admin$ ipc$ and c$ shares gone

F

faadil

Hi all. I have a real problem that's bugging me. First, the server
contracted Vundo virus. After a lot of fighting, I was able to remove
it. It was creating randomly created .dll files of 26kb and it opened
iexplorer windows pointing to ad sites. It also removed all shares
above. After I was able to remove Vundo, I proceeded to change the
registry entry located at HKLM\System\CurrentControlSet\Services
\lanmanserver\parameters\AutoShareServer to 1 and AutoShareWks to 1
also. After a restart, the shares had again disappeared. Even if I
manually enable them through a command box using "NET SHARE ADMIN$"
etc... for all shares, they remain present for a while. After about 5
mins, they are no longer there. Any ideas anyone???

Thanks a lot.
 
P

Pegasus \(MVP\)

Hi all. I have a real problem that's bugging me. First, the server
contracted Vundo virus. After a lot of fighting, I was able to remove
it. It was creating randomly created .dll files of 26kb and it opened
iexplorer windows pointing to ad sites. It also removed all shares
above. After I was able to remove Vundo, I proceeded to change the
registry entry located at HKLM\System\CurrentControlSet\Services
\lanmanserver\parameters\AutoShareServer to 1 and AutoShareWks to 1
also. After a restart, the shares had again disappeared. Even if I
manually enable them through a command box using "NET SHARE ADMIN$"
etc... for all shares, they remain present for a while. After about 5
mins, they are no longer there. Any ideas anyone???

Thanks a lot.

In my book an infected server is a compromised server
that must be rebuilt. You're seeing some of this already -
who knows what else might be lurking there?
 
F

faadil

In my book an infected server is a compromised server
that must be rebuilt. You're seeing some of this already -
who knows what else might be lurking there?

Ok, I'll have to use this as a last resort. But nothing else can be
done which involves a quicker fix?
 
F

faadil

Ok, I'll have to use this as a last resort. But nothing else can be
done which involves a quicker fix?

I have done an upgrade but the problem is still present. I know the
only thing left to do is a clean install but doh...
 
S

Steve Parry

In
Pegasus (MVP) said:
In my book an infected server is a compromised server
that must be rebuilt. You're seeing some of this already -
who knows what else might be lurking there?

Agreed, even if it was 100% fixed there's still that creeping paranoia that
somehow, somewhere, someone may be able to get access :)
 
F

faadil

Agreed, even if it was 100% fixed there's still that creeping paranoia that
somehow, somewhere, someone may be able to get access :)

Any idea how this happened though? Both firewall and antivirus are up
to date. It blows me away...

Well, will be doing a clean install tomorrow. In the mean time, I have
scheduled a small batch file to run every 5 mins which restores the
"permanent" shares. Thanks again.
 
J

JM

quoting:
Any idea how this happened though? Both firewall and antivirus are up
to date. It blows me away...

Well, will be doing a clean install tomorrow. In the mean time, I have
scheduled a small batch file to run every 5 mins which restores the
"permanent" shares. Thanks again.


It may be a rootkit... I usually AV scan my computers with a boot disk so
that it gets under the OS.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top