Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Roger Wright
: Roger Wright [mailto:rhw...@gmail.com] Sent: Thursday, October 06, 2011 3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Roger Wright
...@gmail.com] Sent: Thursday, October 06, 2011 3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day. My long term

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Erik Goldoff
3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Cynicalgeek
Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term goals together. On Thu, Oct 6

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread John Aldrich
...@gmail.com] Sent: Friday, October 07, 2011 10:25 AM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Did it successfully install the software and NOT allow you to update the definition files? This is a good sign of an infected computer. On Thu, Oct 6, 2011 at 6:31 PM

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Cynicalgeek
...@gmail.com] Sent: Thursday, October 06, 2011 3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day. My long term goal

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Cynicalgeek
:* Friday, October 07, 2011 11:12 AM *To:* NT System Admin Issues *Subject:* Re: Torpig/Anserin/Mebroot infection ** ** Try to boot normally and update Malwarebytes now. On Fri, Oct 7, 2011 at 11:02 AM, John Aldrich jaldr...@blueridgecarpet.com wrote: Well, I was using

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread John Aldrich
9:42 AM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection bad disc clamp in CD ROM drive, preventing proper rotational speed to read the disk ??? (guessing the machines that won't read are NOT brand new) On Fri, Oct 7, 2011 at 9:13 AM, Roger Wright rhw...@gmail.com wrote

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread John Aldrich
Working on *installing* it on one of those computers. John-AldrichThread-Count From: Cynicalgeek [mailto:cynicalg...@gmail.com] Sent: Friday, October 07, 2011 11:23 AM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yes. On Fri, Oct 7, 2011 at 11:21 AM, John

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread John Aldrich
System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Try to boot normally and update Malwarebytes now. On Fri, Oct 7, 2011 at 11:02 AM, John Aldrich jaldr...@blueridgecarpet.com wrote: Well, I was using the bootable CD, so any infection on the computer should not affect

Re: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Cynicalgeek
] ** ** *From:* Cynicalgeek [mailto:cynicalg...@gmail.com] *Sent:* Friday, October 07, 2011 11:23 AM *To:* NT System Admin Issues *Subject:* Re: Torpig/Anserin/Mebroot infection ** ** Yes. On Fri, Oct 7, 2011 at 11:21 AM, John Aldrich jaldr...@blueridgecarpet.com wrote

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Paul Hutchings
John, do you do any sort of DNS or URL filtering at your firewall to control/restrict outbound traffic? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 07 October 2011 4:02 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection Well

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread John Aldrich
System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection John, do you do any sort of DNS or URL filtering at your firewall to control/restrict outbound traffic? _ From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 07 October 2011 4:02 PM To: NT System Admin Issues Subject

RE: Torpig/Anserin/Mebroot infection

2011-10-07 Thread Paul Hutchings
From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 07 October 2011 5:42 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection Not really. I don’t do much with the firewall as I don’t know much about Cisco. I rely on an outside consultant

Re: Torpig/Anserin/Mebroot infection

2011-10-06 Thread Roger Wright
John, How'd you make out with this issue? Determine the source yet? Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term goals together. On Mon, Oct 3, 2011 at 1:22 PM, John Aldrich jaldr...@blueridgecarpet.comwrote:

RE: Torpig/Anserin/Mebroot infection

2011-10-06 Thread John Aldrich
it could be a false-positive. Don't know. From: Roger Wright [mailto:rhw...@gmail.com] Sent: Thursday, October 06, 2011 12:03 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection John, How'd you make out with this issue?  Determine the source yet? Roger Wright ___ My short

Re: Torpig/Anserin/Mebroot infection

2011-10-06 Thread Cynicalgeek
: Re: Torpig/Anserin/Mebroot infection John, How'd you make out with this issue? Determine the source yet? Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term goals together. On Mon, Oct 3, 2011 at 1:22 PM, John Aldrich

RE: Torpig/Anserin/Mebroot infection

2011-10-06 Thread John Aldrich
was detected (about a dozen or two.) Do y'all know of any good free/trialware that one can download a bootable ISO for to scan for this bug? From: Cynicalgeek [mailto:cynicalg...@gmail.com] Sent: Thursday, October 06, 2011 3:16 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot

Re: Torpig/Anserin/Mebroot infection

2011-10-06 Thread Roger Wright
To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection So you have no root cause but it is resolved? On Thu, Oct 6, 2011 at 2:57 PM, John Aldrich jaldr...@blueridgecarpet.com wrote: Nope. I managed to get the ASA logging to a Linux box successfully, but it's not showing any

RE: Torpig/Anserin/Mebroot infection

2011-10-06 Thread John Aldrich
Thanks! I'll give that a shot. John-AldrichThread-Count From: Roger Wright [mailto:rhw...@gmail.com] Sent: Thursday, October 06, 2011 3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try: http

Re: Torpig/Anserin/Mebroot infection

2011-10-06 Thread Micheal Espinola Jr
:* Thursday, October 06, 2011 3:56 PM *To:* NT System Admin Issues *Subject:* Re: Torpig/Anserin/Mebroot infection ** ** Yeah... give the one from Microsoft a try: http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day

RE: Torpig/Anserin/Mebroot infection

2011-10-06 Thread John Aldrich
...@gmail.com] Sent: Thursday, October 06, 2011 3:56 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Yeah... give the one from Microsoft a try:   http://connect.microsoft.com/systemsweeper Roger Wright ___ My short term goal is to make it through the day.   My long term goal

Re: Torpig/Anserin/Mebroot infection

2011-10-04 Thread Erik Goldoff
in the firewall? -Original Message- From: Paul Hutchings [mailto:paul.hutchi...@mira.co.uk] Sent: Monday, October 03, 2011 4:04 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection Jus to confirm, you don't allow outbound SMTP from anything other than your

