Need computer help Chalk
Moderators: bman, Tom Keels, Chalk
Need computer help Chalk
We have only one WIN2003 server here and a hacker got into it and changed the registry setting for the Network Services
If you have a 2003 server there, could you look and see what file should be executed from the registry setting "My Computer\HKEY_LOCAL_MACHINE\System\controlset001\services\netsrv"
The SOB put a Trojan .exe in place of the real file

Last edited by wevans on April 5th, 2007, 8:44 am, edited 1 time in total.
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
Google "netsrv.exe"
It is a trojan. Looks to be a little complicated to remove, but try avg antispyware trial.....I have had good luck with it.....
Beware, DO NOT go to one of the sites on google and download removers. You will get more than you bargained for!
Just read up on it...
Dubble
It is a trojan. Looks to be a little complicated to remove, but try avg antispyware trial.....I have had good luck with it.....
Beware, DO NOT go to one of the sites on google and download removers. You will get more than you bargained for!
Just read up on it...
Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
Don't have the netsrv.exe trojan
I do have a network service that don't work do to him changing the registry to run a trojan in place of the network service
I just can't find which file SHOULD be running instead of the one he put in place
PS: The server has been cleaned
I just have to repair the damage now 
PS: The server has been cleaned
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
Ours is 2003 standard edition with Exchange 2003 installed.
These where they major files he installed "through our firewall"
JAcheck.dll Generic BackDoor(Trojan)
psexec.exe RemAdm-PSKill(Remote Admin Tool)
csrms.exe ServU-Daemon(Trojan)
As well as some txt files that he used
I guess I'll just restore the hive "from backup" to a directory and see what it had in it before the intrusion
These where they major files he installed "through our firewall"
JAcheck.dll Generic BackDoor(Trojan)
psexec.exe RemAdm-PSKill(Remote Admin Tool)
csrms.exe ServU-Daemon(Trojan)
As well as some txt files that he used
I guess I'll just restore the hive "from backup" to a directory and see what it had in it before the intrusion
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
I think that key must been added by the trojan. The key "netsrv" is not under ControlSet001/Services on any of the 3 2003 servers I just looked at.
Try exporting the key netsrv, then delete it, and try that. You can reimport it if it does not work.
Oh, and remember you will have to reboot to check it.
Dubble
Try exporting the key netsrv, then delete it, and try that. You can reimport it if it does not work.
Oh, and remember you will have to reboot to check it.
Dubble
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
Chalk wrote:Dunno....they don't let me play with the servers...I know enough to either break them or fix them![]()
![]()
Ahhhh....hmmmmm
What does your backup say
hehe, servers are fun. I love watching 25 people running around freaking out..........They look at you and say, "How can you be so calm.
Dubble
Oh yeah, keep a spray bottle of water handy, so you can look like you are sweating a little.....
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.
- Chalk
- Moderator
- Posts: 9550
- Joined: March 9th, 2002, 7:00 pm
- Location: 30° 13' N, 85° 40' W
- Contact:
I help manage a pretty complex system, keyword being manage
http://www.ctc.com/files/ctcVideos/DJC2_medium.wmv
http://www.ctc.com/files/ctcVideos/DJC2_medium.wmv
- Dubble Trubble
- Site Sponsor
- Posts: 2310
- Joined: October 30th, 2005, 7:46 pm
- Location: Thomasville
The thing that REALLY freaks me out is our defense system being run on WINDOZS......
"Ok, Mr. President, we are launching a first strike to disable their missle system....Ahhhhh....waiiiaattt just a minute...the system just locked up, but it's ok we are reboo.......BOOOMMMMMMMMMM!!!!!
Dubble
PS, The virus that locked up the system came from Russia and China...

"Ok, Mr. President, we are launching a first strike to disable their missle system....Ahhhhh....waiiiaattt just a minute...the system just locked up, but it's ok we are reboo.......BOOOMMMMMMMMMM!!!!!
Dubble
PS, The virus that locked up the system came from Russia and China...
Last edited by Dubble Trubble on April 5th, 2007, 9:45 am, edited 2 times in total.
The more I know about something, the more I know that I did not know as much as I thought I knew that I knew.

_______________