GOZI VIrus - Help

Status
Not open for further replies.

Eriks Abzinovs

Honorable
Aug 27, 2013
69
0
10,630
Good Morning.

I am in seek for help in urgent matter. It seems that One of the machines has been infected with GOZI virus judging by CBL report. I have run Spohos scans on all of then but it seems that with unsuccessful results.

Please help me get rid of it as it is causing me to have massive issues.



This IP is infected with, or is NATting for a machine infected with s_gozi

Note: If you wish to look up this bot name via the web, remove the "s_" before you do your search.

This was detected by observing this IP attempting to make contact to a s_gozi Command and Control server, with contents unique to s_gozi C&C command protocols.


Please help !

Much appreciated in advance.
 

Eriks Abzinovs

Honorable
Aug 27, 2013
69
0
10,630


Thanks i will try to look in to this solutions now
 

Eriks Abzinovs

Honorable
Aug 27, 2013
69
0
10,630


Hello and Apologies for late reply. I have tried the steps in the both links and it is till trying to connect to that dress. also created a script that will block all attempts to connect that address and implemented them on all machines. Still no go. Starting to wonder if it might be on router or any other device. There is no currently any additional hardware connected to machines. Also still sophos is not detecting anything.

Any other ideas ?
 
Status
Not open for further replies.