Possible Variant of IERK8234.SYS

From: Greg Chatten - St. Louis Internet (gchatten@ST-LOUIS.NET)
Date: 03/01/03

  • Next message: Russ: "Re: Alert: Microsoft Security Bulletin - MS03-006"
    Date:         Sat, 1 Mar 2003 11:48:42 -0600
    From: "Greg Chatten - St. Louis Internet" <gchatten@ST-LOUIS.NET>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    At exactly 16:00Z 3/1/03 a server which was previously infected with the
    IERK8234.SYS driver, which caused blue-screen crashes, blue-screened again
    specifying a driver name of "P2.SYS". This is on a fully-patched W2K
    Advanced Service box which is also running Norton Corporate. No prior
    detection was made.

    Previously we had removed the IERK issue from a customers' colo server
    following all the steps outlined in a previous NTBUGTRAQ advisory, and all
    has been running well since then.

    I cannot find a descriptive reference to "P2.SYS" anywhere. We located the
    file in SAFE MODE under: root\winnt\system32\drivers

    and removed it. So far the box has been running fine since.

    While no evidence suggest the two are linked, the result (blue-screen) is
    certainly in common.

    Regards - Greg

    G. Chatten
    St. Louis Internet, Inc.
    http://www.st-louis.net
    636-458-2866
    Fax: 314-215-4162

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Have you discovered a security vulnerability related to Windows or a
    commercial product which runs on Windows?

    Need assistance crafting the format or translating your advisory to English?

    Need to verify it, or having problems contacting the Vendor?

    Contact mailto:Advisories@NTBugtraq.com

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo



    Relevant Pages

    • RE: xp pro sharing printer
      ... How to troubleshoot network printing problems in Windows XP ... SMB-connected print server ... Incompatible print driver ... and then redirect the port to the network server. ...
      (microsoft.public.windowsxp.security_admin)
    • RE: Bidirectional Printing Windows 2003 Cluster
      ... when the the same driver is insttaled on the cluster Bidrectional printing is ... 278455 How to set up a clustered print server ... The language monitor provides the common language that is needed for the ... Windows Server 2003 includes Pjlmon.dll, ...
      (microsoft.public.windows.server.clustering)
    • Re: Remote Printing with RWW Help Req.
      ... through remote desktop from a laptop located in a Windows 2003 LAN, ... Firstly please go to RWW page and Connect to Server or Client Desktops, ... The local printer's driver is not for Windows Server 2003, ...
      (microsoft.public.windows.server.sbs)
    • Printing, Imaging, Fax and All-in-One FAQ for Mar 17, 2004
      ... Windows XP setup, configuration, and troubleshooting of client Fax Services ... Questions about printers, print client and server setup, drivers, ... A "driver" is a software component that is used by applications and the ...
      (microsoft.public.win2000.fax)
    • Printing, Imaging, Fax and All-in-One FAQ for Mar 17, 2004
      ... Windows XP setup, configuration, and troubleshooting of client Fax Services ... Questions about printers, print client and server setup, drivers, ... A "driver" is a software component that is used by applications and the ...
      (microsoft.public.windowsxp.print_fax)