Advice for batch of viruses (3days in a row)

Hi,
We've been hit 3 days in a row with the same virus (variant).
First day it was:
wire-confirm0120.src (can't remember the name of the zip file)
trans_completed6341289_pdf.zip
fax-message921497.zip
I'm sure we will get hit tomorrow as well and i'd like some advices on to secure our network without bringing down Exchange or blocking all ZIP files. Our virus définitions are up to date.
I'm sure there's a pattern and we can somehow prevent the infection.
Thank you

Lisa - we just used standard free tools to disinfect machines, like Malwarebytes, Kaspersky TDSSKiller, etc.
I managed to format the Kaspersky pdf a little better. It's not pretty, but it's readable. If you can to block the ftp urls in your content filtering software or firewall you can probably prevent it from downloading the bad files that it drops in the C:\Windows
folder.
Keep in mind, this is for only the fax-message921497.scr file. I have no info on the others.
SHA256: 86f1b78efe2bc736b5d85bb75d2920130fb9ddbf1a41480a44a660e5a3803aba
File name: fax-message921497.scr
Opened files
C:\WINDOWS\system32\mfcsubs.dll (successful)
C:\86f1b78efe2bc736b5d85bb75d2920130fb9ddbf1a41480a44a660e5a3803aba (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\tusi01T.txt (failed)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\tusi01T.txt (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\mscodecs.exe (successful)
\\.\PIPE\lsarpc (successful)
c:\autoexec.bat (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
C:\WINDOWS\system32\rsaenh.dll (successful)
\\.\pipe\net\NtControlPipe10 (failed)
Read files
C:\WINDOWS\system32\mfcsubs.dll (successful)
C:\86f1b78efe2bc736b5d85bb75d2920130fb9ddbf1a41480a44a660e5a3803aba (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\tusi01T.txt (successful)
c:\autoexec.bat (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
C:\WINDOWS\system32\rsaenh.dll (successful)
Written files
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\tusi01T.txt (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\mscodecs.exe (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
C:\WINDOWS\aLOMWkSaHqsrLGD.exe (successful)
Deleted files
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (failed)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe:Zone.Identifier (failed)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
Created processes
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\mscodecs.exe (successful)
C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
C:\WINDOWS\aLOMWkSaHqsrLGD.exe C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\hyOpp23.exe (successful)
Created mutexes
RasPbFile (failed)
Opened mutexes
RasPbFile (successful)
ShimCacheMutex (successful)
Global\zx5fwtw4ep (failed)
Global\zx5fwtw4ep (successful)
Opened service managers
MACHINE: localhost
DATABASE: SERVICES_ACTIVE_DATABASE (successful)
Opened services
RASMAN (successful)
Runtime DLLs
advapi32.dll (successful)
wsock32 (successful)
ws2_32 (successful)
rasapi32.dll (successful)
rtutils.dll (successful)
rpcrt4.dll (successful)
sensapi.dll (successful)
ntdll.dll (successful)
shell32.dll (successful)
userenv.dll (successful)
Additional details
The file sends control codes directly to certain device drivers making use of the DeviceIoControl (http://msdn.microsoft.com/enus/
library/windows/desktop/aa363216%28v=vs.85%29.aspx) Windows API function.
HTTP requests
URL: http://202.153.35.133:50320/2201us21/<MACHINE_NAME>/0/51SP3/
0/
TYPE: GET
USER AGENT: Mazilla/4.0
URL: http://202.153.35.133:50320/2201us21/<MACHINE_NAME>/1/0/0/
TYPE: GET
USER AGENT: Mazilla/4.0
URL: http://WHOLESALESYNTHETICMOTOROIL.COM/mandoc/story_su21.pdf
TYPE: GET
USER AGENT: Mazilla/4.0
URL: http://www.wholesalesyntheticmotoroil.com/mandoc/story_su21.pdf
TYPE: GET
USER AGENT: Mazilla/4.0
URL: http://202.153.35.133:50320/2201us21/<MACHINE_NAME>/41/7/4/
TYPE: GET
USER AGENT: Mazilla/4.0
DNS requests
wholesalesyntheticmotoroil.com (192.163.217.66)
www.wholesalesyntheticmotoroil.com (192.163.217.66)
google.com (216.58.211.110)
stun.voiparound.com (77.72.169.166)
TCP connections
202.153.35.133:50320
192.163.217.66:80
UDP communications
77.72.169.156:3478
77.72.169.157:3479
Dan

