Re: NetDevil - ADVAPI

From: bclay (bclay_at_discussions.microsoft.com)
Date: 01/22/05


Date: Fri, 21 Jan 2005 16:59:04 -0800


"Ian Kenefick" wrote:

> On Fri, 21 Jan 2005 15:53:03 -0800, "bclay"
> <bclay@discussions.microsoft.com> wrote:
>
> >Every reference with a Google search for ADVAPI came up with the Netdevil
> >virus. A subsequent Technet search found one hit - apparently ADVAPI is a
> >Kerberos component in AD.
> >
> >The massive logon attempts, still disconcerting.
>
> The massive login attempts are explained by the fact that netdevil is
> a RAT - Remote Access Trojan. Can you capture a sample and send for
> analysis to your AV vendor? If you can, do this! - and for an instant
> analysis send it to scan[at]virustotal.com with subjectline 'SCAN'
> without the inverted commas (replace [at] with @).
>
> Post back with results!
>
> Regards,
> Ian Kenefick
> http://www.IK-CS.com
>

Questions-

1. You said RAT - is this an external trojan attempting to logon via web
services?

2. Capture a sample - do you mean a capture of the public traffic to this
server during logon attempts?

thx-
 



Relevant Pages

  • Re: logon errors (every minute)
    ... This may be the NetDevil virus. ... It uses "Advapi" which can be used to impersonnate a user that has logged onto a machine. ... MVP Windows Server - Networking ... There are no services or programs that logon with this user account... ...
    (microsoft.public.windows.server.general)
  • authentication issues
    ... Windows XP), I have both 'Basic authentication' and 'Integrated Windows ... If I try to capture the userid by using ... the Challenge/Response logon box does not show up. ... Capture the userid after the user enters his userid in the appeared logon ...
    (microsoft.public.inetserver.iis.security)
  • Re: screen capture
    ... > Hello Robert, ... > You can capture this image if you start a remote desktop session. ... > should see the logon box there. ...
    (microsoft.public.win2000.security)
  • Re: Authentication/logon
    ... repeated calls for logon as we move from site to site within the site ... Is there a way to ensure that Windows will capture the ... capture it at the first SharePoint logon? ... Kerberos is enabled on the domain level and not per client. ...
    (microsoft.public.sharepoint.portalserver)
  • Capture logon info
    ... controller that will capture the following from each end station during ... logon and write the output to a text file: ...
    (microsoft.public.scripting.vbscript)