Page 1 of 2

Need computer help Chalk

Posted: April 5th, 2007, 8:02 am
by wevans
We have only one WIN2003 server here and a hacker got into it and changed the registry setting for the Network Services :hammer: If you have a 2003 server there, could you look and see what file should be executed from the registry setting "My Computer\HKEY_LOCAL_MACHINE\System\controlset001\services\netsrv" :-D The SOB put a Trojan .exe in place of the real file :smt013
:beer: :beer:

Posted: April 5th, 2007, 8:20 am
by Dubble Trubble
Google "netsrv.exe"

It is a trojan. Looks to be a little complicated to remove, but try avg antispyware trial.....I have had good luck with it.....

Beware, DO NOT go to one of the sites on google and download removers. You will get more than you bargained for!

Just read up on it...


Dubble

Posted: April 5th, 2007, 8:28 am
by wevans
Don't have the netsrv.exe trojan :thumbup: I do have a network service that don't work do to him changing the registry to run a trojan in place of the network service :smt010 I just can't find which file SHOULD be running instead of the one he put in place :smt012
PS: The server has been cleaned :thumbup: I just have to repair the damage now :beer:

Posted: April 5th, 2007, 8:32 am
by Dubble Trubble
I just checked 2 of my servers. They do not have that key in the registry at all. One is SBS 2003 and the other is 2003 R2.

So, I have no idea what file should be there. Sorry.

Dubble

Posted: April 5th, 2007, 8:41 am
by Dubble Trubble
Checked a few more and NONE of the servers have the Key "system" under ControlSet001.

All have just 4

Control
Enum
Hardware Profiles
Services

Dubble

Posted: April 5th, 2007, 8:43 am
by wevans
Ours is 2003 standard edition with Exchange 2003 installed.
These where they major files he installed "through our firewall" :hammer:
JAcheck.dll Generic BackDoor(Trojan)
psexec.exe RemAdm-PSKill(Remote Admin Tool)
csrms.exe ServU-Daemon(Trojan)
As well as some txt files that he used :smt012
I guess I'll just restore the hive "from backup" to a directory and see what it had in it before the intrusion :beer:

Posted: April 5th, 2007, 8:45 am
by Chalk
Dunno....they don't let me play with the servers...I know enough to either break them or fix them :roll: :lol:

Ahhhh....hmmmmm

What does your backup say :roll:

Posted: April 5th, 2007, 8:46 am
by wevans
I'm an IDIOT :hammer: I typed in system to many times :hammer: :hammer:
My Computer\HKEY_LOCAL_MACHINE\System\controlset001\services\netsrv

Posted: April 5th, 2007, 8:54 am
by Dubble Trubble
ah, now that could make a difference. Hang on, and I will look again....

Dubble

Posted: April 5th, 2007, 8:59 am
by Dubble Trubble
I think that key must been added by the trojan. The key "netsrv" is not under ControlSet001/Services on any of the 3 2003 servers I just looked at.

Try exporting the key netsrv, then delete it, and try that. You can reimport it if it does not work.

Oh, and remember you will have to reboot to check it.


Dubble

Posted: April 5th, 2007, 9:07 am
by Dubble Trubble
Chalk wrote:Dunno....they don't let me play with the servers...I know enough to either break them or fix them :roll: :lol:

Ahhhh....hmmmmm

What does your backup say :roll:

hehe, servers are fun. I love watching 25 people running around freaking out..........They look at you and say, "How can you be so calm. :roll: That is when you just keep quiet and don't tell them you already got it fixed. Just have a little fun and watch the action for another 10 minutes before putting them back online..... :o

Dubble :lol:

Oh yeah, keep a spray bottle of water handy, so you can look like you are sweating a little.....

Posted: April 5th, 2007, 9:10 am
by Barhopr
Hey just call the tech guy, oh wait a minute thats you :-D

Posted: April 5th, 2007, 9:32 am
by wevans
:lol: :o :smt014 :smt013 :smt010 :smt010 :smt009 :beer:

Posted: April 5th, 2007, 9:34 am
by Chalk
I help manage a pretty complex system, keyword being manage :lol:

http://www.ctc.com/files/ctcVideos/DJC2_medium.wmv

Posted: April 5th, 2007, 9:42 am
by Dubble Trubble
The thing that REALLY freaks me out is our defense system being run on WINDOZS......


"Ok, Mr. President, we are launching a first strike to disable their missle system....Ahhhhh....waiiiaattt just a minute...the system just locked up, but it's ok we are reboo.......BOOOMMMMMMMMMM!!!!!



Dubble :smt011


PS, The virus that locked up the system came from Russia and China... :smt009 :smt010