Similar Messages

  • Automatic creation of remittance advice for employee expense reimbursements

    Hello experts
    Is there a way to have remittance advices for employee expense reimbursements created automatically at the time of payment media run? In case of suppliers, in the supplier base you can heck "Advice Required" and then at the time of media run the remittance advice can be generated alongwith the payment. Is there a similar setting that can be done for employees?
    Thanks
    Gopal

    Hi
    Just to follow on from Ravi's reply:  most sites that I work at have the report RPRAPA00 scheduled to run on a periodic basis (define the job via transaction code SM36) to automatically create employee's vendor accounts.   A screen variant is usually saved for the program, and then the batch session is monitored on a regular basis to ensure that it has run successfully.
    Cheers
    Kylie

  • Unable to print remittance advice for certain quick payments

    Hi,
    This is regarding issue " Unable to print remittance advice for certain quick payments."
    Product version:11.5.10.2
    Description:
    -Customer has paid through the payment batch.But the payment batch data is not available in ap_inv_selection_criteria_all.
    -The status of the check is 'RECONCILLED'.
    -The payments have already been submitted to the bank and reconciled to bank statement lines.
    -While running "Send Separate Remittance Advices" concurrent program, some payments generated from Quick Payment are not available for selection for generation of remittance advice.
    Research:
    Search in the metalink but could not find any related issue.
    Could you please adivce me how to proceed on this issue.
    Thanks
    Subhalaxmi
    Edited by: user13536207 on Feb 13, 2012 12:43 AM
    Edited by: user13536207 on Feb 13, 2012 12:46 AM

    Found the problem.
    Paper size for those documents are actually A5 size.
    Solve it by adjusting the Scale to paper size in the printing option to the size that our printer is set to printout 
    which in my case is 'Letter'
    Hope this helps anyone who is encountering the same problem.

  • Cancel insp.lot for batch material with serial number?

    We have a problem with an inspection lot....
    A few months ago we made a goods receipt for batch material... it ended up in Q- stock.
    The weeks went by and the material was changed ito a serial number material... that process works fine...
    But now we want to scrap the material that is batch-handeled ... the inspection dont want to let go.. it want serial numbers... even if I create serial numbers for this the inspection lot
    dont let me register any numbers.. So I cant cancel/delete it... And after all I just want to scrap the batch...
    Can someone help me?
    // Andreas

    if stock of that material with serial numbers exist, then scrap that stock and disable the serial number for the material by deleting the serial number profile in the work scheduling view of the material master.
    then try cancelling the inspection lot. After cancelling the inspection lot, activate the serial number for that material again and bring back the scrapped stock into the unrestricted use.
    Note: please advice the users not to post any stock for that material till you complete this or else block the posting t.code for all the users.

  • Recreate remittance advices for all payment runs of the day at once a day.

    Hello Sap Gurus,
    Here we have requirment for remittacne advices , so please find below quey.
    1.      Run once a day and recreate all the remittance advices for all the payment runs of the day.
    2.       Convert this into PDF format and download to the LAN structure automatically.
    3.       This program should be scheduled in batch and have proper error handling to alert a user via email should there be a error in the download as we need to understand immediately if we donu2019t have all the remittance advices on the LAN.
    Please provide valuable inputs for the customised program? and is this possible with customised program? or any standard SAP avialable for ths requirement.
    Regards,
    Raj

    HI,
    You can create the same via a custom program with below steps:-
    (1) Fetch all the payment run IDs from table REGUV for a particular run date.
    (2) Then for each run date and run identification combination, call in loop Remittance Advice Printing Program (RFFOAVIS or RFFOAVIS_FPAYM) and it will generate the spool.
    (3) Then call the program RSTXPDFT4 to convert the spool into a PDF file and store on SAP aplication server.
    Then you can have a interface from SAP Application server to your LAN to have the file transferred.
    Regards,
    Gaurav

  • Question of uploading files for batch

    I want to upload a batch of files to CMSDK for a certain contenttype,for example, many MP3 files to "MUSIC" contenttype. I want to write a program to allow users to use to upload these MP3s, i hope it is easy to use just like use ftp client.and i need have chance to fill the attributes for the MP3s through some method. Could any one give me any advice for the designing? thanks a lot.

    CM SDK supports two different techniques for supporting custom metadata that describes an item. For example, with an mp3 file, you may want to track the artist, album etc.
    The first technique is to subclass our out of the box document class and introduce additional custom attributes that you want to track such as artist. Then, when you upload a document programatically, you specify that this is a custom document of type mp3document and explicitly specify the various custom metadata information.
    The second and preferred technique is to NOT subclass, but rather make use of custom category objects. Category objects are simply objects that can be applied to any publicobject (document, folder etc) to associate custom metadata. You could create a category object of type mp3, which allows artist, album etc to be captured. When uploading a document programatically, you create a standard document, but then execute a call to add an instance of the specified category to the document. (PublicObject addCategory method!). This is the preferred approach. In fact, CM SDK ships with an out of the box background agent (InterMedia annotator agent) that automatically detects certain content types such as mp3 files when they get uploaded, and automatically in turns extracts the metadata out of these content types, and applies to the documents using category items, so that the files can easily be searched!

