New worm eating my network up

I dont know if this is the right forum for this problem but I hope someone here can help. I have a new virus/worm spreading across my network. It will first ping random addresses in any known subnets and then try to attack port tcp 1433, tcp 2967, tcp 139. I have been sniffing one of the infected machines for the weekend so I have lots of data to look at but no one on the net seems to have a solution yet.
Thanks for your help

possible botnet infection. The solution is very much dependent on your environment. If it were my network, I would shutdown outbound desktop Internet connectivity until it was resolved. At the very least, analyze the infected host(s) and block connections to suspect external hosts(look for IRC/HTTP especially). make sure all your MS SQL, Symantec, and Microsoft machines are patched. find all the infected hosts and re-image with the now fully-patched image;-)
see this link:
http://lists.sans.org/pipermail/unisog/2007-February/027085.html

Similar Messages

  • I hooked up new iMac to wireless network and now iPad and iPhone do not work using wireless.  I am using a Netgear N300 router.  Also my Netgear ethernet/homeplug for wireless TV internet no longer works.  Any ideas?

    I hooked up new iMac to wireless network and now iPad and iPhone do not work using wireless. They did before hooking up the iMac. I am using a Netgear N300 router.  Also my Netgear ethernet/homeplug for wireless TV internet no longer works.  Any ideas?  I have tried unplugging, restarting, and resetting.  No luck!  Thanks!

    You should probalby contact Netgear

  • Info about a new worm (Mytob.GV)

    Hello forum users
    I have found a very interesting article about a new worm that can be very dangerous for your system. The Spanish anti-virus software provider Panda software warns of a new variant of the Mytob Wurms. More data about this worm you can find on
    http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=79530 .
    Bye

    Hello Joao
    Thanks for this info.
    Bye

  • I set up a new user on my network today and am now in a location without access to that network. I just set her up as a user on her macbook but I can't log in with her credentials. Is that because I am not on the network and it is the initial setup?

    I set up a new user on my network today and am now in a location without access to that network. I just set her up as a user on her macbook but I can't log in with her credentials. Is that because I am not on the network and it is the initial setup?

    You need to set the option to create a mobile account using the Directory Utility app. 

  • Adding new switch in my network including Cisco Prime Infrastructure

    hi all,
    if I connect new switch to my network, can I let Cisco PI to apply a specific template of configuration to this switch automatically?
    how can I do that ?
    thanks in advance

    Hi,
    i followed these steps :
    SWITCH SIDE
    - configured Prime Infrastructure as snmp-server host;
    - enabled snmp-traps for linkup and linkdown events globally;
    - disabled snmp-traps for linkup and linkdown on non relevant interfaces using the no snmp trap link-status command
    PRIME INFRASTRUCTURE SIDE
    - under "Deploy/Monitor Deployment" i deployed template "Interface Health"  for all the interested switches
    -  under "Administration/System Settings/Mail Server Configuration" configured my internal SMTP server to make Prime Infrastructure able to send e-mails
    - under "Operate/Alarms & Events" click on "Email Notifications" , then on "Switches and Hubs"
       - check the "critical" box ,  insert the destination e-mail address into the "To" field then click "Save"
     -  check the "switches and Hubs" box and then click Save
    As i know is possible to avoid to configure every single not-interesting port on the switches with "no snmp trap link-status" command (it's a bit annoying when you have tens of switches), using Port Grouping configuration on PI but i tried it without success.
    Hope this helps.
    Best Regards,

  • New worm, called OSX.Inqtana.A

    Sorry, I'm not sure if I'm posting in the right place.
    I'm not finding any info on Apple site about this
    new worm, called OSX.Inqtana.
    That I just saw on yahoo.
    It mainly effects bluetooth macs, and my G5 is that.
    Any word I what I can do to shore-up my iMac?
    Thanks All!
    Stu

