the network the entire time once the virus was discovered

Disconnected during format & reinstall?

Download TCPview and see what is using port 445



Ok, I just found out that it is sending TO port 445 not, sending out on port 445....



ok, what am I looking for? Sending someone over to run the program right now.

green or red? :)

Either on port 445.. It will show you what program is sending/receiving on that port. Remember though, that this port is a Microsoft admin port, so windows components might be using it as well.. Look for weird things like svch0st (that is a zero) or other weird things.

 

dxkj

Lifer
Feb 17, 2001
11,772
2
81
30 billion sent per second
15 trillion and counting (he just turned the machine on again).


lsass:524 (only other process that shows up)



692 736 872 are the ports being used for all the svchost processes..

None go crazy unless you disable the network card, then the bootpc one shows up.
 

txxxx

Golden Member
Feb 13, 2003
1,700
0
0
Formatting doesnt get rid of it as its reinfecting the fresh install of the system upon reboot and connection to network via RPC exploit or something similar. Wipe out again and firewall before network connection?