  • Report for Batch and classification

    Dear Experts,
    Is there any way for getting the report for Batch, Classification etc. In standard SAP.
    Regards,
    Rohit.

    Dear Sir,
    It is giving the batch wise details.
    Is there any method to get a complete report containing batches, classification, material and other details.
    Regards,
    Rohit.

  • Specific Identification Cost for batch managed items (Follow-Up from P2P)

    Specific Identification Cost method is used for serial and batch managed item. Using this method, the outbound cost of such items would be the original cost of specific goods, which can be determined according to the serial or batch number of that item.
    Business One allows the user to receive batch managed items with a batch number that already exists in the DB. It’s possible that the received quantity is added to on-hand quantity in the warehouse. In such case, the quantity on-hand of that batch and the received quantity may have different costs.
    What should be the system behavior in such case:
    1. Block receipts to the same batch with different costs.
    2. Write the difference to a price difference account, as done in Standard Cost method.
    3. Manage the batch cost with Moving Average method.
    This thread is continuation from 'Specific Identification Cost for batch managed Items' <a href="http://p2p.sap.com/businessoneforum?type=join&login=1&uid=41FB661A76CED536C825C4E2B6FF4397&cid=91&go=z37225">discussion</a> in P2P SAP Business One Forum (Product Development Collaboration).
    Previous discussion on P2P is summarized in the attached file.

    Hi Peter,
    This is a very important functionality that you are describing here. For example, in the Steel industry, it could be extremely useful to cost by batch or serial number.
    If you receive a batch that already exists in the system and if the costing method for the product is moving average, then teh cost of the batch should be calculated based on the moving average as well.
    If the costing method is standard, then the cost should go in a variance account.
    If the costing method is FIFO, then it is a getting trickier...
    Regards,
    Vincent

  • Inventory ageing report for batches

    Hi Experts,
    I am looking for a ageing report for batches. MC46 and MC50 is not displaying the batches which is my main requirement. I learnt that its not available in standard SAP. I am planning to develop a Zreport which is a copy/reference of MC46 and MC50.
    If you ever come across this situation before, which approach you followed? I appreciate if you throw some thoughts on builiding a query or Zreport or any logics.
    Regards,
    R.S

    Hi Shiva,
    Thanks for the information. We are not using SLED for the batches and BMBC is just a **** pit where you can use it as work list when you try to change mass batches. I dont know how BMBC helps in fetching a report for ageing.
    Regards,
    R.S

  • What is the field and Table for "Batch Class" and "Class Type" in QM.

    Hi All,
    What is the field and Table for "Batch Class" and "Class Type" in QM.
    Thanks,

    Hi,
      For batch class the class type value is '023' . This you can find from KLAH table and the fileld for class type is KLART..
    And also all the data related to batch class are found in tables INOB, KLAH,KKSK and for the characeteristics of batch materials you can refer AUSP table.
    In INOB table, for batch class, you need to give 023 in KLART field and  value MCH1 in OBTAB filed.
    Please check this and let me know if this you need any more details?

  • Table for batch determination date

    hi,
    im printing the Dispensing slip...they want the output based on the batch determination date..
    can any one tel me in which table i willl get batch determination date?
    Regards
    Smitha

    Are you using a separate batch selection class versus the batch class?
    There are characteristics that must be in the selection class, but cannot be in the batch class.
    See OSS note 33396.
    1.  If you want to search for batches on the basis of a remaining shelf
             life in batch determination, the system has to calculate a requested
             shelf life expiration date dynamically from the information you
             give.
         2.  Add characteristic LOBM_VFDAT to the batch classes.
             For the revaluation of reference characteristics, refer to Note
             78235.
             Characteristics LOBM_RLZ and LOBM_LFDAT must not be included in the
             batch classes!
         3.  Add characteristics LOBM_VFDAT, LOBM_LFDAT, and LOBM_RLZ to the
             selection classes.
             Maintain a remaining shelf life in the strategy records for batch
             determination. Relational operators (> , < , <= , >=) are considered
             in the dynamic calculation of the shelf life expiration date in
             batch determination.
    From your note you have placed LOBM_RLZ  and LOBM_LFDAT in your batch class.  You cannot do that.
    FF