    Here's a little.
    http://www.macworld.com/news/2006/02/17/inqtana/index.php

  • Can a new macbook pro be networked with  2003 microsoft outlook

    Can a new macbook pro be networked with 2003 microsoft outlook

    Shootist007 wrote:
    Noble Seven wrote:
    If the Macbook comes with Lion on it, you cannot downgrade to Snow Leopard.
    Then what is this?
    MBP Model 8.2 i7 2.2 SMC version 1.69f3.
    Really I don't lie and I am getting tired of people calling me a lier.
    Thanks.
    I'm reluctant to wade into this but I noticed that if Mactracker is to be believed, the Early and Late MacBook Pro have the same Model Identifier, which would suggest that the SL installer for the Early MBP might see the Late MBP, which came with Lion, as close enough for government work. While the SL installer wouldn't necessarily be 100% suitable for the Lion Machine and probably wouldn't allow installing over the existing Lion partition, I can imagine it working on a clean partition or external USB or Firewire drive. A 10.6.8 combo updater could then configure the SL installation for the MBP it's actually on.

  • Causing some network problem after connecting the new ASA to my network

    Hi everyone,
    Hope you can help on this issue.... It is strange to me...but may not be to you
    Currently, I have a subnet connects to my primary network. All the internet travel thru a router there in turn thru a pair of ASA failover firewall (ie Subet -> router -> Subnet ASA -> Pirmary network ASA -> Primary network router -> Internet).
    Now we try to setup a internet pipe so the subnet can go to internet by its own. So...for security purpose, we put another new ASA in between.the subnet and the new internet. This will be the first, and the old path to Interent would be the back up route.
    NOW
    I have not even make any route cahgnes on the router yet. What I did was to connect the new ASA to the subnet. Again, I do not change any routes, or any gateway settings on all the computers yet in the subnet!! I just connect the asa. That is it...please remember this.
    However, problem happens. I have a application server in the same subnet.... that keeps kick out users. I also have continuous ping to it... I saw that the server has requesdted time out...it did not come back up until about 10 to 20 seconds later. The server, in fact, is a cluster server. Although I can ping the physical server, I cannot ping the virutal server.
    In order to fix the problem, I really need to unplug the new ASA from the network, and reload the cluster server. Then it starts to work.
    ANother symptom is that...people complaint the log on is obviously slower than usual.
    May I ask why the new ASA will cuase this trouble?? Again, no routes on the router have been change. And all PCs in the subnet are still using old gateway, and did not nkow about the new ASA.
    Any ideas would be great!! Very strange to me. Thank you very much for your help.
    Riderfaiz

    First guest would be proxy ARP.
    Proxy ARP is enabled by default on the ASA. The new ASA might be proxy ARPing for whatever reason.
    OR the new ASA might have been configured with an ip address that belongs to another device by mistake.

  • HT4623 I have an iphone 5. My number has not transferred over to the new phone although my network provider sais that it has. The network provider sais I must setup phone with itunes. How do i do this?

    I have an iphone 5. My number has not transferred over to the new phone although my network provider sais that it has. The network provider sais I must setup phone with itunes. How do i do this?

    If you can access anything on the phone, then try a reset. Hold the sleep/wake and home buttons together until you see the Apple logo and then release. If this doesn't help, then go to Settings, General, Reset, Erase all content and settings, and this will bring you back to the activation screen.

  • I have Office for Mac 2011 on my Mac desktop.  Is there a way to transfer it to my new MBA via my network?

    I have Office for Mac 2011 on my Mac desktop.  Is there a way to transfer it to my new MBA via my network?  If not is there any way to load Office into my MBA short of buying an external DVD player?

