Jump to content

Recommended Posts

Posted

Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. The Alerter service on our replica points to SCVHost.

 

A bit of research looks like the Lssas.exe is a nasty piece of work and shouldn't be there. A trojan variant of GrayBird.

 

Should Alerter be using SCVHost as opposed to the proper Lsass.exe?

 

We're also completely unable to ping our DC. It tells us it's connected to the switch fine, the switch says its fine yet we can't reach it?! Any suggestions. It has a fixed IP and being the DC has all the DNS and DHCP stuff on it.

 

Ta

 

Nick "head scratching" Davies

Posted

turns out someone has loaded several services onto our dc to do with the counterstrike game. we've actually this morning just caught a remote user on it, trying to install more services and transferring stuff via an open ftp connectoin......first thing..pull the plug!

 

dear oh dear.

Posted
You can't. You must rebuild your systems from known good backups and/or scratch. Also, contact your LEAs audit department. They have people for helping you with this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...