  • HT204053 Is it possible to have two (or more) different icloud mail accounts (not alias) under the same apple id? If not what is you best advice for all family members to have their own e-mail and still share the purchases under the same apple id. Thanks

    Is it possible to have two (or more) different icloud mail accounts (not alias) under the same apple id? If not what is you best advice for all family members to have their own e-mail and still share the purchases under the same apple id. Thanks

    mannyace wrote:
    Thanks for the response.
    So I basically won't run into any trouble? I
    There should be no issues. Its designed to work like that.  You don't change Apple IDs just because you get a new device.
    mannyace wrote:
    Thanks for the response.
    Is there any chance that the phones can fall out of sync?
    Unlikely. But nothing is impossible.   Though I don;t see how that would happen. As long as both are signed into the Same Apple ID / iCloud Account they will be N'Sync. (Bad Joke)
    mannyace wrote:
    Thanks for the response.
    If I get a message or buy an app or take a photo on the iPhone 5, how do I get those things onto the iPhone 6?
    If you buy an App, you have 2 ways to get it to the iPhone6: If Automatic Downloads is enabled in Settings->iTunes & App Store, it will automatically download to the iPhone 6 when you buy it on the 5 and vice versa if you buy it on the 6, it will download to the 5.
    Alternatively, you can simply go to the App Store App->Updates->Purchased and look for the App there and download it. Purchased Apps will not require payment again. i.e They'll be free to download to the iPhone 6 once purchased.
    SMS Messages will sync over using Continuity as long as they are on the same Wifi network. Otherwise, restoring the iPhone 5 backup to the iPhone 6 will transfer all messages received up until the backup was made onto the iPhone 6.
    Images, can be transferred either through Photo Stream
    My Photo Stream FAQ - Apple Support
    Or any Cloud service you want such as Dropbox, or One Drive.
    mannyace wrote:
    Also, something i forgot to ask initially: Should I update the iPhone 5 to iOS 8 first or does that not matter?
    If you want the Continuity features as explained above you need to update the iPhone 5 to iOS 8. Otherwise its not all that important.

  • Multiple libraries, Pbook/Pmac, advice for management & updating please.

    Hi Everyone,
    I travel frequently, and am looking for suggestions to keep all my iPhoto libraries up to date. I currently have a g5, Powerbook, and Mini.
    I just upgraded to iPhoto 6 and I have several thousand photos on my Dual g5. I just came back with 1000 more from my diving trip. The problem is, they are on my Powerbook, and taking up alot of space on the relatively small hard drive. I managed to work through the rough upgrade from 5 to 6, and now I need some more help...
    1) What is your advice for managing multiple libraries of photos.
    2) What is the best way to transfer the iphoto pics (and movies) to my desktop, which of course has the larger storage capacity, after travelling...
    Thanks,

    Jason:
    There are several different approaches to what you want to do. Let me just throw out a couple that I'm familiar with.
    To get the new photos from your PB to your G5 and maintain any keywords, and other organization effort you put into them, you'll need the paid version of iPhoto Library Manager. It will allow you to merge libraries or copy between libraries and maintain the metadata, etc. That's the only way currently available to move photos from one library to another and keep the roll, keywords, comments, etc. with those photos. You can connect the two Macs with one in the Target Mode, probably your PB, and then run iPLM to move the photos to the G5 library.
    Now there is a way to have a library on your PB that reflects the one on your G5 but is only a fraction of the size. That's to have an alias based library on your PB that uses the Originals folder as its source of source files. (My 25,600 files, 27G, are represented by an iPhoto Library folder of only 1.75G). When the PB is not connected with the G5, say with a LAN, it will have limited capabilities which are in part: you'll only be able to view the thumbnail files, be able to add comments, create, delete or move albums around, add keywords (but with some hassle-but it can be done). You can't do anything that requires moving thumbnails around, work with books, slideshows or calendars. Once the two computers are networked together again the library will act as normal.
    Now while on the road you can have a "normal" library to import new full sized files, keyword them, add comments, etc. and then transfer to the G5 library. Once in the G5 library they will be represented in a roll(s) and corresponding folder in the Originals folder. You then fire up the "alias" library, and import those new folders in the G5 Originals folder.
    It may be a lot of work but it may be one way of doing it.
    I've not done any of the "sharing" with iPhoto so don't know if that's another possible candidate for transferring.
    P.S. FWIW I've created this workflow for converting from a conventional library to an alias based one.

