Security Forums

Log in

FAQ | Search | Usergroups | Profile | Register | RSS | Posting Guidelines | Recent Posts

sasser on xp pro sp2 machine??

Users browsing this topic:0 Security Fans, 0 Stealth Security Fans
Registered Security Fans: None
Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Viruses // Worms

Special offer!

TechGenix and SolarWinds have partnered to provide a fully-functional, free 21-day trial version of SolarWinds ipMonitor, the WindowsNetworking.com Readers' Choice Award Winner for monitoring applications, servers, and network devices to all visitors who join Security Forums. Sign up to Security Forums and get your copy today! Existing members can pick up a copy from the Members Area.

View previous topic :: View next topic  
Author Message
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Mon Oct 23, 2006 5:41 pm    Post subject: sasser on xp pro sp2 machine?? Reply with quote

just as it says. this lady has xp pro and it's acting like it has the sasser worm on it. she gets random reboots and a lot of times will get a countdown screen before it does the reboot. she can't cancel the counter and it doesn't let her do anything else except reboot once it starts. when it reboots it gives the "recovered from a system error" message and faults lsass.exe as the problem process

the thing is, i know the sasser vulnerability was supposed to be patched as of sp2. i've run the windows vulnerability assessment tool, mcafee viruscan 8.0 full system scan and taken her machine off the network for now. no malware has been detected whatsoever. i am just stumped.
Back to top
View user's profile Send private message
Groovicus
SF Mod - S.M.A.R.T. Member
SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004
Posts: 1170
Location: Centerville, South Dakota

Offline

PostPosted: Mon Oct 23, 2006 6:11 pm    Post subject: Reply with quote

Yours is the second thread I've seen discussing this. I put out some feelers on some other boards, but nothing yet. Have you run a rootkit check yet?
_________________
Never argue with stupid people. They just drag you down to their level and beat you with experience.
Back to top
View user's profile Send private message Visit poster's website
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Mon Oct 23, 2006 6:29 pm    Post subject: Reply with quote

no, i'm doing a complete reformat & reinstall right now, hoping that kills whatever it is. originally this machine was quick formatted and i think it missed whatever was hiding in there. but we can swap out machines pretty quick here so we just gave the user a new machine while we reformat the old one
Back to top
View user's profile Send private message
Groovicus
SF Mod - S.M.A.R.T. Member
SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004
Posts: 1170
Location: Centerville, South Dakota

Offline

PostPosted: Mon Oct 23, 2006 6:37 pm    Post subject: Reply with quote

Aack! Is there any way possible to avoid doing that? At least until you can get a look around? It would be very helpful if you can find an infector of some sort.
_________________
Never argue with stupid people. They just drag you down to their level and beat you with experience.
Back to top
View user's profile Send private message Visit poster's website
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Mon Oct 23, 2006 6:54 pm    Post subject: Reply with quote

sorry, it's already been reformatted this morning Sad if it is a rootkit though, do you think there's a chance of it coming back at this point?
Back to top
View user's profile Send private message
Groovicus
SF Mod - S.M.A.R.T. Member
SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004
Posts: 1170
Location: Centerville, South Dakota

Offline

PostPosted: Mon Oct 23, 2006 7:49 pm    Post subject: Reply with quote

Quote:
it's already been reformatted this morning


Bad doggie!!! No No!! Laughing

I don't think the fact that it may be a root kit has anything to do with anything other than why you were unable to find a cause for the problem. I would assume if the user follows the same course of actions that caused the problem in the first place, whether it be opening an infected email or whatever, that they will get infected again. And this is assuming it is an infection, and assuming that it is the RPC being affected, etc.
_________________
Never argue with stupid people. They just drag you down to their level and beat you with experience.
Back to top
View user's profile Send private message Visit poster's website
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Mon Oct 23, 2006 9:26 pm    Post subject: Reply with quote

this was a machine that was reimaged for another user and we think the original user infected it. so i don't think the problem will come back with the current user since the previous user was known for their browsing habits of going to just about any and every site possible Rolling Eyes
Back to top
View user's profile Send private message
larsmhansen
Trusted SF Member
Trusted SF Member


Joined: 11 Jan 2003
Posts: 812
Location: Boston, MA, USA

Offline

PostPosted: Mon Oct 23, 2006 9:28 pm    Post subject: Reply with quote

Rootkits and other malware usually doesn't survive reformats and/or re-imaging.
_________________
Is there anybody listening? Is there anyone that sees what's going on?
Read between the lines, criticize the words they're selling
Think for yourself and feel the walls Become sand beneath your feet
Back to top
View user's profile Send private message Send e-mail Visit poster's website MSN Messenger
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Tue Oct 24, 2006 2:02 am    Post subject: Reply with quote

that's what i thought too, but the guy who re-installed it originally said he just did a "quick format" during the installation instead of a full format. this time around he did a full format. hopefully it won't have problems when we bring it back on the domain....
Back to top
View user's profile Send private message
Groovicus
SF Mod - S.M.A.R.T. Member
SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004
Posts: 1170
Location: Centerville, South Dakota

Offline

PostPosted: Tue Oct 24, 2006 2:13 am    Post subject: Reply with quote

According to the specs, the only difference between quick format and full format is that the quick format does not check the disk for bad sectors. It says that it removes files from the partition, but that could be taken to mean that files are marked for deletion, etc. I am just guessing at this point.

On the other hand, wouldn't it be interesting (to me, nightmare to you) if there was a different machine on your network that actually carried the infection...say, some sort of worm?

EDIT: Just found this though, and on the face of it, it makes sense.
Quote:
Basically, a Full format truly scrubs the disk from
scratch, rebuilds all of the file structures, and checks to make
sure that everything is copasetic. All a Quick format does is lay
down a blank FAT and directory table. This is why a brand-new
unformatted disk can't be Quick formatted and must receive a Full
format; it needs all of the file structures laid out first, so the
FAT actually has blocks and sectors to track, instead of a
nebulous mess


http://chris.pirillo.com/2002/06/29/full-versus-quick/
_________________
Never argue with stupid people. They just drag you down to their level and beat you with experience.
Back to top
View user's profile Send private message Visit poster's website
moondoggie
Forum Fanatic
Forum Fanatic


Joined: 27 May 2005
Posts: 1304


Offline

PostPosted: Tue Oct 24, 2006 2:48 am    Post subject: Reply with quote

yeah, it was always my understanding that a quick format just recreated the FAT and didn't actually delete anything from the drive, this is why i thought the infection could have made it through the quick format. well, unless it comes back i'll never get the chance to find out if anyone else has it. and i can't say i would be sorry if that's the case Wink
Back to top
View user's profile Send private message
Display posts from previous:   

Post new topic   Reply to topic   Printer-friendly version    Security Forums Index -> Viruses // Worms All times are GMT + 2 Hours
Page 1 of 1


 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Community Area

Log in | Register