The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > OS Specific Forums > Linux
Google UNIX.COM


Linux RedHat, Ubuntu, SUSE, Fedora, Debian, Mandriva, Slackware, Gentoo linux, PCLinuxOS. All Linux questions here!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
ssh script problem problem pcjandyala Shell Programming and Scripting 2 07-31-2008 12:27 PM
CIACTech05-001: Operation of the Sinit/Calypso Worm iBot Security Advisories (RSS) 0 12-24-2007 06:40 AM
CIACTech04-001: Remote Detection of the MyDoom.A Worm iBot Security Advisories (RSS) 0 12-24-2007 06:40 AM
Virus and Worm on Linux/unix System larryase UNIX for Dummies Questions & Answers 1 07-18-2006 11:27 AM
Worm Virus ana_cr32 UNIX for Dummies Questions & Answers 2 09-01-2003 08:21 PM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1  
Old 08-19-2008
Registered User
 

Join Date: Apr 2007
Posts: 12
Problem with worm ctfmon.exe

I have this worm in my network.
It works only on Windows OS. My data server is on Linux with samba server and all the time somebody is copping this worm from windows client to my data server, because the data server is mapped as a network drive.
My question is:
Is there any way to find which machine copy this virus to my server?

I changed my samba log level to 10 (which means debug level) but it doesn't help much.
I can't see the exact IP or NIC hardware address.
Thanks in advanced.
Reply With Quote
Forum Sponsor
  #2  
Old 08-19-2008
Bughunter Extraordinaire
 

Join Date: May 2005
Location: In the leftmost byte of /dev/kmem
Posts: 1,235
Ctfmon.exe is not a "worm", its a system component. 20 microseconds of googling for "ctfmon.exe" revealed the following:

Frequently asked questions about Ctfmon.exe

I hope this helps.

bakunin
Reply With Quote
  #3  
Old 08-19-2008
Registered User
 

Join Date: Apr 2007
Posts: 12
Quote:
Originally Posted by bakunin View Post
Ctfmon.exe is not a "worm", its a system component. 20 microseconds of googling for "ctfmon.exe" revealed the following:

Frequently asked questions about Ctfmon.exe

I hope this helps.

bakunin
I have read that, but this is what I'm toking about.
WORM_VB.BDN - Description and solution

I wrote a scrip to remove all written here WORM_VB.BDN - Technical details

I started it in all machines in my domain with Group Policy but there is no result for now.
10x for help but I need more.
Reply With Quote
  #4  
Old 08-19-2008
sysgate's Avatar
Unix based
 

Join Date: Nov 2006
Location: /root
Posts: 1,197
Possible solution : unmap the network drive, and check the router logs for unsuccessful TCP connections to the data server, but you gotta have network admin with you. Else, you may look recursively in the logs folder, for example : grep -ir "ctfmon.exe" /var/log/*
This will search for any lines with ctfmon.exe string in, and hopefully you will be alarmed with the IP address of the user. On the other hand, have everyone in your office to scan their PCs for viruses and eventually clean them up.
Reply With Quote
  #5  
Old 08-22-2008
Registered User
 

Join Date: Apr 2007
Posts: 12
10x everybody.
I found solution for my problem.
I made script to make smbstat > log_$i.log until I press Ctr+C.
Whem delete ctfmon.exe sombody copy it back. When I grep content of all logs, I found the problem PC.
Thank you very much again.
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 08:47 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0