  • Advice for real performanc​e of LV8.5 operate in the XP and Vista

    Hi all
    My company had purchased new computers for LabVIEW programming purpose.
    We may install the LV8.5 in these computers but OS are not decided yet. Also, we have the current PC is only XP licensed
    Therefore, can anyone give the advice for the real performance advantage of using :
    LV8.5 with Vista over LV8.5 with XP
    LV8.5 with Vista over LV7.1 with XP
    LV7.1 with Vista over LV7.1 with XP
    New computers detail:
    Intel(R) Pentium(R)Dual-Core processor E2160
    BCH-P111 -1.80GHz, 1MB L2 cache, 800MHz FSB
    2GB RAM
    Thanks
    Best Regards
    Steve So

    The biggest issue I have seen with 8.5 Vista vs. XP is that if you leave Vista in the standard theme, the fonts have changed.  I designed several front panels to have them be out of whack with XP.  So if you are going to be using code across platforms, you need to keep in mind they will look different unless you use the XP theme in Vista, or customize your fonts to make sure they remain the same between the systems.  The dialog font is a different size (13 on Vista vs. 11 on XP), and a different font (can't remember the difference).  That was the big one I noticed.
    8.5 over 7.1 is mostly going to be the learning curve to learn the new features.  Overall, I have appreciated the changes, but there are some things (mostly development related) that I have seen run a little slower in 8.5 than in 7.1, but have not noticed any runtime issues as of yet.  One big change between the versions is application building, which is more complex in 8+.  I do appreciate the new features, though, but NIs project still hasn't rubbed me the right way yet.
    NI doesn't support LV 7.1 with Vista.  I have used it and haven't seen any problems, but that doesn't mean one won't pop up.  If you're going to stay with 7.1, you better stay with XP.  8.5 is the first version NIs supports as Vista compatible.  You will also have to use a relatively new set of device drivers, so if you have old hardware you are trying to use in your new system, make sure it is cimpatible with the latest drivers.
    I have actually had more issues with other hardware drivers and software packages than I have with LabVIEW.  TestStand is not yet supported in Vista, and i found out the hard way, one of the ways it is incompatible and had to move back to XP for devlopment.

  • Error while executing the transaction QC22 (Quality Certificate for Batch)

    Hello Friends,
    While executing the transaction QC22(Quality Certificate for Batch), after giving the Batch Number and Customer Number, when i am executing it , system is throwing the error message as "Not all data was found for characteristic 90139982 in profile D80D8".
    Message no. ZQ010
    Diagnosis
    Not all data was found for characteristic 90139982, referenced as number 0030 in certificate profile D80D8. The missing data could be the short text, specifications, or results.
    System Response
    The missing charactertistic will not be printed on the certificate,
    Procedure
    Review the settings for data orgin of the short text, specifications, and results, and adjust accordingly.
    One more thing i would like to add here as against the same batch in april we had taken the print of COA (Quality Certificate) through the transaction QC22. But now we are trying to do that than system is thrown above mentioned error.
    As i am new in QM, kindly explain we were to maintain the certificate profile.
    Waiting for the experts inputs.
    Thanks and Regards,
    Jitendra Chauhan

    Hi
    Try with QA33 you may have display authorization,  or check in MB51 on the base of material and batch you can find the lot number generated, then go to QA03 and check the result, if you want to validate the characters check with the inspection plan, the characters entered in the inspection plan and the characters in the concerned certificate profile.
    Regards
    Naveen.
    Edited by: vaddapalli naveen on Jul 1, 2010 1:57 PM

Maybe you are looking for

  • How to get the dID of any Content from SS_DATAFILE in Site Studio 10gR4?

    Hi, I am trying to get the dID of a Contributor Data File from its dDocName (SS_DATAFILE). I can do a search based on this Content ID but if I am able to get the dID using one of the Site Studio variables, it will be great. Thanks, Justin

  • How to get the index of Mult column list box

    Hello all, I need small help. Please help me. Is there is any property to change the "Multi column list box" row index position dynamically? I want to change the index position at runtime like below. Munna Solved! Go to Solution.

  • BPEL with Reliable Processing

    Hi, I read and work on the "BPEL with Reliable Processing" cookbook. http://www.oracle.com/technology/pub/articles/bpel_cookbook/qualcomm-bpel.html It's great! I try to enhance the process by adding notion of priority between different records. A pri

  • PO output medium XML in Vendor data missing

    When we try to create a BP as vendor, we dont see XML as the output in Send Medium in the Co. code tab. Is there anything to be configured so that XML shows up as the output medium ? We only see Fax, Mail, Print. -Bakulesh

  • Functionality of the function module - FAGL_GET_OPEN_ITEMS_GL

    Hi, I would like to know regarding the working of the module FAGL_GET_OPEN_ITEMS_GL, and details about the parameters to be passed to the function module and the returned values. thanks.