Re: Hidden shares on PDC AD Win2K server self disabling?



Turns out we got nailed by a new exploit on the net... rather unfriendly
critter it is too.

Symptoms include missing admin shares (IPC$ etc) and strange share
behaviours on other network available folders.

You may also find that your sysvol\domain\scripts have gone missing.


We followed up with Microsoft to help track down what was going on, and it
was tracked back to a file named sysinit32.exe in the winnt\system32
folder. After killing the process, deleting the file and removing all
references to it from the registry we were able to restart the Server
service and successfully recreate the shares.

The malware has been submitted, so hopefully we'll see some patches and AV
signatures coming out soon.



On Thu, 28 Jul 2005 10:20:14 +0200, Miha Pihler [MVP] wrote:

> Hi,
>
> Can you check System and Application logs on this server? Are there any
> errors or other events that might give any clues to the problem?
>
> Also check out ...
> Virus scanning recommendations on a Windows 2000 or on a Windows Server 2003
> domain controller
> http://support.microsoft.com/default.aspx?scid=kb;en-us;822158

--
~^~
// "\\ /\\
\\ // //\\\ -------------------
@ // ///=\\SCII Ribbon Campaign
X /=---=\\gainst HTML E- Mail
X /// \\
// \\ ----------------------------
\ // \\
\// \\
\\

.



Relevant Pages

  • Re: policy
    ... I have a folder "userfiles" on the server. ... browsing a list of shared folders and their content, ... running at Windows Server 2003 SP1. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Move large number of files from AIX to Windows
    ... folders, ~60GB) on a JFS2 SSA Raid 5 array that I need to get down to ... a Windows server. ... I've been able to copy the files using NFS and SSH, ... portable/removable drive that can be attached to each server. ...
    (AIX-L)
  • Re: Configure Auditing
    ... a freeware tool in the Windows Server 2003 Resource Kit Tools. ... continue due to access denied messages (I have many folders with ... way to enable auditing using the command prompt where I can use a switch ...
    (microsoft.public.win2000.cmdprompt.admin)
  • Re: Hidden shares on PDC AD Win2K server self disabling?
    ... > Symptoms include missing admin shares and strange share ... > behaviours on other network available folders. ... >> Can you check System and Application logs on this server? ...
    (microsoft.public.windows.server.active_directory)
  • Re: New to FTP
    ... >I'm setting up my first FTP site for my company using windows server 2003. ... How To Set Up an FTP Site So That Users Log Onto Their Folders: ...
    (microsoft.public.inetserver.iis.ftp)