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Shauna Hensala
How many machines are we talking about here? All local or some in remote locations? The ISP did not provide the IP of the device that was misbehaving? Shauna Hensala From: jaldr...@blueridgecarpet.com To: ntsysadmin@lyris.sunbelt-software.com Subject: Torpig/Anserin/Mebroot infection Date

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Paul Hutchings
Can you expand on blacklisted? Which blacklist and for what type of traffic? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011 6:22 PM To: NT System Admin Issues Subject: Torpig/Anserin/Mebroot infection So, our external IP is blacklisted

Re: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Roger Wright
Have you kicked off a VIPRE deep scan on these machines? Roger Wright ___ My short term goal is to make it through the day. My long term goal is to string a bunch of short term goals together. On Mon, Oct 3, 2011 at 1:22 PM, John Aldrich jaldr...@blueridgecarpet.comwrote: So, our

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
: RE: Torpig/Anserin/Mebroot infection How many machines are we talking about here?  All local or some in remote locations?  The ISP did not provide the IP of the device that was misbehaving? Shauna Hensala From: jaldr...@blueridgecarpet.com

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
Issues Subject: RE: Torpig/Anserin/Mebroot infection Can you expand on blacklisted?  Which blacklist and for what type of traffic? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011 6:22 PM To: NT System Admin Issues Subject: Torpig/Anserin

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
Not yet. I can do so though. John-AldrichThread-Count From: Roger Wright [mailto:rhw...@gmail.com] Sent: Monday, October 03, 2011 2:55 PM To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Have you kicked off a VIPRE deep scan on these machines? Roger Wright

Re: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Richard Stovall
infection Can you expand on blacklisted? Which blacklist and for what type of traffic? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011 6:22 PM To: NT System Admin Issues Subject: Torpig/Anserin/Mebroot infection So, our

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
To: NT System Admin Issues Subject: Re: Torpig/Anserin/Mebroot infection Are you using ASDM? Can't you filter the builtin realtime log viewer in a way that might show you the infected machines? (It's been a long time since I've used ASDM...) On Mon, Oct 3, 2011 at 2:59 PM, John Aldrich jaldr

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Paul Hutchings
Issues Subject: RE: Torpig/Anserin/Mebroot infection Can you expand on blacklisted? Which blacklist and for what type of traffic? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011 6:22 PM To: NT System Admin Issues Subject: Torpig/Anserin

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Kennedy, Jim
did CBL get into the non-email abuse gets your email blocked business. -Original Message- From: Paul Hutchings [mailto:paul.hutchi...@mira.co.uk] Sent: Monday, October 03, 2011 4:04 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection Jus to confirm, you don't allow

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Shauna Hensala
you *should* be able to do virus scan of your network and identify the culprit. Shauna Hensala From: jaldr...@blueridgecarpet.com To: ntsysadmin@lyris.sunbelt-software.com Subject: RE: Torpig/Anserin/Mebroot infection Date: Mon, 3 Oct 2011 14:58:42 -0400 I did not receive notification

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Paul Hutchings
: Torpig/Anserin/Mebroot infection This is very interesting, can't wait to see that answer. I doubt it was on port 25, that Trojan looks to phone home with credentials of the infected user, it is not an email bot as far as I can tell. And the two open questions will be; 1) No matter what port

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
4:04 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection Jus to confirm, you don't allow outbound SMTP from anything other than your corporate SMTP boxes do you? From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
suspects with Malware Bytes, but didn't see any infection. As I said, Vipre Enterprise will be deep-scanning tonight. From: Shauna Hensala [mailto:she...@msn.com] Sent: Monday, October 03, 2011 4:10 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection you *should* be able to do

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Paul Hutchings
. From: John Aldrich [jaldr...@blueridgecarpet.com] Sent: 03 October 2011 9:14 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection We don't have a mail server here. Our ISP hosts our email for us, so yeah, we do allow SMTP out. I wonder if there's a way to force all port

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Tammy Stewart
[mailto:paul.hutchi...@mira.co.uk] Sent: Monday, October 03, 2011 4:19 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection You really don't want to be doing that, or if you must do it at least only allow it outbound to the IP of the mail server your PC's are supposed to be using. Looking

Re: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Angus Scott-Fleming
On 3 Oct 2011 at 16:14, John Aldrich wrote: We don't have a mail server here. Our ISP hosts our email for us, so yeah, we do allow SMTP out. I wonder if there's a way to force all port 25 traffic to one IP in the firewall? There's usually a way to limit port-25 traffic to only one IP. It

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread Bourque Daniel
/Anserin/Mebroot infection On 3 Oct 2011 at 16:14, John Aldrich wrote: We don't have a mail server here. Our ISP hosts our email for us, so yeah, we do allow SMTP out. I wonder if there's a way to force all port 25 traffic to one IP in the firewall? There's usually a way to limit port-25 traffic

RE: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
[mailto:paul.hutchi...@mira.co.uk] Sent: Monday, October 03, 2011 4:19 PM To: NT System Admin Issues Subject: RE: Torpig/Anserin/Mebroot infection You really don't want to be doing that, or if you must do it at least only allow it outbound to the IP of the mail server your PC's are supposed to be using

Re: Torpig/Anserin/Mebroot infection

2011-10-03 Thread John Aldrich
On Mon October 3 2011, you wrote: On 3 Oct 2011 at 16:14, John Aldrich wrote: We don't have a mail server here. Our ISP hosts our email for us, so yeah, we do allow SMTP out. I wonder if there's a way to force all port 25 traffic to one IP in the firewall? There's usually a way to limit