Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Unknown Attack--Anyone Seen This?

Status
Not open for further replies.

bugguy51

MIS
Sep 16, 2004
49
US
Started seeing a detection of SDBOT.worm.gen.J late 3/30-early 3/31 on workstations. A small handful (about 6) were found to be pretty much destroyed--RPC thread driving an instance of svchost to 97% processor, Start Bar minimized and locked, assorted registered services (Microsoft Installer Service, MS Scripting Host, and others) broken or unavailable. All workstations are XP SP1 with patches to the end of 04.

On 4/3, 6 of my production MS-SQL (Win2K SP4 & patched, MS-SQL 2K) servers got hit with the same thing. Luckily, didn't see the 97% svchost, and all server processes seem intact, but the desktop environment shows alot of the same symptoms, particularly broken services.

Reconfigured RPC to Take No Action on stop so I could at least have some of the processor, have scanned with every available tool (McAfee GUI, Stinger and command line in Safe Mode, Trend Micro, Panda, F-Prot in Safe Mode), have searched the registry for \RUN keys and inappropriate .exe's, with no luck. Have been unable to capture anything other than error boxes to submit to McPrimeSupport.

Any help appreciated before I set about to rebuild the prod servers.

Thanks!

The Bug Guy
 
Rebuilding sounds like your best bet. [Deity of choice] only knows what rootkits and backdoors have been installed by now.
 
Looks like an outbreak of W32/BUBE.dr--profile 4461 began detecting a few hits today. Wish they'd gotten there a little earlier--those 6 production SQL boxes are NOT going to be fun to rebuild.

Truly nasty bug--anyone else gets hit with this one, I'll be glad to pass along anything I learn about resurrecting the box(es).

The Bug Guy
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top