ndavies Posted October 29, 2007 Posted October 29, 2007 Found both of these in our WINNT/System32 folder. The Alerter service on our DC appears to be pointed to Lssas.exe. The Alerter service on our replica points to SCVHost. A bit of research looks like the Lssas.exe is a nasty piece of work and shouldn't be there. A trojan variant of GrayBird. Should Alerter be using SCVHost as opposed to the proper Lsass.exe? We're also completely unable to ping our DC. It tells us it's connected to the switch fine, the switch says its fine yet we can't reach it?! Any suggestions. It has a fixed IP and being the DC has all the DNS and DHCP stuff on it. Ta Nick "head scratching" Davies
Geoff Posted October 29, 2007 Posted October 29, 2007 On W2k3 SP2: C:\WINDOWS\system32\svchost.exe -k LocalService
ndavies Posted October 30, 2007 Author Posted October 30, 2007 turns out someone has loaded several services onto our dc to do with the counterstrike game. we've actually this morning just caught a remote user on it, trying to install more services and transferring stuff via an open ftp connectoin......first thing..pull the plug! dear oh dear.
ndavies Posted October 30, 2007 Author Posted October 30, 2007 Looks like it. We're working through cleaning it up offline. But how can we ever be sure...there's so many processes running!
Geoff Posted October 30, 2007 Posted October 30, 2007 You can't. You must rebuild your systems from known good backups and/or scratch. Also, contact your LEAs audit department. They have people for helping you with this.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now