TechGenix and SolarWinds have partnered to provide a fully-functional, free 21-day trial version of SolarWinds ipMonitor, the WindowsNetworking.com Readers' Choice Award Winner for monitoring applications, servers, and network devices to all visitors who join Security Forums. Sign up to Security Forums and get your copy today! Existing members can pick up a copy from the Members Area.
| View previous topic :: View next topic |
| Author |
Message |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Mon Oct 23, 2006 5:41 pm Post subject: sasser on xp pro sp2 machine?? |
|
|
just as it says. this lady has xp pro and it's acting like it has the sasser worm on it. she gets random reboots and a lot of times will get a countdown screen before it does the reboot. she can't cancel the counter and it doesn't let her do anything else except reboot once it starts. when it reboots it gives the "recovered from a system error" message and faults lsass.exe as the problem process
the thing is, i know the sasser vulnerability was supposed to be patched as of sp2. i've run the windows vulnerability assessment tool, mcafee viruscan 8.0 full system scan and taken her machine off the network for now. no malware has been detected whatsoever. i am just stumped.
|
|
| Back to top |
|
 |
Groovicus SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004 Posts: 1170 Location: Centerville, South Dakota

|
|
| Back to top |
|
 |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Mon Oct 23, 2006 6:29 pm Post subject: |
|
|
|
no, i'm doing a complete reformat & reinstall right now, hoping that kills whatever it is. originally this machine was quick formatted and i think it missed whatever was hiding in there. but we can swap out machines pretty quick here so we just gave the user a new machine while we reformat the old one
|
|
| Back to top |
|
 |
Groovicus SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004 Posts: 1170 Location: Centerville, South Dakota

|
|
| Back to top |
|
 |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Mon Oct 23, 2006 6:54 pm Post subject: |
|
|
sorry, it's already been reformatted this morning if it is a rootkit though, do you think there's a chance of it coming back at this point?
|
|
| Back to top |
|
 |
Groovicus SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004 Posts: 1170 Location: Centerville, South Dakota

|
Posted: Mon Oct 23, 2006 7:49 pm Post subject: |
|
|
| Quote: |
| it's already been reformatted this morning |
Bad doggie!!! No No!!
I don't think the fact that it may be a root kit has anything to do with anything other than why you were unable to find a cause for the problem. I would assume if the user follows the same course of actions that caused the problem in the first place, whether it be opening an infected email or whatever, that they will get infected again. And this is assuming it is an infection, and assuming that it is the RPC being affected, etc.
_________________ Never argue with stupid people. They just drag you down to their level and beat you with experience.
|
|
| Back to top |
|
 |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Mon Oct 23, 2006 9:26 pm Post subject: |
|
|
this was a machine that was reimaged for another user and we think the original user infected it. so i don't think the problem will come back with the current user since the previous user was known for their browsing habits of going to just about any and every site possible
|
|
| Back to top |
|
 |
larsmhansen Trusted SF Member


Joined: 11 Jan 2003 Posts: 812 Location: Boston, MA, USA

|
Posted: Mon Oct 23, 2006 9:28 pm Post subject: |
|
|
Rootkits and other malware usually doesn't survive reformats and/or re-imaging.
_________________ Is there anybody listening? Is there anyone that sees what's going on?
Read between the lines, criticize the words they're selling
Think for yourself and feel the walls Become sand beneath your feet
|
|
| Back to top |
|
 |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Tue Oct 24, 2006 2:02 am Post subject: |
|
|
|
that's what i thought too, but the guy who re-installed it originally said he just did a "quick format" during the installation instead of a full format. this time around he did a full format. hopefully it won't have problems when we bring it back on the domain....
|
|
| Back to top |
|
 |
Groovicus SF Mod - S.M.A.R.T. Member


Joined: 19 May 2004 Posts: 1170 Location: Centerville, South Dakota

|
Posted: Tue Oct 24, 2006 2:13 am Post subject: |
|
|
According to the specs, the only difference between quick format and full format is that the quick format does not check the disk for bad sectors. It says that it removes files from the partition, but that could be taken to mean that files are marked for deletion, etc. I am just guessing at this point.
On the other hand, wouldn't it be interesting (to me, nightmare to you) if there was a different machine on your network that actually carried the infection...say, some sort of worm?
EDIT: Just found this though, and on the face of it, it makes sense.
| Quote: |
Basically, a Full format truly scrubs the disk from
scratch, rebuilds all of the file structures, and checks to make
sure that everything is copasetic. All a Quick format does is lay
down a blank FAT and directory table. This is why a brand-new
unformatted disk can't be Quick formatted and must receive a Full
format; it needs all of the file structures laid out first, so the
FAT actually has blocks and sectors to track, instead of a
nebulous mess |
http://chris.pirillo.com/2002/06/29/full-versus-quick/
_________________ Never argue with stupid people. They just drag you down to their level and beat you with experience.
|
|
| Back to top |
|
 |
moondoggie Forum Fanatic


Joined: 27 May 2005 Posts: 1304

|
Posted: Tue Oct 24, 2006 2:48 am Post subject: |
|
|
yeah, it was always my understanding that a quick format just recreated the FAT and didn't actually delete anything from the drive, this is why i thought the infection could have made it through the quick format. well, unless it comes back i'll never get the chance to find out if anyone else has it. and i can't say i would be sorry if that's the case
|
|
| Back to top |
|
 |
|