    I recently purchased a MacBook Air and set up the machine using Setup Assistant cloning it from my iMac via wifi. Whilst it took a very long time, eventually it worked.
    The set up option included all programmes. When I opened up MS Word on the Air, I was asked to enter my original product key. Once I had done this all other MS Office programmes worked fine.
    I believe the license allows you to install and run on a desktop and a laptop but not be using them at the same time.
    Hope this helps

  • New MBP and existing network

    Hello All,
    I've just migrated from a G4 PB 1.5 to a new MBP and, while I can log into the existing WiFi, I can't see any of the other nodes on the network. I have my wife's MP Black and a Mini acting as a HTPC/Server. I just migrated through using the assistant and didn't change any of the settings yet.
    The Mini is sitting headless downstairs so I used to log in remotely using Chicken of the Sea VNC. Now it no longer is visible, nor do the computers show up via network.
    It's been a while since I set this network up and I know that 10.4.8 has altered some of the security. What do I need to tweak??
    Cheers,
    JC

    A router separates two LAN networks and creates two broadcast domains. The standard Microsoft workgroup browsing will only list what is inside your LAN and never something outside or across a router.
    If you want to access what is on the other side you must manually enter the share with its IP address. If the computer you want to access has IP address 192.168.100.12 then you enter \\192.168.100.10\share.
    But as you want to be able to share freely inside your LAN anyway, I would suggest you set up the WRT as wireless simple access point. That way, you only have a single LAN and a single broadcast domain and thus you can find all other computers if you check for other workgroup computers. Instructions how to set it up as access point are here.

  • Help with new Airport Extreme (and network name) not recognizing Time Capsule and other Airports in the home

    I had a Time Capsule running in an AV Cabinet and it made too much noise as it backed up and ruined soft/quiet music passages (and created far too much warmth as well).  So, I visited the local Apple store and the guy I met worked through a few solutions with me.  I decided on an Airport Extreme for the audio cabinet, and would move the Time Capsule to another room where it would not create noise interference.
    So, I have the Airport up and running perfectly well.  I changed my wireless network name and password.
    I cannot get the Airport Express and Time Capsule to show up on my network.  They both just blink that brown/orange color on the front.  When I go to the Airport Utility, it does not pick up the Time Capsule or Airport Express.  I have tried unplugging and plugging back in and scanning for devices, but dont know what else to do.  Are they still looking for my old network?  Is there a way to reset them??
    Thanks for any help.

    I've tried the option key on both--the AEBS offers 14 options, including Automatic, while the TC offers 8 options, and no Automatic. The AEBS lists (among others) 802.11 a/n-b/g compatible, 802.11 a-b/g compatible, or 802.11 n (5 GHz)-b/g compatible. The TC offers 802.11.n (b/g compatible), 802.11n only (2.4 GHz), and 802.11n only (5 GHz), among others...
    I had already followed the instructions in the link you supplied, except that the wireless options don't quite match...
    I am currently trying 802.11n (5GHz)-b/g compatible on the AEBS and 802.11 (5GHz) on the TC, which gives me a rate of 270 on my n devices and 54 on my g devices, according to the Airport Utility.
    This might be the best I can do, without buying a new TC. Thanks for any advice you can give...
    C.

  • How can I reconfigure an Airport Timecapsule and Airport Extreme Base Station to extend a new Time Capsule 3TB network.

    Previously they were configured to be part of a network attached to a cable modem.  Now I have a DSL modem.  I can get the 3TB Time Capsule tower to be recognized by my AirPort Utility but cannot get the older 2TB Time Capsule and Extreme Base Station to be recognised as wifi extensions of the 3TB Wi-Fi Base Station.     This latter base station is set up in Bridge mode and the wifi is switched off on the DSL Modem.     I am trying to recreate a home network (I have created a newly named one) and use the Apple products as the wifi routers, leaving the fibre optic-supplied DSL modem to interface with the internet.
    I would have thought that I should set-up the 3TB Time Capsule Base Station in DHCP network mode, but trying to do so gives me error messages and renders the network inoperative.   Does anyone have any suggestions as to how to get the AirPort utility to recognise the two other devices (Base Stations) as extensions of the main one?    I have tried with RJ45 cabel connections to no avail.

