Need computer help Chalk

This section is for our members to talk about things not actually about fishing or boating. However, please read the Code of Conduct before posting.
Image

Moderators: bman, Chalk, Tom Keels

User avatar
wevans
Site Sponsor
Posts: 12827
Joined: June 12th, 2002, 11:06 am
Location: Sopchoppy

Need computer help Chalk

Post by wevans »

We have only one WIN2003 server here and a hacker got into it and changed the registry setting for the Network Services :hammer: If you have a 2003 server there, could you look and see what file should be executed from the registry setting "My Computer\HKEY_LOCAL_MACHINE\System\controlset001\services\netsrv" :-D The SOB put a Trojan .exe in place of the real file :smt013
:beer: :beer:
Last edited by wevans on April 5th, 2007, 8:44 am, edited 1 time in total.
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

Google "netsrv.exe"

It is a trojan. Looks to be a little complicated to remove, but try avg antispyware trial.....I have had good luck with it.....

Beware, DO NOT go to one of the sites on google and download removers. You will get more than you bargained for!

Just read up on it...


Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
wevans
Site Sponsor
Posts: 12827
Joined: June 12th, 2002, 11:06 am
Location: Sopchoppy

Post by wevans »

Don't have the netsrv.exe trojan :thumbup: I do have a network service that don't work do to him changing the registry to run a trojan in place of the network service :smt010 I just can't find which file SHOULD be running instead of the one he put in place :smt012
PS: The server has been cleaned :thumbup: I just have to repair the damage now :beer:
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

I just checked 2 of my servers. They do not have that key in the registry at all. One is SBS 2003 and the other is 2003 R2.

So, I have no idea what file should be there. Sorry.

Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

Checked a few more and NONE of the servers have the Key "system" under ControlSet001.

All have just 4

Control
Enum
Hardware Profiles
Services

Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
wevans
Site Sponsor
Posts: 12827
Joined: June 12th, 2002, 11:06 am
Location: Sopchoppy

Post by wevans »

Ours is 2003 standard edition with Exchange 2003 installed.
These where they major files he installed "through our firewall" :hammer:
JAcheck.dll Generic BackDoor(Trojan)
psexec.exe RemAdm-PSKill(Remote Admin Tool)
csrms.exe ServU-Daemon(Trojan)
As well as some txt files that he used :smt012
I guess I'll just restore the hive "from backup" to a directory and see what it had in it before the intrusion :beer:
User avatar
Chalk
Moderator
Posts: 11996
Joined: March 9th, 2002, 8:00 pm
Location: 30° 13' N, 85° 40' W
Contact:

Post by Chalk »

Dunno....they don't let me play with the servers...I know enough to either break them or fix them :roll: :lol:

Ahhhh....hmmmmm

What does your backup say :roll:
User avatar
wevans
Site Sponsor
Posts: 12827
Joined: June 12th, 2002, 11:06 am
Location: Sopchoppy

Post by wevans »

I'm an IDIOT :hammer: I typed in system to many times :hammer: :hammer:
My Computer\HKEY_LOCAL_MACHINE\System\controlset001\services\netsrv
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

ah, now that could make a difference. Hang on, and I will look again....

Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

I think that key must been added by the trojan. The key "netsrv" is not under ControlSet001/Services on any of the 3 2003 servers I just looked at.

Try exporting the key netsrv, then delete it, and try that. You can reimport it if it does not work.

Oh, and remember you will have to reboot to check it.


Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

Chalk wrote:Dunno....they don't let me play with the servers...I know enough to either break them or fix them :roll: :lol:

Ahhhh....hmmmmm

What does your backup say :roll:

hehe, servers are fun. I love watching 25 people running around freaking out..........They look at you and say, "How can you be so calm. :roll: That is when you just keep quiet and don't tell them you already got it fixed. Just have a little fun and watch the action for another 10 minutes before putting them back online..... :o

Dubble :lol:

Oh yeah, keep a spray bottle of water handy, so you can look like you are sweating a little.....
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
User avatar
Barhopr
Site Sponsor
Posts: 3736
Joined: September 25th, 2006, 10:21 pm
Location: Bainbridge/Beacon Hill

Post by Barhopr »

Hey just call the tech guy, oh wait a minute thats you :-D
VIVA la BT

Image_______________Image
User avatar
wevans
Site Sponsor
Posts: 12827
Joined: June 12th, 2002, 11:06 am
Location: Sopchoppy

Post by wevans »

:lol: :o :smt014 :smt013 :smt010 :smt010 :smt009 :beer:
User avatar
Chalk
Moderator
Posts: 11996
Joined: March 9th, 2002, 8:00 pm
Location: 30° 13' N, 85° 40' W
Contact:

Post by Chalk »

I help manage a pretty complex system, keyword being manage :lol:

http://www.ctc.com/files/ctcVideos/DJC2_medium.wmv
User avatar
Dubble Trubble
Site Sponsor
Posts: 2348
Joined: October 30th, 2005, 8:46 pm
Location: Thomasville

Post by Dubble Trubble »

The thing that REALLY freaks me out is our defense system being run on WINDOZS......


"Ok, Mr. President, we are launching a first strike to disable their missle system....Ahhhhh....waiiiaattt just a minute...the system just locked up, but it's ok we are reboo.......BOOOMMMMMMMMMM!!!!!



Dubble :smt011


PS, The virus that locked up the system came from Russia and China... :smt009 :smt010
Last edited by Dubble Trubble on April 5th, 2007, 9:45 am, edited 2 times in total.
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
Post Reply