1,800 files missing from system32

From: Joe Blatz (sd_wireless_at_yahoo.com)
Date: 10/14/04

  • Next message: Harlan Carvey: "Re: 1,800 files missing from system32"
    Date: Thu, 14 Oct 2004 07:16:08 -0700 (PDT)
    To: incidents@securityfocus.com
    
    

    A customer's Windows 2000 server has come up as
    missing about 1,800 files from system32. Anyone seen
    this happen?

    This is about tenth time this has happened to a
    customer of ours. It's happened at multiple sites and
    servers. It's ONLY happening on W2k servers (DCs and
    non-DCs). They are running up to date Symantec AV
    signatures.

    We've had problems getting to the systems to perform
    any meaningful analysis before they get rebuilt.

    I was able to review the event logs on one system and
    while I found no smoking gun I did find a few things
    that I found odd.
    1. At precisely 9:00:00 AM Windows File Protection
    kicked in when 35 files in "common files\microsoft
    shared", "common files\system\ado", and "common
    files\system\msadc", as well as these three:
    trialoc.dll, wb32.exe and wordpad.exe were restored by
    WFP.

    2.Event ID 1202 SceCli Security policies are
    propagated with warning. 0x2: The system cannot find
    the file specified, is being logged. This could be
    caused by an irresoluble account name but we were not
    able to trouble shoot before the system was restored.
    This started almost 2 hrs before the WFP activity
    mentioned above.

    Something that must be disclosed is that these system
    are only patched through MS04-004. We know that's a
    huge problem but the configuraiton management these
    systems are under has not yet approved more current
    patches. If this is caused by malware I'll put my
    money on missing MS04-011 as being the key factor in
    all of this.

    An MS support rep says he thinks it's a virus, but I'm
    not familiar with any that ONLY target W2k server, and
    he can't tell us which one he thinks it is. Has anyone
    seen malware, or anything else, only affect W2k
    servers and cause massive file deletions in system32?

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - Helps protect you from nasty viruses.
    http://promotions.yahoo.com/new_mail


  • Next message: Harlan Carvey: "Re: 1,800 files missing from system32"

    Relevant Pages

    • Re: What do I do now?
      ... Run a netdiag /fix on the dc they are missing from ... We have a single Windows 2003 domain in 2 sites, ... Beyond these servers, we have a ... We also have a large number of Linux servers, ...
      (microsoft.public.windows.server.dns)
    • Re: What do I do now?
      ... Run a netdiag /fix on the dc they are missing from ... Beyond these servers, we have a ... We also have a large number of Linux servers, Windows and Linux ...
      (microsoft.public.windows.server.dns)
    • Re: Outgoing Mail
      ... "I must be missing something simple, ... "Neil Sprangers" wrote in message ... >servers, all which work fine from an outlook express account. ... I've given up and configured all the clients to use the smtp ...
      (microsoft.public.windows.server.sbs)
    • Re: DNS configuration
      ... Make sure all DCs and even DNS servers point to the internal DNS ... How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com ... It appears that much of the SBS DNS configuration is missing. ...
      (microsoft.public.windows.server.sbs)
    • Re: Error Message - Exchange 2003/Server 2003
      ... Is Exchange Enterprise Servers group also missing? ... >> MCSE, MCT ...
      (microsoft.public.exchange.admin)

  • Quantcast