    First, it would be wise to update your computer to OS X Mavericks. It's just a free update, but it really helps your computer.
    Once you've done that, on to the fix.
    In Airport Utility, select the old router and click "edit". Click the Wireless tab. Select Off. Click Update, and wait. During the update, you should use your phone to read this, as you may have no wireless for a time.
    Once the update is done, click the new Time Capsule and click "edit". Select the wireless tab, and change the Network Mode to "Create a Wireless Network". Choose your name, security and password. Click Update. Once the new Time Capsule is plugged in and wired, you should be able to connect to your network from your laptop.
    Back on the old Time Capsule, go to the Wireless Tab and select, "Extend a Wireless Network". Select your network, and click update.
    On the Airport Extreme, do the same as the old Time Capsule.
    You should be done! Now, you can move your old Time Capsule somewhere else as use it as an extention of your network. And the same with the Airport Extreme. Enjoy your 5TB of network storage!

  • How can I add a new WLC on my network

    Hi there,
    I have a WLC4404(v4.0.219.0) and several APs on my network.
    Those APs are belonged to a couple of vlans.
    I planed to add a new WLC4404(v5.0.148.0) on same network with a old one.
    I configured the new WLC4404 as a primary controller of the APs and the old on as a secondary.
    I noticed some APs could be registered only on same vlan with the managemnet interface of the WLC.
    How can I register the APs on different VLANs with Mgmt. of the WLC?
    Let me know if you have a any idea.
    Thanks
    Jongkwan Lee

    Well since the ap's only know of the existing WLC, the only way they will join, is if you remove the existing wlc and let the ap's find the new wlc. When you configure the mobility group, that info is pushed to the ap, so that it knows of the new wlc. This way you can set the primary ap to the new one and the second wlc to the existing wlc.... make sure ap fallback is enabled so that the ap will try to join the new wlc. If you still have issues, I would console into the ap and capture the log when you faile the existing wlc.

  • Brand new iMac kills home network

    I have a home wi-fi network with a BT Voyager 2100 router and several PCs and laptops. All works fine. So today - I power up my brand new iMac and the home network stops. IE and Firefox on the PCs give "unable to find xxxx" error messages. I have tried the iMac with both wireless and ethernet connections to my router - same result. Safari on the iMac simply does nothing, blank screen. To get my internet back I have to power off the iMac and then re-start the router several times. Eventually all is well again. How do I get my iMac to work with a BT Voyager 2100 router?

    update to my post - an old iMac G4 works just fine. So I guess that basic connectivity between iMac technology and my router is OK... so why does a brand new iMac give problems ?

Maybe you are looking for

  • Problem about D-link card installation on Solaris 8 intel

    hello, I don't know how to install my ethernet card on the Solaris 8 intel. It's a D-link DFE-530TX model on PCI bus. Could you send my the methode to install it. Thank you very much.

  • External links suddenly open in a new window instead of a tab

    I am using Nightly (20.0a1) on WIndows 8, I use the program Teamspeak 3 and it used to be that whenever I clicked on a link it would just open in a new tab in the Nightly window that was open, but now it opens a completely new Nightly window. I have

  • My ipod touch is frozen and it wont turn back on . How can i turn it back on ?

    I was using my ipod touch not too long ago and when it turned off , it wouldn't come back on. Now, all I have is a black screen and its half charged. I read some reviews about the same problem and people have said to plug it in a wall charger and wai

  • Username and password in page0

    i have developed an application where in which i have to register new users with their own username and password. i want to write the code without using the default login page where in which there are stored packages and procedures, can any body just

  • Render and Replace doesn't open Soundbooth

    Mac / PP CS4 (production  premium) Hi, I have a clip in the timeline and I'm right-clicking, choosing Edit in Adobe Soundbooth > Render and Replace but nothing happens.... Soundbooth doesn't open (at all) with the clip to edit. Any suggestion appreci