CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Is this a virus?

 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
rgpta

Cadet
Cadet


Joined: Nov 21, 2003
Posts: 3
Location: USA

PostPosted: Fri Nov 21, 2003 1:31 pm    Post subject: Is this a virus?
Reply with quote

I have multiple users trying to register their workstations names in DNS as ADMIN. This is not heir DNS, WINS or Netbios name. Once DNS returns an error, the stations go to WINS to register, WINS returns error, and the workstaions broadcast the network. Currently 200+ workstations are broadcasting the the network. I edited the hosts file on one WS to resolve ADMIN to lpbk address and broadcasts stopped. This looks like a DOS attack to me. Once users try to log in muliple times, their accounts get locked. I believe this due to WINS security measure. WS that do not have admin rights should not be trying to change names or register as ADMIN (WINS Type 00). I ran stinger and picked up nothing. HELP!!!!!!!!!! Question

Back to top
View users profile Send private message Visit posters website
IP: 212.133.*.*

Guest






PostPosted: Fri Nov 21, 2003 5:18 pm    Post subject:
Reply with quote

Stinger will only pick up the select group of current prevailant threats as per the discription on the website.

It is not a substite for real AntiVirus protection software.

Look for some suspisious processes running on the ws's in question.

Back to top
rgpta

Cadet
Cadet


Joined: Nov 21, 2003
Posts: 3
Location: USA

PostPosted: Fri Nov 21, 2003 6:18 pm    Post subject:
Reply with quote

Do you think this is a virus? It apears that way to me. I have tried researching the symptoms to no avail.

Back to top
View users profile Send private message Visit posters website
CalamityJane

Security Expert
Microsoft MVP

Joined: Oct 05, 2002
Posts: 4004

MVP Premium Security Experts

PostPosted: Fri Nov 21, 2003 7:19 pm    Post subject:
Reply with quote

Assuming you have Antivirus protection on those affected workstations and have scanned them, did they find nothing?

You could try this (it worked for another Sys Admin I know when the QHosts Trojan first came out and was not being detected by the AVs)

Go to one of the affected PCs and download *Hijack This!* http://www.tomcoyote.org/hjt/ or http://www.spywareinfo.com/~merijn/files/hijackthis.zip

Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that and copy & paste its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the contents of the scan results.

With that log we can see what is running on that PC and come up with a fix for you.

Back to top
View users profile Send private message Visit posters website
rgpta

Cadet
Cadet


Joined: Nov 21, 2003
Posts: 3
Location: USA

PostPosted: Mon Nov 24, 2003 6:09 pm    Post subject:
Reply with quote

Thank You, It was a form of blaster virus on one of the DC servers

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer