Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Mail server hit with Win32/Pecoan Virus

[Fixed] Hijackthis! Logs - [Resolved] Mail server hit with Win32/Pecoan Virus posted in the Security & Safety forums; Hi All, Just got into work this morning to find our mail server is infected with Win32/Pecoan Virus. Just great! I will post hijack log soon....

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-24-2007
madmatt2006's Avatar
PC Dinosaur
 
Join Date: Dec 2006
Location: Shepparton
Posts: 2,632
PC Experience: Elite PC Guru
madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page
Default [Resolved] Mail server hit with Win32/Pecoan Virus

Hi All, Just got into work this morning to find our mail server is infected with Win32/Pecoan Virus. Just great! I will post hijack log soon.


  #2  
Old 01-24-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,462
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

im sorry to hear about that madmatt.

Moved to HJT Logs Forum.


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 01-24-2007
madmatt2006's Avatar
PC Dinosaur
 
Join Date: Dec 2006
Location: Shepparton
Posts: 2,632
PC Experience: Elite PC Guru
madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page madmatt2006 - See this Members User comments on their Profile page
Default

Heres the hijackthis log and some info on the payload of the virus is not good!
PayloadDownloads and Executes Arbitrary Files

The trojan attempts to establish communciations with other systems on a custom peer-to-peer network. It connects to certain IP addresses through local UDP port 4000 (Win32/Pecoan.G uses local UDP port 7871) in order to download and execute arbitrary files onto the compromised system.
These IP addresses, along with possible IPs that the trojan blacklists, are stored in a file in the %System% directory. Most variants use the file name "peers.ini", while some variants use the name "wincom32.ini".
Attached Files
File Type: log hijackthis.log (3.8 KB, 2 views)


  #4  
Old 01-25-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,739
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Your HijackThis log shows nothing wrong.

Which program detected Win32/Pecoan, and what was the action taken against it?


Then run Panda ActiveScan.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:35 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top