Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Malicious Attack? Could someone take a look and let me know what you think?

Reply
Thread Tools

Malicious Attack? Could someone take a look and let me know what you think?

 
 
HelenD HelenD is offline
Junior Member
Join Date: May 2007
Posts: 1
 
      05-01-2007
A few weeks ago, I found that a large number of adult material files appeared on the computer over the weekend when it was not connected to the internet and I was not using the computer. Last week, I found that a similar incident had occurred one week earlier when I did not have the computer but it was connected to the company network.

From quick analysis I found the following:

* Both events were bounded by two failed logon attempts under my user ID

* Time duration between the two failed logon attempts was two days and twenty one hours.

* Over the time period between the two failed logon attempts on each occasion, 72 event ID 636 and 72 event ID 637 occurred. Event ID 636 is : A user or group account was added to a local security group on the computer or on the domain, and Event ID 637 is: A user or group account was removed from a local security group on the computer or on the domain.

* MS Installer events occurred post the creation of the adult material files when the computer was next logged onto the network.

I am interested in knowing whether anyone thinks this is substantial evidence of a virus or malware attack or if these two events are related. It is concerning because I have had virus and malware scanners run across the computer that were available between the 30th March and 4th April and none of these returned the presence of any virus or malware – in particular Symantec Anti-Virus v9.0.0.33.8, F-Prot v6.0.6.3, Avast! Anti-Virus v4.7.942 and Ad-Aware v1.06r1. Is it possible that they could have missed something? Are you aware of any other malware / viruses that could have demonstrated this behaviour?

Please find logs and some initial analysis attached. I have separted out the two dates on the last two tabs of the attached excel spreadsheet

Any help is appreciated,

HelenD
Attached Files
File Type: zip Event Viewer.zip (25.8 KB, 0 views)
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Please could someone take a look at this website... Jerry HTML 21 05-21-2006 01:02 PM
Hijack this log could someone please take a look at this and tell me what to delete fred_7038@yahoo.com Computer Support 8 09-15-2005 05:36 AM
noob: Trying perl, and decoding MIME attachments..stuck in my code..can someone take a look? cayenne Perl Misc 3 05-26-2004 05:19 PM
Have a nice day! ...//more of your parables. Pray let us know whoyou are, let us Ravens U. Locksmith Python 1 05-26-2004 11:00 AM
winxp IE will not let you exit, and my comptuer / other folders will not let you open them. Daniel NZ Computing 2 05-11-2004 02:02 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57