Re: Virus like activity, local security policy problem
From: Edward Alfert (edward@alfert.com)
Date: 08/29/02
- Next message: Drew Cooper [MS]: "Re: profile logon problem"
- Previous message: Drew Cooper [MS]: "Re: File ENcryption Problem Detail"
- In reply to: dejann@: "Virus like activity, local security policy problem"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Edward Alfert <edward@alfert.com> Date: Thu, 29 Aug 2002 15:44:35 -0400
dejann@ wrote:
> I am having a virus like problem with 2 windows 2000 (sp3) worstations.
>
> On both machines interactive logon right was revoked for everyone except
> for a single domain user (same user in both cases).
> This can be changed using ntrights tool alowing me to log on, but the
> changes are reverted as soon as I reopen local security policy.
>
> Both machines were scanned for viruses with latest McAfee and Symantec AV
> tools and no viruses were found.
>
> Please help!
>
> Dejan
this is definitely a trojan of some kind...i have just come from helping
clean 2 w2kpro systems.
I should have written down the name of the files...but..go to
/winnt/system32/ and sort by date... you will notice there are several
programs that don't belong with very recent date/time ... i think one is
secedit.sdb or something like that...
another file is tftp<number> ...there are several of these files
there are also (i think) 3 files with 3 letters (with the same date and
time)... i think mdp or ndp or something like that.
also there is a fake taskmgr.exe ..it is called taskmngr.exe ...
norton dat dated 8/28 detected 12 virus (irc trojan) and was able to
quaranteen them.
i have managed to clean the systems but am having problems login in from one
machine to the other... it works in one machines, but not the other.... one
way authorization.
as i get more information, i will post...
-- Edward Alfert http://edward.alfert.com/ * http://www.sysadmin.info/ "Choose a job you love, and you will never have to work a day in your life." - Unknown Sage
- Next message: Drew Cooper [MS]: "Re: profile logon problem"
- Previous message: Drew Cooper [MS]: "Re: File ENcryption Problem Detail"
- In reply to: dejann@: "Virus like activity, local security policy problem"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|